LUIS News
HARICA - Erneute Rückrufe einer diesmal größeren Anzahl von SSL-Server-Zertifikaten am 25.07.2026

HARICA – Another recall of a larger number of SSL server certificates on July 25, 2026

On July 25, 2026, another HARICA recall will take place: all SSL server certificates issued between March 27, 2026 and July 20, 2026 must be revoked. User certificates, including group certificates, are not affected.

Update from July 23, 2026 at 09:50 am

Regarding the availability and performance issues: According to a technically detailed email from Harica, a number of improvements have already been implemented and further adjustments are planned. We can confirm that Harica’s services are currently more reliably and usable.


Update from 22 July 2026 at 8:20 pm

In the meantime, a large number of certificates issued today and approved by HARICA have appeared in the Harica Certificate Manager under "SSL Certificates - Valid". HARICA has apparently implemented its announcement to automatically provide replacement certificates for those that need to be revoked.

Please check in the Harica Certificate Manager whether all the certificates you need as replacements for the certificates affected by the revocations are available for download. If necessary, additional certificates that were previously missing may gradually appear. Currently, the Harica Certificate Manager appears to be relatively stable and accessible.

Notification emails from LUIS to all applicants of the certificates affected by the revocations, including a list of the affected certificates, were sent out around noon today and have hopefully reached you.


Update from July 22, 2026 at 14:40

Regarding the accessibility and performance issues affecting both the ACME API and the HARICA Certificate Manager (cm.harica.gr), there is currently no improvement in sight.

Since we are hoping for an improvement in the situation during the evening and night hours, we have decided to extend the approval period for certificates for today, July 22, 2026, until 24:00, in order to potentially benefit from these hours.


Update from July 22, 2026 at 12:25 PM

Supplementary message from DFN, July 22, 2026, 12:20 PM:

Three info snippets:

  • HARICA has informed GÉANT that the affected manually issued certificates (i.e., not via ACME) will be automatically renewed by HARICA today. Information about the renewed certificate should then be sent out as it was last week.

    “Replacement certificates will be issued today – If you prefer, you may manually issue replacement certificates for the affected certificates and install them before the scheduled revocation. This will not interfere with or affect the automatic replacement process.”

  • HARICA expects to be able to send information to Enterprise Admins (and not just to individual subscribers, as has been the case so far) during the course of the day.
  • Regarding the accessibility issues with the ACME API and cm.harica.gr: GÉANT has communicated this to HARICA as a serious problem.

Notes from LUIS:

In view of the current accessibility issues with HARICA, it might be sensible to keep in mind, as a plan B, the automatically renewed certificates from HARICA, which will hopefully actually arrive in time, in case requesting a certificate is not possible within a reasonable amount of time.


Initial news announcement from July 22, 2026

The revocations will take place on July 25, 2026; a specific time has not yet been announced. Please assume that the certificates should be replaced by the end of July 24, 2026.

All SSL server certificates issued between March 27, 2026 and July 20, 2026 are affected.

SSL server certificates issued up to and including March 26, 2026, and from and including July 21, 2026, are not affected by the revocation.

User certificates, including group certificates, are also not affected by the revocations.

We will provide you with the original notification from DFN as well as the email sent by Harica to DFN.

As with the HARICA recall on July 20, 2026, we will again notify all applicants of affected certificates by email.

In the web version of the news announcement, we will continuously publish up-to-date information should there be any new developments.

Regarding ACME, certificate renewals are expected to be triggered automatically and centrally by the HARICA CA (provided that the client used supports ARI = ACME Renewal Information). Nevertheless, it would be advisable to keep an eye on ACME as well and, if necessary, perform a manual renewal before the expected deadline at the end of July 24, 2026.

 

Email from DFN dated July 21, 2026 at 4:04 PM, translated into English by AI:

Dear colleagues,

As already mentioned yesterday by Mr. Brauckmann in his email with the subject "Pre-warning: Possible further certificate revocations in HARICA-TCS on an even larger scale," HARICA has now officially announced further necessary revocations of SSL server certificates, which will be carried out on July 25, 2026.

All SSL server certificates issued between March 27, 2026 and July 20, 2026 (inclusive) and that do not contain the certificate extension AIA OCSP URI access method are affected.

Unfortunately, this also includes SSL server certificates that were already replaced as part of HARICA's revocation announcements last week.

The affected SSL server certificates will be revoked on July 25, 2026.

Not affected are user certificates, as well as server certificates issued up to and including March 26, 2026 and from July 21, 2026 (today) onwards, inclusive.

The background to this renewed round of revocations is that at the end of March 2026, HARICA removed the certificate extension AIA OCSP URI access method from the issued SSL server certificates, as announced at the beginning of the year, but unfortunately failed to update the CP/CPS document accordingly. As a result, SSL server certificates without the certificate extension AIA OCSP URI access method were issued between March 27, 2026 and July 20, 2026, even though this extension should have been included in these certificates according to the CP/CPS documents valid at the time. Therefore, revocation of the affected SSL server certificates is unfortunately unavoidable.

We are aware that cm.harica.gr is currently experiencing performance issues. This was to be expected and will resolve itself in due course.

Forwarded message from HARICA

Subject: [Ticket#2026072110001273] HARICA URGENT: Upcoming Certificate Revocation on 2026-07-25 
Date: Tue, 21 Jul 2026 16:15:03 +0300 
Organization: AUTh IT Center 

"Dear TCS Members, 

We are writing to notify you of an additional technical issue, identified following feedback received during the review of the public incident related to the *id-kp-clientAuth Extended Key Usage (EKU)*, affecting HARICA's certificate profiles used for *TLS Server Certificates* issued between *2026-03-27* and *2026-07-20*. 

*What happened?* 
The review identified that affected certificate profiles did not include the *Authority Information Access (AIA) OCSP URI access method*, while HARICA's current CP/CPS requires this method to be present in TLS Server Certificates. It is worth noting that HARICA’s decision to remove the AIA OCSP URI was consistent with industry’s best practice. Unfortunately, revocation of incompatible certificates with the at-the-time CP/CPS is also expected in the industry. 

As of today, HARICA has restored the AIA OCSP URI in all affected TLS Server certificate profiles to ensure compliance with the current CP/CPS. 

HARICA is also in the process of updating its CP/CPS to reflect the planned sunsetting of the AIA OCSP URI. Once the updated CP/CPS becomes effective, the AIA OCSP URI will again be removed from the corresponding certificate profiles in accordance with the revised policy. Certificates with AIA OCSP URI will remain valid. 

*Action Required* 
TLS Server Certificates issued between *2026-03-27* and *2026-07-20 *that*do not include the AIA OCSP URI access method *are affected and must be replaced. 
HARICA is taking immediate steps to facilitate replacement of all affected certificates. Over the course of today, all affected subscribers will be notified and provided with specific actions required to replace their certificates in time, depending on their issuance method: 

  * Single requests submitted through HARICA's portal and API-based issuance 
  * HARICA's Legacy ACME 
  * HARICA's Flexible ACME 

For Flexible and Legacy ACME, HARICA has enabled ARI (Automated Renewal Information) support to allow affected subscribers to complete replacement automatically. This has already been tested successfully in the course of the previous mass-replacement event. We urge all server TLS certificate subscribers to switch to ACME if they have not done so already. 

A thorough root cause analysis had already started during the clientAuth issue which will be extended to identify systemic issues that lead to these CP/CPS inconsistencies and take measures to minimize the risk of reoccurrence. 

We sincerely apologize for the inconvenience this causes and appreciate your prompt cooperation in ensuring timely certificate replacement. 

We remain at your disposal for any further information. 

Best regards, 

support-tcs@harica.gr 
Hellenic Academic and Research Institutions Certification Authority (HARICA) 
HARICA"