HARICA – Replacement of Affected Server Certificates Required by 25 July 2026

Information General
2026-07-21 19:27 CEST · 6 days, 13 hours, 32 minutes

Updates

Issue

HARICA has announced another urgent certificate revocation due to a discrepancy between issued server certificates and the requirements of the HARICA CP/CPS. Affected certificates must be replaced no later than 25 July 2026.

Affected certificates:

  • HARICA server certificates issued between 27 March 2026 and 20 July 2026 (inclusive) that do not contain an AIA OCSP URI access method.
  • Certificates that were already replaced as part of last week’s revocation. These certificates must be replaced again.

Not affected:

  • User certificates
  • Server certificates issued before 27 March 2026 or after 20 July 2026

Deadline:

All affected certificates must be replaced by 25 July 2026. Beginning at 10:00 UTC on 25 July 2026, HARICA will automatically revoke any remaining affected certificates. Certificates that have not been replaced may subsequently cause TLS-protected services to become unavailable.

Replacement information:

  • For ACME clients that support ACME Renewal Information (ARI), certificate replacement is performed automatically. This includes:
    • acme.sh version 3.1.4 or later (released five days ago)
    • Certbot version 4.1.0 or later
    • go-acme/lego version 4.12.0 or later
    • All certificates issued with Caddy version 2.8.0 or later
  • For ACME clients without ARI support, certificate replacement must be initiated manually.
  • Users of the HARICA CertManager will automatically receive replacement certificates (provided the validation data is still valid) and should install them promptly once they become available.

For GWDG-operated affected services, the required certificates will be replaced in time. During the replacement process, brief interruptions to affected services may occur.

An official announcement from HARICA has not yet been published but is expected tomorrow. A full incident report is expected by 24 July 2026. [1]

[1] https://bugzilla.mozilla.org/show_bug.cgi?id=2055551#c2

July 21, 2026 · 19:27 CEST

← Back