HARICA nos informa de lo siguiente:

Date: 16 July 2026
Subject: HARICA URGENT: Upcoming Certificate Revocation on 2026-07-20

Dear TCS-PMA Members,

We are writing to notify you of a technical issue, identified following a Certificate Problem Report, affecting HARICA's certificate profiles used for TLS Server Certificates issued on or after June 15th 2026.

What happened?

The affected certificate profiles incorrectly included the clientAuth Extended Key Usage (EKU), which was not permitted under HARICA's CP/CPS. This issue has since been corrected in our CP/CPS. However, in accordance with industry requirements and our CP/CPS, all affected certificates must be revoked within 5 days of the issue's discovery — by 2026-07-20.

This revocation timeline is a standard industry requirement applicable to all publicly trusted CAs, intended to preserve the integrity and trustworthiness of the global certificate ecosystem.

Action Required

HARICA is taking immediate steps to facilitate replacement of all affected certificates. Over the course of today, all affected subscribers will be notified of the upcoming revocation and provided with specific actions required to replace their certificates in time, depending on their issuance method:

  • Single requests submitted through HARICA's portal and API-based issuance
  • HARICA's Legacy ACME
  • HARICA's Flexible ACME

For Flexible and Legacy ACME, HARICA will enable ARI (Automated Renewal Information) support to allow affected subscribers to complete replacement automatically.

We plan to submit a public bug later today following industry practice and share more details.

We sincerely apologize for the inconvenience this causes and appreciate your prompt cooperation in ensuring timely certificate replacement.