HARICA nos informa de lo siguiente:
Subject: HARICA URGENT: Upcoming Certificate Revocation on 2026-07-25
Dear TCS-PMA Members,
We are writing to notify you of an additional technical issue, identified following feedback received during the review of the public incident related to the id-kp-clientAuth Extended Key Usage (EKU), affecting HARICA's certificate profiles used for TLS Server Certificates issued between 2026-03-27 and 2026-07-20.
What happened?
The review identified that affected certificate profiles did not include the Authority Information Access (AIA) OCSP URI access method, while HARICA's current CP/CPS requires this method to be present in TLS Server Certificates. It is worth noting that HARICA’s decision to remove the AIA OCSP URI was consistent with industry’s best practice. Unfortunately, revocation of incompatible certificates with the at-the-time CP/CPS is also expected in the industry.
As of today, HARICA has restored the AIA OCSP URI in all affected TLS Server certificate profiles to ensure compliance with the current CP/CPS.
HARICA is also in the process of updating its CP/CPS to reflect the planned sunsetting of the AIA OCSP URI. Once the updated CP/CPS becomes effective, the AIA OCSP URI will again be removed from the corresponding certificate profiles in accordance with the revised policy. Certificates with AIA OCSP URI will remain valid.
Action Required
TLS Server Certificates issued between 2026-03-27 and 2026-07-20 that do not include the AIA OCSP URI access method are affected and must be replaced.
HARICA is taking immediate steps to facilitate replacement of all affected certificates. Over the course of today, all affected subscribers will be notified and provided with specific actions required to replace their certificates in time, depending on their issuance method:
- Single requests submitted through HARICA's portal and API-based issuance
- HARICA's Legacy ACME
- HARICA's Flexible ACME
For Flexible and Legacy ACME, HARICA has enabled ARI (Automated Renewal Information) support to allow affected subscribers to complete replacement automatically. This has already been tested successfully in the course of the previous mass-replacement event. We urge all server TLS certificate subscribers to switch to ACME if they have not done so already.
A thorough root cause analysis had already started during the clientAuth issue which will be extended to identify systemic issues that lead to these CP/CPS inconsistencies and take measures to minimize the risk of reoccurrence.
We sincerely apologize for the inconvenience this causes and appreciate your prompt cooperation in ensuring timely certificate replacement.