Skip to main content
Back to overview
High

HARICA Revokes SSL Certificates Due to Policy Non-Compliance and Missing OCSP URI

HARICA, a Greek Certificate Authority, announced further necessary revocations of SSL server certificates scheduled for July 25, 2026.

Key points

  • SSL server certificates issued between March 27, 2026, and July 20, 2026, are affected.
  • Revocation is due to the omission of the AIA OCSP URI access method certificate extension, contrary to policy.
  • This follows a previous revocation for certificates issued with "clientAuth" EKU against policy.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Confidentiality impact

Threat source not confirmed

03

Potential impact

Potential data or process integrity risk

Confidentiality, Integrity

Published
Jul 25, 2026
Updated
Jul 25, 2026
Confidence
High
Evidence
8 sources

Structured assessment

Signal analysis

It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch exposure paths that could affect data, operations or third-party trust.

Business impact

Potential data or process integrity risk
Impact area
Confidentiality, Integrity
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

HaricaData DisclosureHARICA Revokes SSL Certificates DuePolicy Non-Compliance and Missing OCSPURI HARICAGreek Certificate AuthoritySSLHARICAAIA OCSP URICertificate Policy

Quick context

Questions about this signal

What happened in this signal?

HARICA, a Greek Certificate Authority, announced further necessary revocations of SSL server certificates scheduled for July 25, 2026. This action affects SSL server certificates issued between March 27, 2026, and July 20, 2026. The primary reason for this renewed revocation is that HARICA removed the AIA OCSP URI access method certificate extension from issued SSL server certificates at the end of March 2026, but the Certificate Policy/Certificate Practice Statement (CP/CPS) document was not updated accordingly. Consequently, certificates were issued without this extension, contrary to the CP/CPS, making their revocation unavoidable to preserve the integrity and trustworthiness of the global certificate ecosystem. This follows an earlier revocation of certificates issued between June 15 and July 15, 2026, which included the Extended Key Usage (EKU) "clientAuth" against HARICA's policy. Affected network contact persons were to be notified by email, and while HARICA announced automatic renewal, proactive renewal via the RA Portal was recommended to avoid potential issues. User certificates are not affected by these revocations.

When was this signal reported?

Shadow Tier lists Jul 25, 2026 as the signal date.

Which organization is connected to this signal?

Harica is the organization connected to this public signal.

Explore Harica