Certificate change in the domain controller infrastructure of the RHRZ
On Wednesday, December 10, 2025 at 11:00 a.m., new certificates will be put into operation on the domain controllers of the RHRZ.
As the underlying root CA provider has changed from Sectigo to HARICA, the root CA certificates used will also change.
In order to avoid possible authentication problems, operators who use the RHRZ Active Directory infrastructure with their systems and applications should ensure that they have classified at least one of the following root CA certificates as trustworthy:
- HARICA TLS RSA Root CA 2021
- Hellenic Academic and Research Institutions RootCA 2015
Further information and download options:
https://doku.tid.dfn.de/de:dfnpki:tcs:2025:cacerts
The domain controller dc05.uni-kl.de is already available in advance with the new certificate chain for compatibility checks.