Skip to content
Trust & Compliance Guides Repository Tools Αλλαγή σε: ελληνικάGreek
HARICA
  • Products
    • Server Certificates
    • Email Certificate
    • Code Signing
    • eSignatures
    • eSeal
  • Solutions
    • For Individuals
    • For Small Businesses
    • For Enterprises
  • About us
  • News
Customer Support
Login to CertManager
HARICA
Login to CertManager

Home / News

March 14, 2025/HARICA, S/MIME Certificates, TLS Certificates/

Implementation of Multi-Perspective Issuance Corroboration (MPIC) and Mandatory CAA Checks for Mailbox Addresses.

Multi-Perspective Issuance Corroboration (MPIC)

Starting on March 15, 2025, HARICA will implement Multi-Perspective Issuance Corroboration (MPIC) for Domain Authorization, Control, and Certification Authority Authorization (CAA) Record checks before issuing any TLS Server Authentication Certificates, in accordance with CA/B Forum Baseline Requirements for TLS Server Certificates.

With MPIC, DNS queries for Domain Validation and CAA checks must be verified from multiple, randomly distributed and distant locations across the Internet. If the information corroboration fails (up to a certain level), the certificate issuance will be blocked. Domain Owners must ensure that their Authoritative DNS servers are accessible from the global Internet, allowing the corroboration to be completed without failures that would prevent certificate issuance.

We remind our Subscribers that Publicly-Trusted TLS Server Authentication Certificates are “intended to be used for authenticating servers accessible through the Internet”, as described in the CA/Browser Forum TLS Baseline Requirements.

Mandatory CAA Checks for Mailbox Addresses

Effective March 15, 2025, HARICA will also be required to perform CAA checks for Mailbox Addresses, as mandated by the CA/Browser Forum S/MIME Baseline Requirements.

What You Need to Know:

  • Before issuing an S/MIME certificate that includes a Mailbox Address, HARICA will retrieve and process CAA records, similar to the process used for TLS Certificates.
  • If your DNS CAA record contains the issuemail tag, it must explicitly include the value “harica.gr”, authorizing HARICA for S/MIME certificate issuance.
  • If no issuemail tag is present, no action is required.

TAGS:

CAA, Domain Validation, MPIC, S/MIME, TLS

Latest News

  • May 21, 2023HARICA

    Implementation of a new policy in the protection of the private key in Code Signing certificates

  • May 16, 2023HARICA, Support

    HARICA announcement on Kiwifarms

Logo Harica

GREEK UNIVERSITIES NETWORK (GUnet)
General Commercial Registry Number: 160729401000,
University of Athens – Network Operation Center,
Panepistimiopolis Ilissia
157 84 Athens, Greece

support@harica.gr

© 2025 HARICA. All Rights Reserved.

Shield iconLogo QCERT

HARICA is the Hellenic Academic & Research Institutions Certification Authority. It participates in all major Global ‘ROOT CA’ Trust Programs, and operates as a ‘Trust Anchor’ in widely used Application Software and Operating Systems. It has received a successful Conformance Assessment Report fulfilling the requirements of Regulation (EU) 910/2014 (also known as eIDAS) in the areas of “Qualified” Certificates for electronic Signatures/Seals, website authentication, and “Qualified” Timestamps.

Policy Trust & Compliance CERT Manager API Documentation Resellers/Partners Data Privacy Statement
Page load link
  • Products
    • Server Certificates
    • Email Certificate
    • Code Signing
    • eSignatures
    • eSeal
  • Solutions
    • For Individuals
    • For Small Businesses
    • For Enterprises
  • About us
  • News
  • Customer Support
Trust & Compliance
Guides
Repository
Tools
Αλλαγή σε: ελληνικάGreek
5630
This website uses only essential cookies for basic functionality.
Go to Top