Resolved -
At Mar 22 01:21:56 2024 GMT, some users of dedicated mainland China region endpoints experienced an expired certificate error on some endpoints. The root cause has been identified and addressed. Global traffic was unaffected.
Mar 22, 03:30 UTC
Resolved -
hCaptcha APIs use several SSL certificate authorities, maintaining both primary and backup certificates; our CAA record is authoritative. We also automatically rotate certificates every three months as part of our security best practices.
We received several reports today from customers running servers with outdated root CA entries. They either needed to update these after our most recent automatic certificate rotation, or had locked their validation for our endpoints to a specific certificate chain rather than relying on CA validation and our CAA records.
Please ensure your servers calling the siteverify endpoint have an updated root CA store. This is an important security practice, as root CAs are occasionally compromised and removed from OS vendors' stores. Similarly, if you would like to enforce additional restrictions on validating our TLS certificates, please rely on the CAA record rather than hard-coding a specific intermediate chain.
Mar 15, 04:00 UTC