Updating the IVPN Certificate Authority

IVPN News By Iain Douglas | Posted on May 18, 2020

This is an advanced warning that you may need to take action to continue using our service beyond 20th July 10:56 2020 UTC.

The IVPN Certificate Authority (CA) is used to sign certificates we issue for our servers. This allows your computer to verify that the VPN server it is connecting to is one of IVPN’s and not one operated by someone else. You can use our service after 20 July with the following app versions:

Please check if your IVPN apps are up-to-date and download the latest versions to avoid disruptions.

Configuration file users

WireGuard and IPSec/IKEv2 - no action required.

More info

The IVPN CA was created 10 years ago and will expire on 20th July 2020. When this happens certificates issued by the CA will become untrusted and OpenVPN connections to our VPN servers will stop working.

In preparation for this event, we have created a new CA and root certificate. We used this to create new VPN server certificates. We also used the old CA to cross sign the new CA root certificate. We have already updated our infrastructure and until 20th July connections to our servers using the old CA certificate and the new CA certificate will be trusted.

If you have any questions please contact support@ivpn.net

We invite you to discuss this post in our Reddit community or on Twitter. You can also send your feedback to blog@ivpn.net.
IVPN News

A security incident on our Bitcoin payment server

By IVPN Staff

IVPN News

Annual security audit scheduled for 2026

By Nick Pestell

Under the Hood

Unlinked Access: reducing cross-service account linkage with HSM-backed token derivation

By Juraj Hilje

IVPN News

A security incident on our Bitcoin payment server

Posted on August 11, 2026 by IVPN Staff

Summary: on 7 August a critical vulnerability was disclosed in BTCPay Server, the open-source software we self-host to accept Bitcoin payments. It was being exploited before disclosure, and we were among the merchants hit: an attacker extracted our Lightning node credentials and transferred out our operating funds.
Annual security audit scheduled for 2026
IVPN News

Annual security audit scheduled for 2026

Posted on June 19, 2026 by Nick Pestell

Consistent with our commitment to regular independent security audits, we have scheduled our eighth annual security audit with Cure53, to be conducted over the course of two weeks in July. As in previous years, audits target systems and services that have undergone significant updates and where review provides the most value to customers in terms of security and auditability.
Spotted a mistake or have an idea on how to improve this page?
Suggest an edit on GitHub.