Find
Aug 25, 2026

Eurex

Introduction of New DBAG Public Key Infrastructure (PKI) and DBAG Certificate Authority (CA)

053/26 Introduction of New DBAG Public Key Infrastructure (PKI) and DBAG Certificate Authority (CA)

1. Introduction

Deutsche Börse has introduced a new Public Key Infrastructure (PKI) with a new Certificate Authority (CA) on 24 August 2026.

Starting 24 August 2026, the process provided in the Member Section of Deutsche Börse Group for generating client certificates for selected interfaces will automatically use the new DBAG PKI infrastructure. 

The following trading related systems and interfaces are affected:

  • T7 Web GUI 
  • Repo F7 (API, GUI, FIX) 
  • Buy-In B7 (GUI)

2. Required action

Participants using one of the affected interfaces must prepare for the PKI transition and renew their client certificates over the next few months prior to 18 December 2026.

Client certificates signed by the existing PKI/CA remain valid and may be used in parallel with certificates issued by the new PKI/CA until 18 December 2026. Usage of client certificates signed by the old PKI/CA beyond 18 December 2026 cannot be guaranteed.

All certificates issued under the previous PKI/CA must be renewed via the Member Section no later than this date. 

3. Details of the initiative

To support participants during the transition, a new column named “Certificate Type” has been added to the list of certificates displayed for each account in the Member Section of Deutsche Börse Group. Each client certificate in the Member Section of Deutsche Börse Group can now easily be identified. Certificates signed by the existing DBAG PKI/CA are marked as “Old”, while client certificates signed by the new DBAG PKI/CA are marked as “New”. 

Participants must complete the following steps for each affected interface: 

  • A. Log in to the Member Section of Deutsche Börse Group.
  • B. Download one or more new client certificates for the relevant interface. As of 24 August 2026, newly generated client certificates will be automatically signed by the new DBAG PKI/CA. 
  • C. Install the new client certificate(s) in the browser used for the GUI applications or store it in the relevant application keystore for the F7 API and F7 FIX interfaces. 
  • D. Verify that the affected interface can be accessed successfully with the new certificate.
  • E. After successful verification, participants may revoke and delete the corresponding old client certificate. 

This change does not affect any other T7 interfaces, such as T7 ETI, T7 FIX LF, or any T7 market data interface. Only the interfaces explicitly listed in this circular make use of Deutsche Börse Group signed client certificates and are therefore affected by this change.


Further information

Recipients: 

All Trading Participants of Eurex Deutschland and Vendors 

Target groups: 

Front Office/Trading, Middle + Backoffice, IT/System Administration 

Contact: 

Your Technical Key Account Manager via VIP number or cts@deutsche-boerse.com 

Web: 

www.eurex.com

Authorized by: 

Quinten Koekenbier


Market Status

XEUR

The market status window is an indication regarding the current technical availability of the trading system. It indicates whether news board messages regarding current technical issues of the trading system have been published or will be published shortly.

Please find further information about incident handling in the Emergency Playbook published on the Eurex webpage under Support --> Emergencies and safeguards. Detailed information about incident communication, market re-opening procedures and best practices for order and trade reconciliation can be found in the chapters 4.2, 4.3 and 4.5, respectively. Concrete information for the respective incident will be published during the incident via newsboard message. 

We strongly recommend not to take any decisions based on the indications in the market status window but to always check the production news board for comprehensive information on an incident.

An instant update of the Market Status requires an enabled up-to date Java™ version within the browser.