{"id":124,"date":"2025-10-11T17:05:37","date_gmt":"2025-10-11T09:05:37","guid":{"rendered":"https:\/\/www.sslcert.com.hk\/blog\/?p=124"},"modified":"2025-10-11T17:44:14","modified_gmt":"2025-10-11T09:44:14","slug":"important-industry-update-deprecation-of-client-authentication-eku-in-ssl-tls-certificates","status":"publish","type":"post","link":"https:\/\/www.sslcert.com.hk\/blog\/en\/2025\/10\/11\/important-industry-update-deprecation-of-client-authentication-eku-in-ssl-tls-certificates\/","title":{"rendered":"Important Industry Update: Deprecation of Client Authentication EKU in SSL\/TLS Certificates"},"content":{"rendered":"<p>\u00a0<\/p>\n<p data-start=\"327\" data-end=\"717\">Starting <strong data-start=\"336\" data-end=\"356\">October 14, 2025<\/strong>, newly issued, renewed, or reissued SSL\/TLS certificates will <strong data-start=\"419\" data-end=\"489\">no longer include the Client Authentication EKU (id-kp-clientAuth)<\/strong>.<br data-start=\"490\" data-end=\"493\" \/>This industry-wide change, led by <strong data-start=\"527\" data-end=\"544\">Google Chrome<\/strong> and soon to be adopted by other major browsers, reinforces best practices to ensure certificates are used solely for their primary purpose \u2014 securing <strong data-start=\"695\" data-end=\"704\">HTTPS<\/strong> connections.<\/p>\n<h4 data-start=\"719\" data-end=\"747\">What This Means for You<\/h4>\n<ul data-start=\"748\" data-end=\"1005\">\n<li data-start=\"748\" data-end=\"836\">\n<p data-start=\"750\" data-end=\"836\"><strong data-start=\"750\" data-end=\"772\">No action required<\/strong> if certificates are used only for website encryption (HTTPS).<\/p>\n<\/li>\n<li data-start=\"837\" data-end=\"1005\">\n<p data-start=\"839\" data-end=\"1005\">If certificates are used for <strong data-start=\"868\" data-end=\"893\">mutual authentication<\/strong>, <strong data-start=\"895\" data-end=\"903\">mTLS<\/strong>, or <strong data-start=\"908\" data-end=\"943\">server-to-server identification<\/strong>, please review your setup as these use cases may be affected.<\/p>\n<\/li>\n<\/ul>\n<h4 data-start=\"1007\" data-end=\"1021\">Key Dates<\/h4>\n<ul data-start=\"1022\" data-end=\"1225\">\n<li data-start=\"1022\" data-end=\"1143\">\n<p data-start=\"1024\" data-end=\"1143\"><strong data-start=\"1024\" data-end=\"1045\">October 14, 2025:<\/strong> All new, renewed, and reissued SSL\/TLS certificates will exclude the Client Authentication EKU.<\/p>\n<\/li>\n<li data-start=\"1144\" data-end=\"1225\">\n<p data-start=\"1146\" data-end=\"1225\"><strong data-start=\"1146\" data-end=\"1163\">May 15, 2026:<\/strong> The policy becomes mandatory \u2014 no exceptions after this date.<\/p>\n<\/li>\n<\/ul>\n<h4 data-start=\"1227\" data-end=\"1251\">Recommended Actions<\/h4>\n<ul data-start=\"1252\" data-end=\"1519\">\n<li data-start=\"1252\" data-end=\"1305\">\n<p data-start=\"1254\" data-end=\"1305\">Inform your customers about this upcoming change.<\/p>\n<\/li>\n<li data-start=\"1306\" data-end=\"1398\">\n<p data-start=\"1308\" data-end=\"1398\">For client authentication requirements, consider migrating to a <strong data-start=\"1372\" data-end=\"1386\">Private CA<\/strong> solution.<\/p>\n<\/li>\n<\/ul>\n<p>\u00a0<\/p>","protected":false},"excerpt":{"rendered":"<p>\u00a0 Starting October 14, 2025, newly issued, renewed, or reissued SSL\/TLS certificates will no longer include the Client Authentication EKU<\/p>\n","protected":false},"author":1,"featured_media":126,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[6,48],"_links":{"self":[{"href":"https:\/\/www.sslcert.com.hk\/blog\/en\/wp-json\/wp\/v2\/posts\/124"}],"collection":[{"href":"https:\/\/www.sslcert.com.hk\/blog\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sslcert.com.hk\/blog\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sslcert.com.hk\/blog\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sslcert.com.hk\/blog\/en\/wp-json\/wp\/v2\/comments?post=124"}],"version-history":[{"count":0,"href":"https:\/\/www.sslcert.com.hk\/blog\/en\/wp-json\/wp\/v2\/posts\/124\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sslcert.com.hk\/blog\/en\/wp-json\/wp\/v2\/media\/126"}],"wp:attachment":[{"href":"https:\/\/www.sslcert.com.hk\/blog\/en\/wp-json\/wp\/v2\/media?parent=124"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sslcert.com.hk\/blog\/en\/wp-json\/wp\/v2\/categories?post=124"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sslcert.com.hk\/blog\/en\/wp-json\/wp\/v2\/tags?post=124"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}