⚠️ Technical Alert

Remove client authentication EKU from public TLS certificates

Solution ID: ALERT53 · Last modified: 05/10/2026

Important Update

Google Chrome has updated its root program requirements and extended the deadline for removing the Key Usage Extension (EKU) for client authentication (clientAuth) from public TLS certificates.

Consequently, through CertiSur, DigiCert will be able to continue including the client authentication EKU in public TLS certificates until March 1, 2027.

Google Chrome Root Program Requirements

The Google Chrome Root program requires that Certificate Authorities (CA) stop including the client authentication EKU in publicly trusted TLS certificates.

To comply with this global standard and continue promoting best practices in digital trust, CertiSur and DigiCert will stop including the client authentication EKU in public TLS certificates starting March 1, 2027.

Which certificates does this change affect?

It affects all public TLS certificates:

  • Validation types: DV, OV, EV.
  • Regulatory certificates: QWAC (EU Qualified Website Authentication Certificate) and QWAC PSD2.
  • DigiCert brands available at CertiSur: DigiCert®, GeoTrust®, Thawte®, RapidSSL®, and Encryption Everywhere®.

Note: We keep this article permanently updated according to the information available from DigiCert and browser forums (CAB Forum). We recommend saving this page for periodic consultation.

Transition plan and measures adopted

Step 1: Change in default configuration (in effect since October 1, 2025)

As of October 1, 2025, public TLS certificates are issued by default with only the server authentication EKU.

Do you still need to include the client authentication EKU explicitly? During the transition period (until March 1, 2027), you can continue to request it during issuance. If you manage your certificates through CertCentral® or API, you will need to proactively select both EKUs (Server Authentication and Client Authentication). CertCentral® administrators can adjust their default preferences from the console.

Step 2: Final removal (as of March 1, 2027)

As of March 1, 2027, the option to include the client authentication EKU in any public TLS issuance (new certificates, reissues, renewals, or duplicates) will be completely removed.

Impact on existing certificates: certificates issued before March 1, 2027 that contain the client authentication EKU will remain valid and trusted until their original expiration date.

Oct 1, 2025 Issuance by default with server authentication only. Manual option available.
Today Transition period: Client EKU can continue to be requested manually.
March 1, 2027 Complete removal of Client EKU from public TLS certificates.
Stage Google Chrome Policy DigiCert / CertiSur Transition Plan
Before March 15, 2027 Both Server Authentication and Client Authentication EKU are allowed to be included in public TLS certificates. October 1, 2025: issuance by default with Server Authentication only. Manual option to add Client Authentication available.
As of March 15, 2027 Only Server Authentication EKU is permitted in publicly trusted TLS certificates. March 1, 2027: complete removal of Client Authentication EKU from new certificates, reissues, renewals, and duplicates.

What should you do to prepare?

Analyze the use cases of your current SSL/TLS certificates:

Case A

You use your certificates only for HTTPS (web site security)

Recommended action: None.

Tip: review your IT processes to verify that no system or client depends on Client EKU.

Case B

You use your certificates for mTLS (mutual TLS), server-to-server authentication, or other processes

Recommended action: you must take steps before March 2027 to avoid interruptions in service or authentication of your applications.

CertiSur Solutions for organizations that require Client Authentication EKU

If your network architectures or services require Client Authentication, at CertiSur we have alternative solutions outside the scope of public browsers:

X9 PKI Infrastructure for TLS Certificates

Migration to DigiCert's X9 public key infrastructure (managed by the ASC X9 PKI operations and policy teams). It offers a certificate policy independent of public browser requirements, ideal for protecting B2B and multi-organizational communications.

Private Public Key Infrastructure (Private PKI)

Implementation of a dedicated private CA (PKI-as-a-Service) for strictly internal environments and infrastructures of your company, allowing you to define the EKU extensions you require with total control and flexibility.

Public Trust Hierarchies Not Based on Browsers

Transition to DigiCert-specific root hierarchies (such as DigiCert Assured ID G2 RSA or G3 ECC) oriented toward enterprise solutions outside the scope of Chrome/Firefox.

Affected TLS Products

DigiCert

OV: OV Basic, Secure Site OV, Secure Site Pro SSL, Cloud, SSL Standard, SSL Multi-Domain, Wildcard, Secure Site SSL, Secure Site Multi-Domain, Secure Site Wildcard.

EV: EV Basic, Secure Site EV, Secure Site Pro EV SSL, SSL Extended Validation, SSL Multi-Domain EV, Secure Site EV SSL, Secure Site Multi-Domain EV.

EU QWAC: EU Qualified Website Authentication Certificate and PSD2.

GeoTrust

DV: GeoTrust DV, GeoTrust Cloud DV, GeoTrust Standard DV, GeoTrust Wildcard DV.

OV: GeoTrust TrueBusiness ID OV.

EV: GeoTrust TrueBusiness ID EV.

Thawte

DV: Thawte SSL 123 DV.

OV: Thawte SSL Web Server OV.

EV: Thawte SSL Web Server EV.

RapidSSL

DV: RapidSSL Standard DV, RapidSSL Wildcard DV.

Encryption Everywhere

DV: Encryption Everywhere DV.

Do you have questions about how this change affects your systems?

Contact our technical support team or your account executive at CertiSur to help you plan the transition or evaluate the best private PKI alternative for your organization.