Menu
picture of tbs certificates
picture of tbs certificates
Certificates
Our products range
Partners
Support
Focus


20260410 - Chain change for TBS X509 server certificates

From May 1 , 2026, TBS X509 server certificates will be issued on a new intermediary.

Certificates in RSA format will be issued on the TBS RSA Organization Validation Secure Server CA 4, replacing TBS RSA Organization Validation Secure Server CA 3.

Certificates in ECC format will be issued on the TBS ECC Organization Validation Secure Server CA 4, replacing TBS ECC Organization Validation Secure Server CA 3.

What are the consequences?

Certificates issued on the new intermediary will be issued without the client EKU, to comply with the deprecation of the client EKU of SSL certificates.

Similarly, this will impact the recognition of your SSL certificates by browsers and mobile tools.

What impact will this have on pending orders?

Certificates requested before May 1 , 2026 can be delivered on the old intermediary until May 15.

Certificates requested from May 1 , 2026 or not delivered by May 15 will be issued on the new intermediary.

What impact will this have on existing certificates?

None. These certificates will continue to function normally until their expiration date.

However, if a reissue is performed after the deadline, the new certificate will be issued on the new intermediary.

Useful links