20250516 - Deprecation of the Client Authentication EKU (Extended Key Usage) for SSL Certificates
Starting February 15, 2027, Google Chrome will no longer recognize server SSL certificates that include a "Client Authentication" EKU. Only the "Server Authentication" EKU will be accepted.
What is an EKU?
An EKU, or Extended Key Usage, is an extension that specifies the uses that can be made of a certificate.
A certificate can combine several uses, such as authentication, signing, or encryption. The value of its EKU will then determine which applications or purposes the certificate can be used for.
Why this change?
Google, through its Chrome root policy, has introduced new security requirements prohibiting the inclusion of the client authentication EKU in public SSL/TLS certificates. These changes aim to better regulate certificate use and improve the security of the ecosystem.
What's Changing
Until now, most server certificates were issued with an EKU of "TLS Web Server Authentication" and "TLS Web Client Authentication." They will then be issued with only "TLS Web Server Authentication."
Timeline
- April 8, 2025: Sectigo will cease to include the "Client Authentication" EKU in QWAC SSL/TLS certificates.
- September 15, 2025: Sectigo will cease including the "Client Authentication" EKU by default in SSL/TLS certificates. It will still be possible to obtain a certificate including this field under certain conditions.
- October 1 , 2025: DigiCert will cease including the "Client Authentication" EKU in SSL/TLS certificates. It will still be possible to obtain a certificate including this field under certain conditions until February 28, 2027 (contact us if needed).
- May 1 , 2026: TBS X509 SSL/TLS certificates will no longer include the "Client Authentication" EKU.
- May 15, 2026: Sectigo will no longer include the "Client Authentication" EKU in new SSL/TLS certificates.
- June 15, 2026: Chrome will stop accepting server certificates issued after June 15, 2026, that include the "Client Authentication" EKU.
NOTE: Sectigo SSL/TLS and QWAC certificates issued via TBS will continue to have the EKU "Client Authentication" field until February 10, 2027.
What are the consequences?
If your tools require this extension, you will need to switch to another product.
QWAC Certificates
What impact will this have on existing certificates?
None. These certificates will continue to function normally until their expiration date.
However, if a reissue is performed after the deadline, the new certificate will be issued with only the "TLS Web Server Authentication" EKU.


