Main section
TLS/SSL Client Authentication: update on new certificate profiles
Google Chrome will no longer accept the Client Authentication use case (EKU clientAuth) in publicly trusted TLS/SSL certificates. The corresponding deadline remains unchanged at 15 March 2027.
What is changing:
- SwissSign is introducing new ICA and leaf policies that will only include the purpose "Server Authentication" going forward.
- For MPKI customers, the introduction of the new certificate profiles is currently planned for the end of September 2026.
- The existing policies with clientAuth and serverAuth are expected to be replaced by the end of January 2027.
What you need to do:
- Check whether your active publicly trusted TLS/SSL certificates contain the “Client Authentication” EKU.
- Plan the migration early and replace affected certificates with suitable alternatives by the end of January 2027 at the latest.
- Certificates in private PKI environments are not affected by this change.
- S/MIME certificates or private PKI certificates can be used as an alternative depending on the use case.
Resources: You can find more information in our blog post: TLS/SSL Client Authentication: what is changing
Your SwissSign team