Main section

14.09.2026

TLS/SSL Client Authentication: update on new certificate profiles

Google Chrome will no longer accept the Client Authentication use case (EKU clientAuth) in publicly trusted TLS/SSL certificates. The corresponding deadline remains unchanged at 15 March 2027.

What is changing:

  • SwissSign is introducing new ICA and leaf policies that will only include the purpose "Server Authentication" going forward.
  • For MPKI customers, the introduction of the new certificate profiles is currently planned for the end of September 2026.
  • The existing policies with clientAuth and serverAuth are expected to be replaced by the end of January 2027.

 

What you need to do:

  • Check whether your active publicly trusted TLS/SSL certificates contain the “Client Authentication” EKU.
  • Plan the migration early and replace affected certificates with suitable alternatives by the end of January 2027 at the latest.
  • Certificates in private PKI environments are not affected by this change.
  • S/MIME certificates or private PKI certificates can be used as an alternative depending on the use case.

 

Resources: You can find more information in our blog post: TLS/SSL Client Authentication: what is changing

Your SwissSign team