Important Notice on Removal of Client Authentication EKU from SSL Certificates Across All Brands
Dear Valued Customers and Partners:
Hello! Thank you for your long-standing trust and support in Racent!
To actively comply with the latest compliance requirements of the Google Chrome Root Certificate Program, all international and domestic Certificate Authorities (CAs) are required to phase out the inclusion of the "Client Authentication Extended Key Usage (Client Authentication EKU)" in publicly trusted TLS/SSL certificates. This adjustment aims to enhance the security and standardization of the global digital trust system and reduce the risk of certificate misuse.
Against this backdrop, major CAs have successively released their final implementation timelines. To help you plan your certificate procurement and deployment strategies in advance and avoid future browser trust issues caused by the presence of this EKU in certificates, we have compiled and announced the specific change arrangements for each brand as follows:
Timeline and Explanation for Removal of Client Authentication EKU from SSL Certificates Across All Brands
| Certificate Brand | Key Effective Date | Specific Implementation Measures | Remarks |
|---|---|---|---|
| DigiCert | March 1, 2027 | Client Authentication EKU will be completely removed from all newly issued public TLS certificates (including new purchases, renewals, and reissues). | Certificates containing this EKU issued before March 1, 2027 will remain trusted during their validity period and will not be affected. |
| Sectigo | Phase 1: October 7, 2025 Phase 2 (Full Discontinuation): February 10, 2027 | Starting from Phase 1, this EKU will no longer be included by default; Starting from Phase 2, this EKU will not be included under any circumstances, meaning the function will be fully discontinued. | During the period between Phase 1 and Phase 2, if you need to use the EKU, you may contact us to apply for activation. If your business strongly relies on this EKU, we recommend completing migration to alternative solutions before the full discontinuation date. |
| GlobalSign | July 27, 2026 | TLS certificates with the EKU function will no longer be issued. | Existing issued certificates will remain trusted until their expiration and will not be affected. |
| Certum | Launch: September 2026 Deadline: End of December 2026 | The EKU will be phased out starting from September 2026, and the issuance of certificates containing the EKU will be fully stopped by the end of December 2026. | It is recommended to stop relying on this function starting from September. |
| CFCA | May 1, 2026 | China Root/China Root Pro SSL certificates will no longer be issued with the EKU. | Guomi (SM cryptography) certificates and standard server certificates are not affected. |
Racent will continuously monitor the policy updates of each CA and keep you informed in a timely manner. If you have any questions, please feel free to contact your account manager at any time. We will wholeheartedly provide you with technical consultation and migration assistance.
Thank you again for your understanding and cooperation!
Best regards,