The End of Client Authentication in Public SSL Certificates. What Changes in 2026 and How to Prepare?
For years, Client Authentication (mTLS) has been implemented using public SSL/TLS certificates issued by publicly trusted certification authorities. This model worked because server certificates could include both Server Authentication and Client Authentication (EKU), and browsers and operating systems accepted such a dual-use scenario.