For years, Client Authentication (mTLS) has been implemented using public SSL/TLS certificates issued by publicly trusted certification authorities. This model worked because server certificates could include both Server Authentication and Client Authentication (EKU), and browsers and operating systems accepted such a dual-use scenario.
This model is now coming to an end.
Under new root program rules, particularly those of the Chrome Root Program, public TLS is intended solely for server authentication, not client authentication. As a result, major public certificate authorities have begun phasing out Client Authentication support in public certificates.
For many organizations, this creates a real risk of silent mTLS failures during automated certificate renewals.
Table of Contents
ToggleDigiCert
Sectigo
These changes are not isolated decisions by individual CAs, but a direct consequence of root program policies, including browser requirements.
In many environments, mTLS based on public certificates has been operating for years without being redesigned. Typical examples include:
In such scenarios, renewing a certificate without Client EKU results in:
Importantly, the change may occur silently if the renewal process is fully automated.
If you currently rely on public TLS for Client Authentication, your time window is limited.
DigiCert
Sectigo
It must be clearly stated that this only postpones the problem, rather than solving it.
For B2B, financial, and regulated environments, the correct direction is PKI outside browser root programs.
DigiCert X9 PKI for TLS
For internal and hybrid environments:
This is currently the recommended model for:
Regardless of the chosen model, certificate visibility is critical. Tools such as DigiCert Trust Lifecycle Manager enable organizations to:
A lack of certificate inventory is one of the most common sources of operational incidents today.
The removal of Client Authentication from public SSL/TLS certificates is not a temporary policy shift, but a permanent transformation of the Internet trust model. Organizations that continue to rely on public SSL for mTLS must make architectural decisions in 2026 to avoid outages and security incidents.
We recommend treating this moment as an opportunity to clean up PKI, improve visibility, and implement a modern trust model rather than applying another temporary workaround.
If you need support with audits, migration, or selecting the right PKI model, our team remains at your disposal.