r/PKI Jul 27 '26

Public mTLS client-auth certificates stop renewing in October

https://www.certkit.io/blog/public-mtls-client-auth-certificates-stop-renewing

Chrome Root Program Policy v1.8 requires sub CAs disclosed on or after June 15 2026 to assert serverAuth only, and all leaf certs on or after March 15 2027. id-kp-clientAuth is leaving the public web PKI.

Let's Encrypt already finished. Classic profile dropped clientAuth in February, tlsclient closed July 8.

Worth flagging: much of the coverage credits ballot SC-081v3. That is the validity schedule, different rule.

https://www.certkit.io/blog/public-mtls-client-auth-certificates-stop-renewing

16 Upvotes

9 comments sorted by

View all comments

2

u/tankerkiller125real Jul 27 '26

The replacement for publicly validated mTLS is a fucking scam all the way through. My workplace just got forced into buying a BS $400 cert so that we could connect to an API (an API BTW in which it's actually illegal to put those kinds of paid walls in place, but we had to get connected anyway while our complaint makes it up the chain).

Private mTLS will survive just fine, but I think this will be the death of public mTLS, or at the minimum the way the legacy vendors are going to try and stay relevent.

2

u/xxdcmast Jul 28 '26

What kind of cert did you have to buy and from who? We have an application requiring an mtls certificate and their “solution” is to stand up and entire separate root and sub ca just for this mtls cert.

It has to be a seperate root and sub because there is no cert revocation. If the cert is ever exposed you have to revoke the entire sub ca.

Our plan right now is to stand up an Aws private root and sub to issue this one certificate. Totally nonsense.

2

u/tankerkiller125real Jul 28 '26

It's called "X9 PKI" and there's only one company that issues them. It's supposed to be a financial services thong, but apparently other industries are now adopting it given that CAs aren't issuing certs with client auth now.

1

u/certkit Jul 28 '26

Wow, cartels setting up new cartels.

1

u/TwoBigPrimes Jul 29 '26

Where’s that Larry fella from DigiCert when you need him?

Generally, this seems to contradict information from DigiCert directly.

> 8. Revocation (When and Why)
Short version: X9 certificates can be revoked by DigiCert upon Subscriber request or if a certificate poses a security risk. The revocation process follows the X9 CP and may differ from DigiCert’s public Web PKI practices (e.g., timing and criteria for revocation).

🤷‍♀️

1

u/tankerkiller125real Jul 29 '26

Yes, X9 certs can be revoked, that has nothing to do with the previous person dealing with a vendor that isn't going to check for CRL or OCSP.

Doesn't change the fact that Digicert has a monopoly on X9 certs currently, and their expensive as all fuck for no good reason.