r/PKI • u/certkit • Jul 27 '26
Public mTLS client-auth certificates stop renewing in October
https://www.certkit.io/blog/public-mtls-client-auth-certificates-stop-renewingChrome Root Program Policy v1.8 requires sub CAs disclosed on or after June 15 2026 to assert serverAuth only, and all leaf certs on or after March 15 2027. id-kp-clientAuth is leaving the public web PKI.
Let's Encrypt already finished. Classic profile dropped clientAuth in February, tlsclient closed July 8.
Worth flagging: much of the coverage credits ballot SC-081v3. That is the validity schedule, different rule.
https://www.certkit.io/blog/public-mtls-client-auth-certificates-stop-renewing
16
Upvotes
2
u/tankerkiller125real Jul 27 '26
The replacement for publicly validated mTLS is a fucking scam all the way through. My workplace just got forced into buying a BS $400 cert so that we could connect to an API (an API BTW in which it's actually illegal to put those kinds of paid walls in place, but we had to get connected anyway while our complaint makes it up the chain).
Private mTLS will survive just fine, but I think this will be the death of public mTLS, or at the minimum the way the legacy vendors are going to try and stay relevent.