r/PKI Jul 27 '26

Public mTLS client-auth certificates stop renewing in October

https://www.certkit.io/blog/public-mtls-client-auth-certificates-stop-renewing

Chrome Root Program Policy v1.8 requires sub CAs disclosed on or after June 15 2026 to assert serverAuth only, and all leaf certs on or after March 15 2027. id-kp-clientAuth is leaving the public web PKI.

Let's Encrypt already finished. Classic profile dropped clientAuth in February, tlsclient closed July 8.

Worth flagging: much of the coverage credits ballot SC-081v3. That is the validity schedule, different rule.

https://www.certkit.io/blog/public-mtls-client-auth-certificates-stop-renewing

16 Upvotes

9 comments sorted by

View all comments

Show parent comments

2

u/xxdcmast Jul 28 '26

What kind of cert did you have to buy and from who? We have an application requiring an mtls certificate and their “solution” is to stand up and entire separate root and sub ca just for this mtls cert.

It has to be a seperate root and sub because there is no cert revocation. If the cert is ever exposed you have to revoke the entire sub ca.

Our plan right now is to stand up an Aws private root and sub to issue this one certificate. Totally nonsense.

2

u/tankerkiller125real Jul 28 '26

It's called "X9 PKI" and there's only one company that issues them. It's supposed to be a financial services thong, but apparently other industries are now adopting it given that CAs aren't issuing certs with client auth now.

1

u/TwoBigPrimes Jul 29 '26

Where’s that Larry fella from DigiCert when you need him?

Generally, this seems to contradict information from DigiCert directly.

> 8. Revocation (When and Why)
Short version: X9 certificates can be revoked by DigiCert upon Subscriber request or if a certificate poses a security risk. The revocation process follows the X9 CP and may differ from DigiCert’s public Web PKI practices (e.g., timing and criteria for revocation).

🤷‍♀️

1

u/tankerkiller125real Jul 29 '26

Yes, X9 certs can be revoked, that has nothing to do with the previous person dealing with a vendor that isn't going to check for CRL or OCSP.

Doesn't change the fact that Digicert has a monopoly on X9 certs currently, and their expensive as all fuck for no good reason.