{"id":16738,"date":"2026-02-17T13:30:36","date_gmt":"2026-02-17T13:30:36","guid":{"rendered":"https:\/\/dmsretail.com\/RetailNews\/changes-to-tls-clientauth-certificates-ensuring-youre-not-impacted\/"},"modified":"2026-02-17T13:30:36","modified_gmt":"2026-02-17T13:30:36","slug":"changes-to-tls-clientauth-certificates-ensuring-youre-not-impacted","status":"publish","type":"post","link":"https:\/\/dmsretail.com\/RetailNews\/changes-to-tls-clientauth-certificates-ensuring-youre-not-impacted\/","title":{"rendered":"Changes to TLS clientAuth Certificates: Ensuring You\u2019re Not Impacted"},"content":{"rendered":"<p> <p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/>\n<\/p>\n<div>\n<p>Cisco customers and partners\u00a0who use\u00a0Cisco equipment and services must be aware of important upcoming changes to public TLS certificates used for client authentication,\u00a0driven by browser security policies such as those from Google Chrome. These changes affect certificates\u00a0containing\u00a0the Client Authentication Extended Key Usage (EKU) and require careful management of certificate trust stores to avoid service disruptions.<\/p>\n<p>This article explains the changes, the role of trust stores, how to verify and update them, and steps to ensure your systems\u00a0remain\u00a0secure and operational.<\/p>\n<p><strong>Important Note:<\/strong>\u00a0This does NOT affect certificates that are issued by private PKI.<\/p>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-7b3ec710f86dd480bde2727b73899cca\" id=\"h-what-is-extended-key-usage-eku-and-why-it-matters\" style=\"font-style:normal;font-weight:400\">What is Extended Key Usage (EKU) and Why It Matters<\/h2>\n<p>Extended Key Usage (EKU) defines the specific purposes for which a digital certificate can be used. Two\u00a0common\u00a0EKUs in TLS certificates are:<\/p>\n<ul class=\"wp-block-list\">\n<li>Server Authentication (OID 1.3.6.1.5.5.7.3.1):\u202fThis EKU verifies a server\u2019s identity to clients, enabling secure HTTPS connections.<\/li>\n<li>Client Authentication (OID 1.3.6.1.5.5.7.3.2):\u202fThis EKU verifies a client\u2019s identity to a server, which is essential for mutual TLS (mTLS) where both parties authenticate each other.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-547c7decbe8954da572d453479f2219c\" id=\"h-changes-to-public-tls-certificates\" style=\"font-style:normal;font-weight:400\">Changes to Public TLS Certificates<\/h2>\n<p>The\u00a0change,\u00a0to disallow public TLS certificates\u00a0from containing the\u00a0<strong>clientAuth<\/strong>\u00a0EKUs, was\u00a0initiated\u00a0by\u00a0Google Chrome\u2019s root store program\u00a0policies. This may work fine within the boundaries of\u00a0web-browsing.\u00a0\u00a0However,\u00a0Cisco\u2019s ecosystem\u00a0has different security requirements which include\u00a0trusting\u00a0root certificates for its services and equipment to securely authenticate\u00a0both\u00a0clients and servers.<\/p>\n<p>Important facts:<\/p>\n<ul class=\"wp-block-list\">\n<li>From\u202f<strong>June 15, 2026<\/strong>, public Certificate Authorities (CAs)\u00a0within Google Chrome\u2019s root store\u00a0will stop issuing TLS certificates\u00a0containing\u00a0both\u00a0serverAuth\u00a0and\u00a0clientAuth\u00a0EKUs.<\/li>\n<li>Certificates issued before this date remain valid until\u00a0their\u00a0expiration, even beyond June 15, 2026.<\/li>\n<li>Cisco\u2019s publicly\u00a0accessible Trusted\u00a0Root\u00a0Store bundles will include Root CAs needed for\u00a0clientAuth\u00a0validation.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-b3ad3d23da1408bbddb4072c5f2e2164\" id=\"h-certificate-authority-ca-and-eku-mapping-for-cisco-services\" style=\"font-style:normal;font-weight:400\">Certificate Authority (CA) and EKU Mapping for Cisco Services<\/h2>\n<p>If\u00a0Cisco customers\u00a0and partners are currently\u00a0utilizing\u00a0the\u00a0clientAuth\u00a0EKU in certificates, then it is important\u00a0to verify that\u00a0the\u00a0trust store includes\u00a0Root CAs\u00a0that will continue to include the\u00a0clientAuth\u00a0EKU.\u00a0<\/p>\n<p>Cisco manages its own publicly\u00a0accessible Trusted\u00a0Root\u00a0Store\u00a0<strong>bundles<\/strong>\u00a0tailored for\u00a0various types\u00a0of services. These bundles include the necessary Root CAs to\u00a0validate\u00a0certificates used in Cisco services, ensuring secure mutual authentication while aligning with browser root store policies.<\/p>\n<p>Click here for more information on Cisco\u2019s Trusted Root Stores\u00a0<\/p>\n<p>Using\u00a0IdenTrust\u00a0and\u00a0Digicert\u00a0as examples, you can see how the industry is shifting from using the \u201cIdenTrust\u00a0Commercial Root CA 1\u201d and \u201cDigicert\u00a0Global Root G2\u201d towards different Root and Issuing\/Sub CAs.\u00a0\u00a0This is because the\u00a0aforementioned Root CAs\u00a0will remain in the Google Chrome root stores, where they are no longer allowed to issue certificates that\u00a0contain\u00a0the\u00a0clientAuth\u00a0EKU.<\/p>\n<figure class=\"wp-block-table is-style-regular has-small-font-size\">\n<table>\n<tbody>\n<tr>\n<td><strong>Solution\u00a0<\/strong><\/td>\n<td><strong>EKU Type<\/strong>\u00a0<\/td>\n<td><strong>Root CA\u00a0<\/strong><\/td>\n<td><strong>Issuing\/Sub CA\u00a0<\/strong><\/td>\n<\/tr>\n<tr>\n<td>IdenTrust\u00a0<\/td>\n<td>clientAuth\u00a0<\/td>\n<td>IdenTrust\u00a0Public Sector Root CA 1*\u00a0<\/td>\n<td>TrustID\u00a0RSA\u00a0ClientAuth\u00a0CA 2\u00a0<\/td>\n<\/tr>\n<tr>\n<td>IdenTrust\u00a0<\/td>\n<td>clientAuth\u00a0+\u00a0serverAuth\u00a0<\/td>\n<td>IdenTrust\u00a0Public Sector Root CA 1*\u00a0<\/td>\n<td>IdenTrust\u00a0Public Sector Server CA 1\u00a0<\/td>\n<\/tr>\n<tr>\n<td>IdenTrust\u00a0<\/td>\n<td>serverAuth\u00a0(browser trusted)\u00a0<\/td>\n<td>IdenTrust\u00a0Commercial Root CA 1\u00a0<\/td>\n<td>HydrantID\u00a0Server CA O1\u00a0<\/td>\n<\/tr>\n<tr>\n<td>DigiCert\u00a0<\/td>\n<td>clientAuth\u00a0<\/td>\n<td>DigiCert Assured ID Root G2*\u00a0<\/td>\n<td>DigiCert Assured ID Client CA G2\u00a0<\/td>\n<\/tr>\n<tr>\n<td>DigiCert\u00a0<\/td>\n<td>clientAuth\u00a0+\u00a0serverAuth\u00a0<\/td>\n<td>DigiCert Assured ID Root G2*\u00a0<\/td>\n<td>DigiCert Assured ID CA G2\u00a0<\/td>\n<\/tr>\n<tr>\n<td>DigiCert\u00a0<\/td>\n<td>serverAuth\u00a0(browser trusted)\u00a0<\/td>\n<td>DigiCert Global Root G2\u00a0<\/td>\n<td>DigiCert Global G2 TLS RSA SHA256\u00a0<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>This example illustrates the drive towards new Root CAs for\u00a0clientAuth\u00a0needs and the importance of verifying that your services trust them\u00a0in order to\u00a0successfully make TLS connections.\u00a0\u00a0<\/p>\n<p><strong>Note:<\/strong>\u00a0The\u00a0above\u00a0Root CAs are\u00a0all\u00a0included in Cisco\u2019s\u00a0Trusted\u00a0Root\u00a0Store bundles.\u00a0<\/p>\n<p>For more details, see Cisco\u2019s trusted root store bundles:\u00a0<br \/>Cisco Trusted Root Store Bundles Readme<\/p>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-609182fc893b6dba72b0b1a43a6d6713\" id=\"h-understanding-trust-stores-and-their-importance\" style=\"font-style:normal;font-weight:400\">Understanding Trust Stores and Their Importance<\/h2>\n<p>A\u00a0<strong>trust store<\/strong>\u00a0is a collection of trusted Root CA certificates that your systems use to\u00a0validate\u00a0TLS certificates. To avoid disruptions:<\/p>\n<ul class=\"wp-block-list\">\n<li>Ensure your\u00a0systems\u2019\u00a0trust stores include the correct Root CAs\u00a0like those\u00a0listed above.<\/li>\n<li>Regularly update trust stores to align with Cisco\u2019s publicly available bundles.<\/li>\n<li>Missing or outdated Root CAs in trust stores can cause certificate validation failures.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-d94ab5701d22af31db3195f42be63150\" id=\"h-how-to-verify-what-is-in-your-trust-store\" style=\"font-style:normal;font-weight:400\">How to Verify What Is in Your Trust Store<\/h2>\n<p><strong>General Verification Steps<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li>Identify\u00a0the trust store location used by your system or application.<\/li>\n<li>Use tools such as\u202fKeytool\u202f(Java),\u202fOpenSSL, or platform-specific utilities to list certificates in the trust store.<\/li>\n<li>Confirm that the\u00a0new\u00a0Root CAs\u00a0you will\u00a0utilize\u00a0for\u00a0clientAuth\u00a0needs\u00a0(e.g.,\u00a0IdenTrust\u00a0Public Sector Root CA 1, DigiCert Assured ID Root G2) are present.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-be49c56782282805f7fabbbb4c457dbf\" id=\"h-how-to-ensure-you-are-not-impacted\" style=\"font-style:normal;font-weight:400\">How to Ensure You Are Not Impacted<\/h2>\n<ol class=\"wp-block-list\">\n<li><strong>Audit Your Current Certificates and Trust Stores<\/strong>\u00a0<br \/>Inventory all public TLS certificates, especially those used for\u00a0mTLS, and verify the EKUs they\u00a0contain. Confirm that your trust stores include the correct Root CAs.\u00a0\u00a0Contact your Certificate Authority partner (Digicert,\u00a0IdenTrust,\u00a0Sectigo, etc) to ensure you understand which Root CA\u00a0to trust\u00a0for\u00a0clientAuth.<\/li>\n<li><strong>Update Trust Stores Regularly<\/strong>\u00a0<br \/>Align your trust stores with Cisco\u2019s publicly available trusted root store bundles.<\/li>\n<li><strong>Add Missing Root CAs to Trust Stores<\/strong>\u00a0<br \/>If a required Root CA is missing, import it into your trust store.<\/li>\n<li><strong>Coordinate with Partners<\/strong>\u00a0<br \/>Communicate with external partners to ensure their certificates and trust stores\u00a0comply with\u00a0the new standards.<\/li>\n<li><strong>Monitor Browser and CA Policy Changes<\/strong>\u00a0<br \/>Stay informed about browser policies (e.g., Google Chrome) that enforce these changes\u00a0and\u00a0website\u00a0of your chosen Certificate Authority partner.<\/li>\n<li><strong>Test<\/strong>\u00a0<br \/>Utilizing new CAs requires testing on both the Server and Client sides to ensure the new certificates are trusted.<\/li>\n<\/ol>\n<p>By auditing your certificates and trust stores now and aligning with Cisco\u2019s trusted root store bundles, you can ensure your Cisco services and equipment continue to\u00a0operate\u00a0securely and without interruption.\u00a0\u00a0We encourage impacted organizations to\u202freview their current certificate usage\u202fand begin planning their migration well ahead of the deadlines.<\/p>\n<p><strong>Reference Document Links:<\/strong>\u00a0<\/p>\n<ol class=\"wp-block-list\">\n<li>CUCM Certificate Management and Change Notification \u2013 Cisco<\/li>\n<li>Security Guide for Cisco Unified Communications Manager, Release 15 and SUs \u2013 Default Security<\/li>\n<li>Secure Network Analytics SSL\/TLS Certificates Guide for Managed Appliances v7.5.3\u00a0<\/li>\n<\/ol>\n<hr class=\"wp-block-separator has-text-color has-light-gray-color has-alpha-channel-opacity has-light-gray-background-color has-background\"\/>\n<p class=\"has-text-align-center\" id=\"block-a1b11bef-8542-478b-95c4-6b43d582001b\"><em>We\u2019d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.<\/em><\/p>\n<p class=\"has-text-align-center\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cisco-green-color\">Cisco Security Social Media<\/mark><\/strong><\/p>\n<p class=\"has-text-align-center\" id=\"block-85b5e58a-7e0a-4b88-a1bd-54a5f658e51f\">LinkedIn<br \/>Facebook<br \/>Instagram<br \/><a href=\"https:\/\/twitter.com\/CiscoSecure\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a><\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script async defer src=\"https:\/\/platform.instagram.com\/en_US\/embeds.js\"><\/script><br \/>\n<br \/><p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cisco customers and partners\u00a0who use\u00a0Cisco equipment and services must be aware of important upcoming changes to public TLS certificates used for client authentication,\u00a0driven by browser [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":16739,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-16738","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/16738","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/comments?post=16738"}],"version-history":[{"count":0,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/16738\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media\/16739"}],"wp:attachment":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media?parent=16738"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/categories?post=16738"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/tags?post=16738"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}