Starting May 2026, major public Certificate Authorities (CAs) including Let's Encrypt, DigiCert, Sectigo, and GlobalSign will stop including the Client Authentication Extended Key Usage (EKU) in publicly issued TLS certificates. This affects any deployment using mutual TLS (mTLS) with public-CA-issued client certificates —

9m read timeFrom news.apache.org
Post cover image
Table of contents
What Apache Software Deployers Need to Know Before May 2026When Industry Standards Shift Beneath Your FeetThe Common Failure Mode Across Apache DeploymentsWhat Will Break and WhenHow to Know If You’re AffectedHow to check your certificatesThree Proven Paths ForwardWhat You Should Do NowA Moment for the EcosystemWhere to Get Help

Sort: