cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3531
Views
17
Helpful
30
Replies

Public certs removing client authentication breaking Expressway

mhurley131
Level 4
Level 4

I just received my first publicly signed certificate that does not include the client authentication key usage.    Apparently this is an industry change happening:

https://www.sectigo.com/resource-library/tls-client-authentication-public-ca-end-2026#:~:text=Sectigo%20announced%20that%20starting%20September,no%20exceptions%20will%20be%20granted.

Expressway requires this attribute for the mutual authentication between C & E, and will not accept the certificate.

mhurley131_0-1761307327517.png

If we use a certificate signed by a private certificate, non-IT controlled devices will get a warning and/or fail when trying to use MRA.   Also, my understanding is that physical phones have a trust list which can not be added to, so they will stop working.

Is Cisco aware of this change and is there a recommended path forward?

 

30 Replies 30

samuel.gay
Level 1
Level 1

FYI I just renew a certificate with Digicert. I confirm that is still possible to get a certificate with EKU server and client authentication, you just need to configure it in the settings first:

samuelgay_0-1764176700406.png