I just received my first publicly signed certificate that does not include the client authentication key usage. Apparently this is an industry change happening: https://www.sectigo.com/resource-library/tls-client-authentication-public-ca-end-2026#...