cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3686
Views
2
Helpful
4
Comments
DuoKristina
Cisco Employee
Cisco Employee

This is a reminder that Duo’s existing CA bundle will expire on April 15, 2026 due to the the Mozilla CA distrust policy. This expiration will affect all Duo products that use certificate pinning. This service change affects all Duo customers and deployments. Once the CA root is distrusted, it can no longer be used to establish trust and secure communication with Duo’s systems. Duo cannot change or extend the Mozilla CA distrust date.

Duo will impose a staged soft cutoff of clients which include the expiring CA bundle on February 2, 2026 so we can manage disruptions and provide support. 

We will follow that with a managed hard cutoff of clients which include the expiring CA bundle on March 31, 2026

To avoid interrupted communications to Duo's cloud service you must update all affected applications and clients that connect to Duo’s servers to a compatible version with the latest CA bundle version by February 2, 2026. 

Please review the article How can I make sure I am up to date with Duo's latest applications in time for the Duo root certificate authority bundle replacement? for detailed information and guidance, such as... 

  • Why this is happening. 
  • Which products are affected or unaffected. 
  • How to identify your affected clients and applications. 
  • Update recommendations for affected Duo products. 
  • Who to contact about Duo integrations from third-party software vendors. 

Questions?  

Managed Service Providers may contact their MSP Partner Manager (PM) for additional details, such as the list of affected sub-accounts. 

All other customers may contact Duo Support with any questions after reviewing the guidance in the linked knowledge base article. 

Comments
DuoKristina
Cisco Employee
Cisco Employee

Updated post to include the March 31 hard cutoff information.

Gigawatt
Level 1
Level 1

Not sure if anyone else is encountering this, but we run the OnPrem version of Delinea Secret Server and is flagged on the Duo unsupported client's since it's running "DuoAPICSharp/1.0 (Microsoft Windows NT 10.0.14393.0; .NET 4.0.30319.42000)". 

We've reached out to Delina support and state that Secret Server does not require any upgrade or configuration changes for this -  https://docs.delinea.com/online-help/secret-server/authentication/two-factor-authentication/duo-security-authentication/index.htm#DuoSecurityAuthentication 

Fingers crossed

hawley35
Level 1
Level 1

@Gigawatt

I ask the same question of Delinea support, and got the same answer, but no reference to that link. Thanks. 

DuoKristina
Cisco Employee
Cisco Employee

Our technical partners team has also been in direct contact with Delinea about both of their Duo 2FA integrations. This article dedicated to third-party integration status notes our last update. When we have an official answer from them that article will be updated (we have some unanswered questions).

If you have anything showing up in your Unsupported Clients Log report in the Duo Admin Panel it's a good idea to submit an extension request ahead of the Feb 2 soft cutoff date. Since their client sends a useragent known to be affected it could still get blocked without the extension, even if they modified our open-source client to remove cert pinning.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Quick Links