Feisty Duck
Read post

Web PKI Ditches TLS Client Authentication

Chrome's root store policy now requires dedicated CA hierarchies exclusively for TLS server authentication, ending support for client authentication, S/MIME, and code signing by June 2026. Major CAs like DigiCert and Sectigo have already stopped issuing multipurpose certificates. While this strengthens Web PKI security by preventing cross-purpose certificate misuse, it creates challenges for mTLS use cases and threatens Certificate Transparency coverage as new Internet PKI hierarchies emerge without CT requirements. The change highlights the need for a comprehensive public root program that can enforce CT and security standards across all PKI use cases beyond just browser traffic.

    #google-chrome#pki#security
Oct 30, 2025•6m read time•From feistyduck.com
Post cover image
Table of contents
Red Sift's Guide to Certificate Lifecycle ManagementShort News
708 Impressions
Feisty Duck's image
Feisty Duck

Piccalilli's resource offers insights, tutorials, and resources for frontend developers and web desi...

4 Followers

•

12 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard