Let's Encrypt Dropping TLS Client Authentication EKU

2025-05-18
Let's Encrypt Dropping TLS Client Authentication EKU

Let's Encrypt will remove the "TLS Client Authentication" Extended Key Usage (EKU) from its certificates starting in 2026. This primarily affects clients using Let's Encrypt certificates for server authentication. A phased rollout using ACME profiles will minimize disruption. Most website users won't need to take action. The change is driven by Google Chrome's root program requirements and the increasing suitability of private CAs for client authentication.