Second and more importantly: these intermediates do not contain the “TLS Web Client Authentication” Extended Key Usage. This means that these intermediates cannot issue end-entity certificates containing that EKU. As we’ve [already announced](/2025/05/14/ending-tls-client-authentication), we will be phasing out issuance of tlsClientAuth certificates in 2026 due to a root program requirement. Until that time, we will only be using the new hierarchy to issue certificates under the “[tlsserver](https://letsencrypt.org/docs/profiles/#tlsserver)” and “[shortlived](https://letsencrypt.org/docs/profiles/#shortlived)” profiles, which already omit that EKU. After the tlsClientAuth deprecation is complete, we will shift to using the new intermediates for all issuance.
0 commit comments