Client authentication EKU changes in public TLS certificate

Simon O'Hara 60 Reputation points
2025-09-23T14:09:16.8166667+00:00

Client authentication EKU changes in public TLS certificate

Hi,

Can someone clarify the upcoming change to remove the client authentication EKU and the conflicting information within MS docs for Teams Direct Routing certificates?

As stated here from October 2025 there is an industry wide change to remove the client authentication EKU from issued TLS certificates:

https://knowledge.digicert.com/alerts/sunsetting-client-authentication-eku-from-digicert-public-tls-certificates

However, both server and client EKU's are required for mTLS and Microsoft states here that both server and client EKU's are required: https://learn.microsoft.com/en-us/microsoftteams/direct-routing-whats-new#sbc-certificates-eku-extensions-test

Digicert are offering an X9 PKI that includes both server and client EKU's but it seems the signing CA is not trusted by Microsoft at this stage.

What guidance are Microsoft offering with this upcoming change to ensure that customers are not affected when renewing their certificates?

Microsoft Teams | Microsoft Teams for business | Meetings and calls | Audio and video
0 comments No comments

1 answer

Sort by: Oldest
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.