Source note · Setting up certificates on Cisco Expressway
One Cisco workaround is to switch to public CAs that still issue certificates carrying both clientAuth and serverAuth EKUs from alternative roots, naming DigiCert and IdenTrust.
Checked 2026-09-30
- Vendor
- Cisco
- Product
- Cisco Expressway
- Subsystem
- eku
- Deployment
- on-premises
- Region
- not restricted
- Release range
- time-limited; as of 2026-06-01
- Checked
- 2026-09-30
Sources
- Field Notice: FN74362 - Cisco Expressway: Impact on Secure Communication due to Upcoming Changes to TLS Certificates Issued by Public Certificate Authorities with Client Authentication EKU, Starting May 2026 - Workaround Provided — Cisco Systems · tier 2 current vendor documentation · Workaround/Solution > Option 1
Cite this note
APA
WarmTransfer. (2026, September 30). Setting up certificates on Cisco Expressway: source note expressway-certificate-setup-eku-combined-roots. WarmTransfer. https://warmtransfer.net/knowledge/claims/expressway-certificate-setup-eku-combined-roots
BibTeX
@misc{warmtransfer-claim-expressway-certificate-setup-eku-combined-roots,
title = {Setting up certificates on Cisco Expressway: source note expressway-certificate-setup-eku-combined-roots},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/expressway-certificate-setup-eku-combined-roots},
note = {Source note expressway-certificate-setup-eku-combined-roots, checked 2026-09-30}
}