Source note · Troubleshooting Expressway Mobile and Remote Access
An MRA deployment still on X14 or X15.0 through X15.3.2 that renews its Expressway-E certificate from a public CA after mid-2026 is likely to see MRA SIP registration fail unless it uses a combined-EKU alternative root or private PKI where allowed.
inferred · Checked 2026-10-01
- Vendor
- Cisco
- Product
- Cisco Expressway
- Subsystem
- certificates
- Deployment
- on-premises
- Region
- not restricted
- Release range
- X14 through X15.3.2
- Status
- inferred
- Checked
- 2026-10-01
Sources
- Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates — Cisco Systems · tier 2 current vendor documentation · How MRA ... Are Impacted; Workarounds
Cite this note
APA
WarmTransfer. (2026, October 1). Troubleshooting Expressway Mobile and Remote Access: source note expressway-mra-troubleshooting-eku-renewed-cert-risk. WarmTransfer. https://warmtransfer.net/knowledge/claims/expressway-mra-troubleshooting-eku-renewed-cert-risk
BibTeX
@misc{warmtransfer-claim-expressway-mra-troubleshooting-eku-renewed-cert-risk,
title = {Troubleshooting Expressway Mobile and Remote Access: source note expressway-mra-troubleshooting-eku-renewed-cert-risk},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/expressway-mra-troubleshooting-eku-renewed-cert-risk},
note = {Source note expressway-mra-troubleshooting-eku-renewed-cert-risk, checked 2026-10-01}
}