Source record · tier 2 current vendor documentation
Field Notice: FN74362 - Cisco Expressway: Impact on Secure Communication due to Upcoming Changes to TLS Certificates Issued by Public Certificate Authorities with Client Authentication EKU, Starting May 2026 - Workaround Provided
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/support/docs/field-notices/743/fn74362.html
- Published
- 2026-06-01
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- Cisco copyright; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- Field notice FN74362 lists Expressway X14.0.0 through X14.3.7 and X15.0.0 through X15.3.2 as affected by public CAs sunsetting the Client Authentication EKU. in context
- FN74362 says the Chrome Root Program will restrict roots in the Chrome Root Store to Server Authentication EKU only from March 2027. in context
- Under FN74362, X15.4 lets Expressway-E take an upload of a Server-Authentication-only EKU certificate. X15.5 adds a UI that separates client and server certificates and options to turn off EKU checking. in context
- FN74362 says public CAs stop issuing certificates that combine Server and Client Authentication EKUs from May 2026. Expressway mTLS connections expect both EKUs. in context
- FN74362 says Expressway-E and Expressway-C must both be upgraded to the same fixed version. in context
- FN74362 offers three workarounds: switch to a CA that still issues combined-EKU certificates, renew existing combined-EKU certificates before the sunset, or move to a private PKI (Expressway-C only). in context
- Field notice FN74362 lists the UC traversal zone (where Expressway-C presents a Client Authentication EKU) and MRA Onboarding cloud connections as affected by public CAs dropping Client Authentication EKU on releases X14.0.0 through X15.3.2. in context
- FN74362 gives X15.4 as an interim fix allowing a ServerAuth-only certificate upload on Expressway-E and X15.5 as the solution separating client and server certificates, with Expressway-E and -C on the same version; a private CA for Expressway-C is a workaround. in context
Cite this source record
APA
WarmTransfer. (2026, June 1). Field Notice: FN74362 - Cisco Expressway: Impact on Secure Communication due to Upcoming Changes to TLS Certificates Issued by Public Certificate Authorities with Client Authentication EKU, Starting May 2026 - Workaround Provided. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-fn74362-expressway-client-eku
BibTeX
@misc{warmtransfer-cisco-fn74362-expressway-client-eku,
title = {Field Notice: FN74362 - Cisco Expressway: Impact on Secure Communication due to Upcoming Changes to TLS Certificates Issued by Public Certificate Authorities with Client Authentication EKU, Starting May 2026 - Workaround Provided},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-fn74362-expressway-client-eku},
note = {Cisco Systems, accessed 2026-09-24}
}