Source record · tier 2 current vendor documentation
Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway-series/225482-prepare-expressway-for-client.html
- Published
- 2026-02-13
- Updated
- unknown
- Accessed
- 2026-09-30
- HTTP status
- 200
- License
- Cisco documentation; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- Expressway-C needs a certificate with both clientAuth and serverAuth EKUs because it acts as the TLS client on the UC traversal zone. in context
- Cisco technote 225482 gives June 2026 as the full enforcement date of the public-CA client-authentication EKU restriction. disputed in context
- Under the Chrome Root Program policy, public CAs may assert only the Server Authentication EKU on TLS certificates, and Let's Encrypt stopped issuing combined-EKU certificates on 2026-02-11. in context
- Cisco's EKU technote gives 2026-03-15 as the date public TLS certificate validity dropped to 200 days. in context
- Cisco technote 225482 places full enforcement of the Chrome Root Program server-auth-only policy in June 2026, with public CAs stopping Client Authentication EKU issuance in May 2026. disputed in context
- Cisco requires Expressway-E and Expressway-C to be upgraded to the same version (X15.4 or X15.5) for the Client Auth EKU fix. in context
- Before X15.4 Expressway-C validates both Server and Client Authentication EKUs on the certificate Expressway-E presents for the MRA SIP SERVICE exchange, so a server-only EKU certificate on Expressway-E shows up as failed SIP registration. in context
- An MRA deployment still on X14 or X15.0 through X15.3.2 that renews its Expressway-E certificate from a public CA after mid-2026 is likely to see MRA SIP registration fail unless it uses a combined-EKU alternative root or private PKI where allowed. inferred in context
- Expressway X15.4 (February 2026) accepts a Server Authentication EKU-only certificate on Expressway-E for MRA, enabled by xConfiguration XCP TLS Certificate CVS EnableServerEkuUpload: On. in context
Cite this source record
APA
WarmTransfer. (2026, February 13). Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-technote-225482-exwy-client-eku-sunset
BibTeX
@misc{warmtransfer-cisco-technote-225482-exwy-client-eku-sunset,
title = {Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-technote-225482-exwy-client-eku-sunset},
note = {Cisco Systems, accessed 2026-09-30}
}