mTLS, mutual TLS, or server-to-server authentication deprecation of Sectigo

Michel Admiraal 0 Reputation points
2025-03-21T10:05:14.8666667+00:00

I recently got an email from Sectigo that they are going to remove mTLS or server-to-server authentication from their certificates. I checked and this would impact the Exchange online Hybrid situation as far as i can see it. Does someone know if Microsoft is aware of this and if i further miss something what would break if this is gonna mis from the certificate. As far as i see only Sectigo is gonna do this, but they say as an explanation :

Major browser and root program providers have introduced new security requirements that prohibit the inclusion of the Client Authentication EKU in publicly trusted SSL/TLS certificates. These changes are designed to reinforce certificate purpose specificity and improve ecosystem security.

So maybe other CA's are also doing this after Sectigo announces it. The "solution" is to use a private CA, but thats costly for SMB. Here's more information :

https://www.sectigo.com/faq-client-authentication-eku-deprecation

Exchange Hybrid management
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2025-03-24T02:01:18.2066667+00:00

    Hi @Michel Admiraal ,

    Welcome to the Microsoft Q&A platform!

    Microsoft has not yet issued a definitive announcement or guidance on this adjustment for Sectigo. If there is a significant impact, Microsoft should release an update or guidance on a solution. It is recommended to stay tuned to Microsoft and related technical community announcements.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.