Antony Vennard
unread,Oct 22, 2025, 6:27:20 AM (11 days ago) Oct 22Sign in to reply to author
Sign in to forward
You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to server...@groups.cabforum.org
Good afternoon Forum,
As you are no doubt aware some root program operators have chosen to
only host TLS Server-specific hierarchies; as a consequence, multiple
CAs have chosen to cease issuing certificates containing the client-
authentication EKU.
Rightly or wrongly, many financial and other organisations rely on this
property for mutual TLS. id-kp-clientAuth remains a "MAY" in subscriber
certificate EKU according to the latest BRs for server certs.
I would therefore like to ask the following questions:
1) Is it the case in the view of the forum that "servercert" is
uniquely for the server authentication use case?
2) If so, should this be reflected in the BRs?
3) If so, does the forum envisage a role for client auth certificates
specifically for server to server authentication (either in this WG or
elsewhere), where the "client" is always a machine?
Kind regards,
Antony
(representing myself only, as an "interested party")