Client Authentication EKU Phased Out

This blogpost addresses the upcoming changes regarding the removal of Client Authentication Extended Key Usage (EKU) from publicly trusted SSL/TLS certificates, a shift driven by security concerns and the need for clearer roles in cryptographic operations.

Breaking News: Prepare for 47-Day SSL/TLS Certificates

The CA/Browser Forum Ballot for drastically reducing the maximum lifespan of publicly trusted SSL/TLS certificates has officially passed. Read in this blog post what actions you need to take to ensure you are prepared for this.

DNS CAA S/MIME Resource Check 2025 Required

Starting March 13, 2025 CA’s such as DigiCert will start checking CAA resource records before issuing a Secure Email (S/MIME) certificate with a mailbox address. Read how to check and why this CAA S/MIME resource check is needed.

Email domain validation change policy by CA/B Forum

The CA/B forum has announced a major change to the annual validation of domain names via email. This will impact organizations that purchase certificates from DigiCert and GlobalSign. Read more about the change here.