All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth.
What is the effective date for All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth.?
For All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth., effective date is 2027-03-15; authority is Google Chrome Root Program; scope is CAs included in the Chrome Root Store, recorded from its source on 2026-08-05.
All corresponding subscriber certificates issued on or after March 15, 2027 , MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth.
— googlechrome.github.io, retrieved 2026-08-05
2027-03-15
The date this requirement takes effect, as printed in the issuing programme's own effective-date table. Verified against the passage quoted below.
- Requirement
- All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth.
- Effective date
- 2027-03-15
- Authority
- Google Chrome Root Program our reading
- Scope
- CAs included in the Chrome Root Store our reading
Values marked our reading are our classification of what the source says — the source does not print them in those words. The quote below is the evidence for each one; judge it yourself.
Source
- googlechrome.github.iohttps://googlechrome.github.io/chromerootprogram/
This one changes, and we watch it.TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla) is re-read on a schedule and every change is dated. Subscribe: Atom feed · JSON · what has changed so far.