Reference Source

All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth.

For All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth., requirement is All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth; effective date is 2027-03-15; authority is Google Chrome Root Program; scope is CAs included in the Chrome Root Store, recorded from its source on 2026-08-05.

Requirement
All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth. verified
Effective date
2027-03-15
Authority
Google Chrome Root Program our reading
Scope
CAs included in the Chrome Root Store our reading
Sourcegooglechrome.github.io
Verified2026-08-05
Review by2026-11-03
DatasetTLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)

Values marked our reading are our classification of what the source says — the source does not print them in those words. The quote below is the evidence for each one; judge it yourself.

What the source says

All corresponding subscriber certificates issued on or after March 15, 2027 , MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth.

googlechrome.github.io, retrieved 2026-08-05

Source

Last verified against source: 2026-08-05. Due for re-check by 2026-11-03. This page as Markdown · OKF bundle · full dataset as JSON.