# All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth. — TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)

For All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth., requirement is All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth; effective date is 2027-03-15; authority is Google Chrome Root Program; scope is CAs included in the Chrome Root Store, recorded from its source on 2026-08-05.

- **Requirement:** All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth. _(verified: appears in the quote below)_
- **Effective date:** 2027-03-15
- **Authority:** Google Chrome Root Program _(our reading, not quoted from the source)_
- **Scope:** CAs included in the Chrome Root Store _(our reading, not quoted from the source)_

## What the source says

> All corresponding subscriber certificates issued on or after March 15, 2027 , MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth.

## Source

- https://googlechrome.github.io/chromerootprogram/

Last verified: 2026-08-05. Review by: 2026-11-03.
Part of [TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)](https://referencesource.org/tls-certificate-requirement-effective-dates/).
