Unclassified | Non classifié


 

 

 Hello everyone,

 

We want to inform you of an upcoming change to SSL/TLS certificate policies that may impact your organization.

 

Key Details:

 

  • Client Authentication Extended Key Usage (EKU) will be removed from publicly trusted SSL/TLS certificates by February 10, 2027 .This aligns with updated browser and industry security requirements, including Google Chrome’s enforcement timeline, to ensure certificates are used only for their intended server authentication functions.
  • Impact: Organizations using certificates for mutual TLS (mTLS), server-to-server authentication, or other client authentication scenarios will be affected. Certificates used strictly for HTTPS website encryption are not impacted.
  • Starting September 15, 2026 , SSC will issue only commercial certificates with server authentication EKU.
  • Existing certificates remain valid until they expire or are revoked.

 

 

Recommended Action:

 

  • Migrate to the Internal Certificate Authority – GOC-GDC-Root-A (an NDA enterprise solution) to continue supporting Client Authentication EKUs with greater lifetime.
  • Review your current certificate deployments and begin planning your migration well before the February 2027 deadline.

 

 

If you encounter issues with the newer certificates, please contact our generic mailbox or open an incident for assistance.

 

 

 

Objet : Mise à jour importante : Modifications des politiques de certificats SSL/TLS

 

Bonjour a tous,

 

 

Nous tenons à vous informer d’un changement imminent aux politiques de certificats SSL/TLS qui pourrait avoir un impact sur votre organisation.

 

Détails clés :

  • Ce qui change : L’utilisation de la clé étendue d’authentification client (EKU) sera supprimée des certificats SSL/TLS publiquement approuvés d’ici le 10 février 2027 . Cette modification s’aligne sur les nouvelles exigences de sécurité des navigateurs et de l’industrie, y compris le calendrier d’application de Google Chrome, afin de garantir que les certificats sont utilisés uniquement pour leurs fonctions d’authentification de serveur prévues.
  • Impact : Les organisations utilisant des certificats pour l’authentification mutuelle TLS (mTLS), l’authentification serveur à serveur ou d’autres scénarios d’authentification client seront touchées. Les certificats utilisés strictement pour le chiffrement de sites web HTTPS ne sont pas concernés.
  • Calendrier : À partir du 15 septembre 2026 , le SSC émettra uniquement des certificats commerciaux avec l’EKU d’authentification serveur.
  • Certificats existants : Les certificats actuels restent valides jusqu’à leur expiration ou leur révocation.

 

Actions recommandées :

  • Migrez vers l’Autorité de certification interne – GOC-GDC-Root-A (une solution d’entreprise NDA) pour continuer à prendre en charge les EKU d’authentification client avec une durée de vie prolongée.
  • Examinez vos déploiements de certificats actuels et commencez à planifier votre migration bien avant la date limite de février 2027.

 

Si vous rencontrez des problèmes avec les nouveaux certificats, veuillez contacter notre boîte de réception générique ou ouvrir un incident pour obtenir de l’aide.

 

 

 

 

 

 

Thank you, Merci

 

Courtney Jacob

 

Program Support  Officer, Credential Management (CM)

Contact Centres and Digital Identity (CCDI)

Digital Services Branch (DSB)

Shared Services Canada (SSC) | Government of Canada

Courtney.Jacob@ssc-spc.gc.ca | Tel:  (613) 606-9555

 

Agente de soutien aux programmes, | Gestion des justificatifs d’identité (GJI)

Centre de Contact et Identité Numérique (SCCIN)

Direction des services numériques (DSN)

Services partagés Canada (SPC) Gouvernement du Canada

Courtney.Jacob@ssc-spc.gc.ca | Tel:  (613) 606-9555

 

I am on the traditional unceded territory of the Anishnaabeg nation, Ottawa, Ontario, Canada