Skip to content

ceremony: Add support for configuring cross-sign EKUs#8750

Open
aarongable wants to merge 2 commits intomainfrom
cross-sign-ekus
Open

ceremony: Add support for configuring cross-sign EKUs#8750
aarongable wants to merge 2 commits intomainfrom
cross-sign-ekus

Conversation

@aarongable
Copy link
Copy Markdown
Contributor

As of 2025-09-15, the CCADB policy requires that all subordinate CA certificates, including cross-signs of existing roots, must have an EKU extension. As of 2026-06-15, the Chrome policy will require that all new subordinate CA certificates only contain the tlsServerAuth EKU. This change allows us to configure the set of EKUs that will appear in a CA certificate, while restricting that selection per the aforementioned requirements.

@aarongable aarongable requested a review from a team as a code owner May 9, 2026 08:03
@aarongable aarongable requested a review from ezekiel May 9, 2026 08:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants