Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-40720

Impact of clientAuth EKU Deprecation by Public CAs

    XMLWordPrintable

Details

    • Galera TLS Assess impact of clientAuth EKU deprecation by Public CAs

    Description

      Public Certificate Authorities (CAs), such as Sectigo, are removing the clientAuth EKU from publicly trusted TLS certificates. Sectigo plans to completely remove it from newly issued certificates by February 10, 2027.

      This may impact Galera because the MariaDB documentation currently recommends using Galera node certificates with both serverAuth and clientAuth EKUs.

      References:

      MariaDB – https://mariadb.com/docs/galera-cluster/galera-security/choosing-a-certificate-authority-for-galera-cluster#issue-certificates-with-both-serverauth-and-clientauth-ekus

      Sectigo – https://www.sectigo.com/resource-library/deprecation-of-client-authentication-eku-from-sectigo-ssl-tls-certificates

      Few clarifications are required at this stage :

      Does Galera currently require the clientAuth EKU for inter-node TLS communication?

      Will Galera work if the node certificate contains only serverAuth?

      If clientAuth is required, do we need to update Galera to support certificates without clientAuth?

      I believe customers using public CA certificates may need to move to a Private CA rather than disabling TLS if they are getting impacted by this. Also our documentation should be updated accordingly.

      Attachments

        Activity

          People

            Unassigned Unassigned
            pramod.mahto@mariadb.com Pramod Mahto
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:

              Git Integration

                Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.