SAP Knowledge Base Article - Preview

3725252 - Client Authentication EKU Deprecation - Impact to Inbound API Management scenarios

Symptom

You have received a notification regarding upcoming changes to client certificates used for mutual TLS (mTLS) in SAP API Management. Public Certificate Authorities (CAs) are removing the Client Authentication (clientAuth) Extended Key Usage (EKU) attribute from the certificates they issue, which will impact inbound mTLS communication.


Read more...

Environment

  • API Management

Keywords

Chrome Root Program, EKU, Extended Key Usage, clientAuth, mTLS, mutual TLS, private PKI, DigiCert, API Management, TLS handshake, certificate authentication, two-way SSL, APIM , KBA , OPU-API-OD-OPS , Operations , Product Enhancement

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.