Skip to main content

Action Required: Chrome Policy Changes & Your Salesforce mTLS Setup

 

Hey Trailblazers!  

 

If your org uses Mutual TLS (mTLS) for secure integrations or inbound API calls, there is a major industry shift coming that you need to track for 2026.

Google Chrome is updating its Root Program Policy (v1.7)

 to ban "dual-use" certificates. This means a single certificate can no longer be used for both a website (Server Auth) and identifying a client (Client Auth) if it’s issued by a Public CA trusted by Chrome. 

 

The good news is that Salesforce is proactive here. We are aware of specific vendors that will continue to issue public certificates with the Client Auth EKU

 under dedicated hierarchies. 

 

Salesforce will begin trusting these specific roots in the coming weeks. If you are looking for a public CA that will remain compliant, these are your verified options:

Vendor | Verified Root CA (Client Auth Support)

  • DigiCert | CN=DigiCert Assured ID Root G2
  • DigiCert | CN=DigiCert Assured ID Root G3
  • SSL.com | SSL.com Client ECC Root CA 2022
  • SSL.com | SSL.com Client RSA Root CA 2022
  • Sectigo | CN=Sectigo Public Email Protection Root R46
  • Sectigo | CN=Sectigo Public Email Protection Root E46

📜 What is changing?

  • The Rule: Starting June 15, 2026, Chrome will only trust single-purpose certificates from its Root Store.
  • The Impact: If your mTLS setup relies on a "multi-purpose" certificate from a standard public root, it will likely stop working in Chrome after the deadline.
  •  

🛠️ What should Salesforce Admins & Devs do?

  1. Audit your mTLS: Check your "Certificate and Key Management" in Setup. Are your certificates issued by a Public CA?
  2. Review the Roots: Check if your certificates chain up to the "Safe List" mentioned above.
  3. Plan for Re-issuance: If you are NOT using one of the roots above, you will not be able to renew your "dual-use" certificates in their current form after June 2026.
  4. Coordinate with IT: Ensure your architecture uses a Public CA for the Server identity and one of the verified Public roots above for the Client identity.

Questions?

 Please log a case and we can assist you.  

 

For further reading, please read the following article. 

Upcoming Mandatory Changes to Public Key Infrastructure (PKI).

1 comentário
  1. 27 de mai., 15:27

    Hi @Andrew Kavanagh

    We do not have any certificates listed under "Certificate and Key Management" in our production or sandbox orgs. 

    That being the case, does the deprecation of dual-use certificates, reduced certificate lifespans, or root certificate transition affects us? Is there anything I have to do to prepare for the changes, specially the dual-use certificates by June 15?  

    Thanks, Miriam H.

0/9000