mTLS is going to be a problem soon, arguably bigger than this lifetime reduction.
Most server certs today have clientAuth EKU and can be used for mTLS. That stops next year.
[1]: https://googlechrome.github.io/chromerootprogram/#321-applic...
I've scoured the CA/Browser Forum BRs and ballots, Chrome Root Store policies, and CCADB policies, and can't find mention of this coming restriction.
In case it helps - am the CTO of a large CA, so (un)fortunately aware of what's happening and when.
All corresponding unexpired and unrevoked subscriber (i.e., TLS server authentication) certificates issued on or after June 15, 2026 MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth.
Thanks!