• Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to X
  • Link to Instagram
  • English English English en
  • Deutsch Deutsch German de
Sales: +49 5251 304-800 | Support: +49 5251 304-636
NoSpamProxy
  • PRODUCT
    • NoSpamProxy Cloud
    • NoSpamProxy Protection
    • NoSpamProxy Encryption
    • NoSpamProxy Large Files
    • NoSpamProxy Disclaimer
    • NoSpamProxy 25Reports
  • SOLUTIONS
    • M365 Mail Security
    • Managed Certificates
    • 32Guards
    • 32Guards Sandbox
  • RESOURCES
    • Documentation
    • Forum
    • Webcasts
    • Training Courses
    • Support
    • Software Download
  • PARTNERS
    • Finding Resellers
    • Becoming Reseller
    • Partner Portal
    • NFR Licenses
  • COMPANY
    • Contact
    • Testimonials
    • Team
    • Career
    • Events
    • Awards
  • PRICES
  • BLOG
    • Blog
    • Newsletter Subscription
  • FREE TRIAL VERSION
    • Price Request
    • Free Trial Version
  • English
    • Deutsch
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Information

End of TLS Client Authentication Certificates

Effective immediately, public CAs (certification authorities) are no longer permitted to use the Extended Key Usages (EKU) id-kp-clientAuth and id-kp-serverAuth simultaneously in TLS certificates. Those who do not comply with this rule will no longer be included in the Chrome Root Program and will therefore no longer appear in the Trust Store. We provide information about who is affected and what you should do now.

19.02.2026|zuletzt aktualisiert:02.04.2026

More and more CAs are no longer issuing TLS certificates with EKU for client authentication. This means that customers can no longer use their existing “normal” TLS certificates for client authentication.

In practice, this means that systems can no longer authenticate themselves to other email servers—such as Exchange Online—using TLS client authentication certificates.

Customers with automatic certificate generation via NoSpamProxy – new solution

Both NoSpamProxy Cloud customers and NoSpamProxy Server customers who use automatic certificate generation for O365 via NoSpamProxy are not affected and do not need to take any action.

NoSpamProxy obtains its TLS client authentication certificates for O365 via Let’s Encrypt. Let’s Encrypt has provided a special profile for this transition phase that allows pure TLS client auth certificates to be requested.

Options for customers without automatic certificate generation via NoSpamProxy

All customers who do not obtain their O365 certificates automatically via NoSpamProxy or who rely on TLS client authentication in their own connectors should check which of the following options is suitable for them:

  • Continue to use TLS client authentication with a certificate, provided that it is necessary and the server supports it;
  • Switch to IP filtering.
  • Find a CA that issues individual TLS client authentication certificates in addition to “normal” TLS server certificates and purchase these.
  • Set up a private CA to issue the required certificates yourself.

Important note for Exchange Online customers

NoSpamProxy uses TLS client authentication by default for connecting to Exchange Online. If you use your own certificates, they must come from a trusted CA – otherwise Microsoft will not accept them.

You can use our automatic certificate generation or use a new certificate of your own without EKU.

Do you have questions or need support?

You will find a dedicated thread on this topic in the NoSpamProxy forum. Please use it for any queries or suggestions.

Go to the thread in the NoSpamProxy forum
  • share 
  • share 
  • share 
  • email 

SEARCH

PRODUCT

  • All Topics
  • NoSpamProxy Cloud
  • NoSpamProxy Protection
  • NoSpamProxy Encryption
  • NospamProxy Large Files

You need support?

You can find more information about NoSpamProxy in our documentation and forum.

CATEGORY

  • All Topics
  • News
  • Product
  • Tech & Support
  • Events

NoSpamProxy Newsletter

Subscribe to Newsletter
RSS Feed Logo RSS Feed Logo Subscribeto RSS Feed

NoSpamProxy

  • NoSpamProxy Cloud
  • NoSpamProxy Encryption
  • NoSpamProxy Large Files
  • NoSpamProxy Disclaimer
  • Price request
  • Team
  • Career
  • General terms and conditions
  • Data Protection Information for Business Partners and Applicants
  • Cybersecurity (PSIRT)

Partners

  • Becoming a reseller
  • Partners
  • Order Certificates
  • Newsletter

Categories

  • All topics
  • News
  • Support
  • Updates
  • Order certificates

Latest News

  • DKIM richtig betreiben: Der Schlüssel zu sicherer E-Mail-Kommunikation 800x800
    Getting DKIM Right: The Key to Secure Email Communication18.05.2026 - 10:00
  • Die unterschätzten Risiken von Spam- und Quarantäneordnern
    The Underestimated Risks of Spam and Quarantine Folders05.05.2026 - 10:00
  • Info Icon
    Authentication error in NoSpamProxy following Windows updates starting in January 202630.04.2026 - 14:46
IMPRINT • EULA • Privacy Policy • • © 2026 Net at Work GmbH
  • Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to X
  • Link to Instagram
Link to: NoSpamProxy enables DKIM signing of automated emails – update now! Link to: NoSpamProxy enables DKIM signing of automated emails – update now! NoSpamProxy enables DKIM signing of automated emails – update now!NoSpamProxy ermöglicht die DKIM-Signatur automatisierter E-Mails 800x800 Link to: When invoices become a trap: Invoice fraud and what you can do about it Link to: When invoices become a trap: Invoice fraud and what you can do about it Invoice Fraud und was Sie dagegen tun können 800x800When invoices become a trap: Invoice fraud and what you can do about it
Scroll to top Scroll to top Scroll to top