Do *NOT* remove TLS Client Auth EKU!

FWIW, the discussion is taking place on mailop.org mailing list as well:
[mailop] No more TLS client certificates from public CAs
And the consensus there also is that this won't – or at least shouldn't – have an impact on public SMTP (ie. without prior private agreement between communicating parties).

10 Likes