Browsers are retiring the technology that powers client authentication. SSL.com built a path that keeps your mutual-TLS deployments working and keeps your websites trusted everywhere, without you having to choose between the two.

For years, a single digital certificate could do double duty, proving a server’s identity to a visitor, and proving a client’s identity right back. That two-way handshake is the heart of mutual TLS (mTLS), the quiet workhorse behind secure APIs, connected devices, and zero-trust networks. It’s how a system knows that the thing on the other end of the connection is exactly who it claims to be.
Now the ground is shifting. Chrome has begun removing support for the client authentication capability inside the public web trust ecosystem, and Mozilla is expected to follow. The browsers’ reasoning is sound: the certificates that secure public websites and the certificates that authenticate clients are increasingly seen as two different jobs that deserve two different homes. That’s good hygiene for the web. But if your business depends on mTLS, it raises an uncomfortable question: do you have to give up trusted client authentication to keep your websites working in modern browsers? With SSL.com, the answer is no.Two roots, two jobs, zero compromise
Think of a root certificate as the ultimate source of trust, the anchor that browsers and operating systems agree to vouch for. SSL.com operates more than one, and that’s the key to this whole story.- Our 2016 roots are general-purpose. They were built to support a wide range of uses, including the client authentication that mTLS relies on.
- Our 2022 roots are purpose-built for TLS — dedicated solely to securing websites, exactly the way browsers now prefer.
What this means for you
Your public websites stay trusted in Chrome and every modern browser. Your mTLS deployments, APIs, IoT fleets, internal service meshes, partner integrations, keep authenticating clients without interruption. One provider, one relationship, both needs covered.
Why it matters now
Most certificate providers will eventually force a clean split, leaving customers to scramble for a separate source of client-authentication certificates, or to re-architect deployments under deadline pressure. SSL.com saw the change coming and engineered around it ahead of time, so the transition happens on our side, not yours.- No re-architecting. Your existing mTLS patterns keep working with certificates issued the way they always have been.
- No browser breakage. Website certificates chain to roots Chrome already trusts, with cross-signed reach into older environments.
- One trusted partner. Server identity and client identity, both sourced from a CA with a long public audit history and roots embedded across the ecosystem.