Managing sound and video settings during Teams meetings and calls for optimal communication
Based on the latest Microsoft guidance, the key point is that the upcoming industry change affects Microsoft's SIP interface certificates, not necessarily the certificate requirements for customer SBC certificates. Microsoft has clarified that Direct Routing will continue to rely on mutual TLS (mTLS) and that Teams SIP interface certificates will continue to support the requirements needed for Direct Routing authentication. [learn.microsoft.com], [erik365.blog]
The more recent Direct Routing updates include a specific section titled**"Clarification on Client Authentication Extended Key Usage (EKU)"**, which was added to address customer concerns after public CAs announced plans to stop issuing dual-EKU certificates. Microsoft's guidance focuses on ensuring that SBCs trust the updated Microsoft certificate chains and supported root CAs rather than requiring customers to make immediate architectural changes. [learn.microsoft.com], [erik365.blog]
For customers renewing SBC certificates, the recommended actions are:
- Verify that the SBC certificate is issued by a Microsoft-supported CA.
- Ensure the SBC trust store contains all Microsoft-supported root CAs listed in the Direct Routing documentation.
- Follow guidance from the SBC vendor regarding support for the upcoming certificate changes.
- Validate TLS connectivity using Microsoft's published testing and validation processes before certificate renewal or deployment. [learn.microsoft.com], [erik365.blog], [maxime.hiez.ca]
At this time, Microsoft documentation does not indicate that Direct Routing customers must migrate to DigiCert X9 PKI specifically. The primary focus is ensuring SBC trust configuration is updated and aligned with Microsoft's supported certificate authorities and future certificate rollouts. [learn.microsoft.com], [erik365.blog]
If Microsoft engineering can provide additional clarification, it would be particularly useful to confirm whether SBC certificates used for Direct Routing will continue to require both Server Authentication and Client Authentication EKUs after public CA providers complete the transition away from dual-EKU public TLS certificates.