Back to Insights
SM2 SSL certificatesSM2 algorithmDigital certificatesChinese cryptography compliance 2024-10-14

SM2 SSL Certificates: Supporting Chinese Cryptographic Standards

An introduction to SM2 SSL certificates, their role in China’s domestic cryptography ecosystem, available certificate types and the application process.

Digital certificates bind identity information to cryptographic keys. Common certificate ecosystems use algorithms such as RSA and elliptic-curve signatures, together with hash algorithms such as SHA-2. These algorithms have different roles: a hash algorithm is not an alternative to a public-key signature algorithm.

Alongside these widely deployed systems, SM2 SSL certificates support China’s domestic cryptographic standards and associated deployment requirements. What are they, and where are they used?

SM2 SSL certificates

1. What is an SM2 SSL certificate?

An SM2 SSL certificate uses the SM2 public-key algorithm family developed in China and follows the relevant technical specifications. In a compatible cryptographic and protocol environment, it supports server authentication and secure communications using Chinese cryptographic algorithms.

These certificates are used in domestic-technology projects involving Chinese government bodies, public institutions, state-owned enterprises, banks and other organizations. They can form part of an implementation designed to meet applicable Chinese cryptography requirements; deploying a certificate alone does not demonstrate compliance with an entire regulatory framework.

2. What can SM2 SSL certificates support?

  1. Deploying Chinese cryptography end to end. They help organizations address compatibility and implementation requirements between clients and servers using the relevant domestic algorithms.
  2. Protecting network communications. In a correctly configured, compatible protocol implementation, certificates support identity authentication while the secure connection protects data in transit against unauthorized disclosure and alteration. They do not certify the trustworthiness of all content on a website.
  3. Trusted connections in compatible browsers. A supported browser can validate a correctly installed certificate when it trusts the issuing chain and all other checks pass. An SM2 certificate does not automatically remove warnings in every browser or operating system.
  4. Supporting cryptographic upgrades and assessments. In China, SM2 deployments can contribute to projects governed by requirements associated with the Cybersecurity Law, the classified-protection framework commonly called MLPS 2.0, the Cryptography Law and other applicable rules. Assessment also covers the wider system and operational controls.

About SM2: SM2 is an elliptic-curve public-key cryptographic algorithm family. Its encryption and signature mechanisms support uses such as confidentiality, identity authentication, integrity and authenticity. It can serve as an alternative to RSA in appropriately designed systems, but it is not a drop-in replacement in clients or protocols that do not support it.

3. Certificate providers and types

The original October 2024 article described offerings from CFCA, WoTrus and Huace. Depending on the provider and product, these included domain, organization and extended identity-validation options, as well as single-domain, multi-domain and wildcard coverage. This is a historical overview of the described SM2 product ecosystem, not a claim that all combinations are available today or follow the rules of ordinary publicly trusted Web PKI products.

  • CFCA: China Financial Certification Authority. The original article described its establishment with approval from Chinese financial and information-security authorities and its WebTrust assurance background. It listed SM2 OV single-domain and OV wildcard offerings.
  • WoTrus: A CA described in the original article as holding a Chinese electronic certification service license and international assurance credentials. Its listed SM2 offerings included DV, OV and EV validation variants and single-domain, multi-domain and wildcard coverage.
  • Huace: An electronic certification service provider described as supporting online identity authentication and information security for government bodies, organizations, businesses, individuals and devices. The article listed DV, OV and EV variants, including single-domain and wildcard products.

Current certificate availability, trust coverage and assurance credentials should be confirmed for the selected CA and product. Browser compatibility depends on the specific SM2 trust and protocol environment.

SM2 certificate providers

4. Applying for an SM2 SSL certificate

The original article described the following application workflow through Racent:

  1. Choose an appropriate SM2 SSL certificate and place an order.
  2. Complete and submit the certificate application.
  3. Complete the CA’s domain-control and, where applicable, identity verification.
  4. Receive the issued SM2 SSL certificate.

Required documents and validation steps vary between CAs and certificate types. Confirm the precise requirements before applying.

SM2 certificates provide one component of the move toward China’s domestic cryptographic ecosystem. Their practical value depends on the selected protocol, client compatibility, trust configuration and the security requirements of the deployment.

Racent’s original announcement discussed SM2 certificate services from providers including CFCA, WoTrus and Huace. Read our SM2 SSL overview or contact us to discuss requirements. International inquiries are handled through NicSRS; this is a consultation route, not a promise that a matching SM2 product is available for direct online purchase.