Domestic compliant and trustworthy pure domestic root certificate

sslTrus China-Rooted SSL Certificates

SSL certificates issued by domestic trusted certificate authorities are domestically produced and compliant. They can provide HTTPS encryption protection for websites and trusted identity authentication, preventing the leakage or tampering of transmitted data. They can be applied as a domestic alternative to SSL certificates for customers in industries such as e-government, medical education, and large and small finance. Currently, China-rooted SSL certificate brands include sslTrus, CFCA, WoTrus, and CTI, etc. They support various certificate types such as DV, OV, EV, single domain, multiple domain, and wildcards, which can meet the needs of enterprises of different industries and scales for China-rooted SSL certificates in different scenarios.

Get a special offer Understand the verification rules
https://www.gov.racent.com
Verification of domestic trusted root Certificate chain
China's IT application innovation ecosystemand e-Government Compliance Access
Self-developed and controllable Security algorithm reinforcement
sslTrus China-rooted SSL certificate

All certificates are issued under a self-controlled domestic root, fully meeting the strict compliance and data security audit requirements of the finance and government sectors.

Single-domain version

OV SSL Certificate (Domestic root)

One certificate protects a precise domain name, comprehensively verifying the true identity of the enterprise, and is the top choice for compliance.

¥1600Since /
  • Protect one fixed domain name
  • Fast issuance within 1-2 working days
  • A high insurance coverage amount of 50,000
  • Standard equipped with secure RSA encryption algorithm
  • 7*24 Local expert technical service
  • 30-day worry-free refund guarantee plan
Purchase now
Multi-domain version

OV multi-domain SSL Certificate (Domestic root)

One certificate supports adding multiple different main domains or subdomains, facilitating centralized management and renewal.

¥1600Since /
  • Protect multiple different specified domain names
  • Fast issuance within 1-2 working days
  • A high insurance coverage amount of 50,000
  • Standard equipped with secure RSA encryption algorithm
  • 7*24 Local expert technical service
  • 30-day worry-free refund guarantee plan
Purchase now

How does an SSL certificate work?

Through a strict handshake protocol, an invisible and immediate encrypted channel is established between the client and the server.

1. Certification stage

When the client accesses the site, the server returns an SSL certificate. The browser automatically verifies the certificate authority (CA), validity period and domain name match.

2. Key Encryption

After the authentication is successful, the client generates a random "session key" and encrypts it using the public key that comes with the certificate, then securely sends it to the server.

3. Decryption and Communication

After receiving the encrypted data, the server decrypts it with its own private key to obtain the session key. From then on, all data is symmetrically encrypted and transmitted through this key.

Domestic Compliance

The core underlying advantages of China-rooted SSL certificates

Built for China's information technology innovation ecosystem, it uses high-standard, self-controlled technology assets to help government, enterprise and critical infrastructure nodes complete fully automated, localized SM2 migration.

View version pricing

Safe and trustworthy · Domestic Compliance

Issued by an authoritative and trusted Chinese CA with end-to-end autonomous technology control, in line with national cybersecurity regulations and policies.

Trusted identity authentication

Deeply assist medium and large-sized websites and public communication nodes in achieving end-to-end HTTPS high-intensity encryption protection, and simultaneously complete the advanced authenticity authentication of official subject identities.

Leak-proof and tamper-proof

Establish an unforgeable protective wall to strictly prevent core business messages and sensitive user data from being eavesdropped on or maliciously tampered with during transmission, and directly erase the website's unsafe pop-up alerts.

Industry priority solution

Specifically designed for scenarios such as e-government information networks, large state-owned enterprises, public medical and educational institutions, and major financial payment platforms, it provides the preferred alternative solution for HTTPS upgrades with the highest compliance weight.

Full-spectrum diversified category alignment

It fully supports DV, OV, and EV verification levels, and provides complete certificate specification styles including single domain names, multiple domain names, and wildcards. It deeply covers domestic benchmark brands such as sslTrus, CFCA, WoTrus, and CTI, meeting the management requirements of various application nodes.

Enhancing the Security of enterprise websites

Domestic substitution is not only a policy baseline requirement, but also endows key network nodes with highly reliable, anti-sniffing, and ultra-fast handshake response digital credit assets.

Powerful data encryption

Built on core domestic high-strength algorithms, it creates a fully closed encrypted channel between both parties that locks down the privacy of data exchange.

Enhance the trustworthiness of the website

Infusing the front end of the website with highly credible local digital signature marks can effectively prevent malicious false phishing and deception, and consolidate the authoritative image of the official platform.

SEO Ranking Optimization

In line with the priority weighting strategy of mainstream search engine algorithms for highly compliant and secure sites (HTTPS), it smoothly safeguards the healthy rise of the website's natural search ranking.

Eliminate browser warnings

Effectively blocks the security warning pop-ups caused by untrusted certificates or algorithm vulnerabilities, keeping business traffic flowing and users retained.

User Privacy Protection

High-intensity monitoring of user real-name files, registration passwords and core financial messages transmitted through core routing nodes is carried out to meet the legal red line standards for information security.

Display the security lock level

After successful configuration and installation, the trusted network padlock symbol representing green security will be prominently displayed in the address bar of terminal browsers in various environments for a long time.

Frequently Asked Questions

What are the differences between China-rooted SSL certificates and international brand certificates?

China-rooted SSL is issued by authoritative domestic cas. Both the root certificate and the intermediate certificate are domestically produced. Data does not leave the country and the entire chain is independently controllable, meeting the requirements of China's IT application innovation ecosystemand compliance audits. The encryption strength is consistent with that of international brands, and browser compatibility is also guaranteed.

Which industries should give priority to using China-rooted SSL certificates?

Key information infrastructure industries such as e-government, finance, healthcare, education, and energy, as well as units with the need for China's IT application innovation ecosystemalternatives or Multi-Level Protection Scheme (MLPS) compliance audits, are usually required to give priority to using pure domestic root certificates.

Do China-rooted SSL certificates support the SM2 algorithm?

Support. sslTrus offers two product lines: international algorithms (RSA/ECC) and SM2. For public network services, the international algorithm version can be selected to ensure global compatibility. For systems with confidential evaluation requirements, the SM cryptographyversion or the SM2+RSA dual-certificate adaptive solution can be selected.

How is the browser compatibility of domestic certificates?

The sslTrus China-rooted SSL certificate has completed root access to mainstream browsers and operating systems, and is compatible with domestic browsers such as Chrome, Edge, Safari, 360, and Qianxin. It will not display the "Untrusted" warning.

Will the domestic substitution of certificates affect the existing business?

No. The replacement process is the same as that of the regular Certificate Renewal. The new Certificate Issuancecan be smoothly switched after being replaced and deployed. The sslTrus provides 7×24 local expert services to assist in the migration and verification.

From Manual Certificate Operations to Automation

From SSL/TLS certificate discovery, enrollment and deployment to continuous monitoring, alerting and automatic renewal, sslTrus helps enterprises build a unified certificate automation platform—reducing the operational burden of growing certificate inventories and shorter validity periods.

  • Overview
  • Certificate Requests
  • Certificate Deployment
  • Discovery Agents
  • Compliance & Alerts
  • Settings
Global Overview
Total Certificates
12,458
Pending
34
Expiring in 30 Days
15
Expired
2
Automated Deployments · 30 Days
Expiration Risk · Next 6 Months
Overall Compliance Rate
96%

Certificates Meet the Latest Security Baseline

Device & Cloud Asset Mix
Alibaba Cloud (40%)
AWS (25%)
Azure (15%)
F5 (10%)
Cisco (10%)