告别手动运维:锐安信CLM重磅发布,开启SSL证书自动化运维新时代
锐成信息联合Sectigo共同举办了「CLM – SSL证书自动化运维解决方案发布会」,重磅发布了专为中大型企业与复杂网络环境设计的SSL证书自动化运维系统——锐安信CLM。
The SM2 SSL certificate is a trusted server certificate based on the national root that supports Chinese commercial cryptographic algorithms. It complies with the SM2 SSL security protocol and meets compliance requirements. Self-controlled, secure and reliable SSL certificates that support SM2/SM3Chinese commercial cryptographic algorithmscan issue single-domain, multi-domain and wildcard certificates, meeting the needs of government and enterprise, state-owned enterprise, public institution and other industry customers to achieve HTTPS encryption. Currently, well-known brands of SM2 SSL certificates include CFCA, Wotong, etc.
Supports single domain name, multiple domain names, and wildcard full lineage styles. Meet the demands of enterprises of different industries and scales for China-rooted SSL certificates in various scenarios.
One certificate protects one precise domain name. Chinese commercial cryptographic algorithms, ultra-fast issuance automated closed loop.
One certificate protects the main domain name and all subdomains at the next lower level, taking into account both the compliance of SM cryptographyand the cost of expansion.
One certificate centrally protects multiple different independent SM cryptographydomain names, facilitating unified operations.
Protect a core domain name and comprehensively verify the authenticity of the business entity of an enterprise.
Centralized control of the main domain name and all subdomains at the lower level conveys a strong signal of compliance for government and enterprises.
Centralize and merge multiple different independent enterprise-level site domain names and encrypt them with high strength.
Undergo the most rigorous enhanced enterprise verification, and the address bar is equipped with an advanced illuminated security lock.
Provide the same highest level of compliance confirmation for multiple core financial or government affairs interfaces at the enterprise level.
Through a strict handshake protocol, an invisible and immediate encrypted channel is established between the client and the server.
When the client accesses the site, the server returns an SSL certificate. The browser automatically verifies the certificate authority (CA), validity period and domain name match.
After the authentication is successful, the client generates a random "session key" and encrypts it using the public key that comes with the certificate, then securely sends it to the server.
After receiving the encrypted data, the server decrypts it with its own private key to obtain the session key. From then on, all data is symmetrically encrypted and transmitted through this key.
Because browser support for SM2 remains limited in some environments, sslTrus offers an adaptive dual-certificate solution that combines SM2 and RSA certificates to meet both domestic cryptography requirements and broad browser compatibility.
That is, one SM2 SSL certificate and one sslTrus SSL certificate are issued, with dual algorithm support. This makes it convenient for the client browser to automatically switch: when users access through Chrome, FireFox, etc., the system adaptively displays the RSA certificate. When accessing with browsers such as 360 and Qianxin based on Chinese commercial cryptographic algorithms, the SM cryptographyHTTPS connection should be established first. Take into account both the compliance of SM cryptographyand global common requirements.
In accordance with the Cybersecurity Law, Multi-Level Protection Scheme (MLPS)2.0 and other laws, regulations and national policy regulatory requirements, we will comprehensively assist the financial and key sectors in completing the upgrade and transformation of SM cryptography.
It features complete identity authentication and data encryption functions, effectively preventing website phishing and data leakage during transmission, allowing visitors to browse and trade with peace of mind and security.
By using the SM2 SSL certificate, we help important government and enterprise functional departments in our country perfectly break through and solve the existing obstacles in applying domestic cryptographic algorithms from the client side to the server side.
Using domestic certificates in SM2-capable browsers effectively removes security warnings and adds the trusted padlock, preventing eavesdropping, forgery and tampering.
High-intensity monitoring of sensitive information in important functional departments such as critical infrastructure effectively protects privacy and significantly enhances the credibility of enterprises and public institutions.
Implementing domestic compliant HTTPS security weighting for domestic sites is beneficial for optimizing the natural SEO rankings of search engines such as Baidu. It is also widely compatible with domestic operating systems such as 360, Qianxin, UOS of UnionTech, and KylinOS of China's IT application innovation ecosystem, as well as mainstream secure browser environments.
Based on the national root certificate and the independently controllable protocol of SM cryptography, we have comprehensively tightened the security red line and built a solid embankment for the security ecosystem of China's IT application innovation ecosystem.
With a self-developed cryptographic matrix that meets national high-standard cryptography evaluation requirements, it establishes a closed secure channel between both ends and locks down exchange privacy.
Fully vetted by well-known domestic CA institutions, it displays an official anti-forgery seal on the digital front and removes users' fraud concerns at the source.
Fully in line with the priority indexing preferences of major search engines for HTTPS domestic alternative sites, it helps the website's main domain gain higher natural weight.
On trusted domestic browsers such as 360 Secure Browser and QiAnXin, it keeps the green padlock on, removes jarring blocking pop-ups and greatly reduces page abandonment.
Implement high-resilience privacy-level full-process isolation and protection for registration passwords, real-name files, and sensitive transaction data that flow through core e-government and state-owned enterprise gateways.
After successful configuration, the exclusive security lock logo of SM cryptographywill be prominently displayed in the address bar of the built-in browsers of all China's IT application innovation ecosystemsystems, highlighting the seamless compliance signal externally.
The SM2 SSL certificate adopts the SM2/SM3/SM4 commercial cryptographic algorithms independently designed in China and is issued based on the national root certificate system, meeting the requirements of Multi-Level Protection Scheme (MLPS)2.0 and cryptographic evaluation compliance. Ordinary SSL certificates use the RSA/ECC international algorithm. The encryption strength of the two is comparable, with the difference lying in the algorithm system and regulatory compliance attributes.
Depending on business requirements: For internal network systems that are only targeted at domestic browsers, SM2 certificates can be deployed separately. For websites facing the public, it is recommended to adopt the SM2+RSA dual-certificate adaptive solution. The server automatically negotiates based on the client - domestic browsers use SM cryptography, while international browsers such as Chrome, Edge, and Safari use RSA, achieving both compliance and compatibility.
360 Security Browser, Qianxin Trusted Browser, Red Lotus and other SM cryptographybrowsers natively support the SM2 algorithm; At present, the mainstream international browsers do not recognize the SM2 certificate. They need to provide an RSA international certificate through a dual-certificate adaptive solution to ensure that users around the world can access it normally.
The Multi-Level Protection Scheme (MLPS)2.0 and the "Cryptography Law" require that critical information infrastructure, important networks and information systems such as government affairs and finance be protected by commercial cryptography. In the security assessment of commercial cryptography applications (cryptography evaluation), network communication encryption is a key item under examination. Deploying the SM2 SSL certificate is one of the basic measures to meet the requirements of the cryptography evaluation.
Consistent with international certificates, it offers three verification levels: DV/OV/EV, supports single domain name, multiple domain name, wildcard and other specifications, covers domestic brands such as CFCA and Wotong, and can be flexibly selected according to business scenarios and compliance requirements.
From SSL/TLS certificate discovery, enrollment and deployment to continuous monitoring, alerting and automatic renewal, sslTrus helps enterprises build a unified certificate automation platform—reducing the operational burden of growing certificate inventories and shorter validity periods.
Certificates Meet the Latest Security Baseline
Trusted certificates secure applications, servers, gateways and websites with HTTPS.
A lightweight, cloud-native subscription model that enables agile, automated deployment across public clouds and business nodes.
Scale signing with cloud HSM protection while keeping private keys secure.
Provides industry-standard tamper-proof authentication with a high level of trust for commercial software and e-commerce.
Encrypt and sign enterprise email to prevent phishing, tampering and interception.
Discover, monitor, deploy and renew certificates across your environment—automatically. Prevent outages caused by missed renewals.
Explore sslTrus updates, security trends and in-depth technical guidance.