National Root Certificate System · SM cryptographyCompliant

sslTrus SM2 SSL Certificates

The SM2 SSL certificate is a trusted server certificate based on the national root that supports Chinese commercial cryptographic algorithms. It complies with the SM2 SSL security protocol and meets compliance requirements. Self-controlled, secure and reliable SSL certificates that support SM2/SM3Chinese commercial cryptographic algorithmscan issue single-domain, multi-domain and wildcard certificates, meeting the needs of government and enterprise, state-owned enterprise, public institution and other industry customers to achieve HTTPS encryption. Currently, well-known brands of SM2 SSL certificates include CFCA, Wotong, etc.

Get a special offer Understand the verification rules
https://www.sm2-secure.com
SM2 SSL Security protocol matching
National Root Certificate Chain Verification
Self-controlled SM2/SM3 algorithm handshake
sslTrus SM2 SSL Certificate

Supports single domain name, multiple domain names, and wildcard full lineage styles. Meet the demands of enterprises of different industries and scales for China-rooted SSL certificates in various scenarios.

Single-domain version

DV SSL certificate

One certificate protects one precise domain name. Chinese commercial cryptographic algorithms, ultra-fast issuance automated closed loop.

¥900Since /
  • Protect one fixed domain name
  • Fast automatic issuance within 5-10 minutes
  • SM2/SM3 encryption algorithm
  • 7*24 local expert service support
Purchase now
Multi-domain version

DV multi-domain certificate

One certificate centrally protects multiple different independent SM cryptographydomain names, facilitating unified operations.

¥900Since /
  • Protect multiple different specified domain names
  • Fast automatic issuance within 5-10 minutes
  • SM2/SM3 encryption algorithm
  • 50,000 Commercial security anti-counterfeiting guarantee
Purchase now
Enterprise single domain name

OV SSL certificate

Protect a core domain name and comprehensively verify the authenticity of the business entity of an enterprise.

¥3475Since /
  • Protect one fixed domain name
  • Official compliance review within 1-2 working days
  • 50,000 Commercial security anti-counterfeiting guarantee
  • The official and authoritative root system of SM cryptographyissues
Purchase now
Enterprise multi-domain

OV multi-domain certificate

Centralize and merge multiple different independent enterprise-level site domain names and encrypt them with high strength.

¥3475Since /
  • Protect multiple designated enterprise domain names
  • Official compliance review within 1-2 working days
  • 50,000 Commercial security anti-counterfeiting guarantee
  • The official and authoritative root system of SM cryptographyissues
Purchase now
Top-of-the-line defense · Multi-domain

EV Multi-domain Certificate

Provide the same highest level of compliance confirmation for multiple core financial or government affairs interfaces at the enterprise level.

¥5100Since /
  • Protect multiple core financial-grade domain names
  • 1 to 3 working days for in-depth qualification review
  • 100,000 High security compensation insurance
  • Fully compatible with domestic browsers such as 360 and QiAnXin
Purchase now

How does an SSL certificate work?

Through a strict handshake protocol, an invisible and immediate encrypted channel is established between the client and the server.

1. Certification stage

When the client accesses the site, the server returns an SSL certificate. The browser automatically verifies the certificate authority (CA), validity period and domain name match.

2. Key Encryption

After the authentication is successful, the client generates a random "session key" and encrypts it using the public key that comes with the certificate, then securely sends it to the server.

3. Decryption and Communication

After receiving the encrypted data, the server decrypts it with its own private key to obtain the session key. From then on, all data is symmetrically encrypted and transmitted through this key.

Adaptive Solution

SM2/RSA Dual Certificate Solution

Because browser support for SM2 remains limited in some environments, sslTrus offers an adaptive dual-certificate solution that combines SM2 and RSA certificates to meet both domestic cryptography requirements and broad browser compatibility.

That is, one SM2 SSL certificate and one sslTrus SSL certificate are issued, with dual algorithm support. This makes it convenient for the client browser to automatically switch: when users access through Chrome, FireFox, etc., the system adaptively displays the RSA certificate. When accessing with browsers such as 360 and Qianxin based on Chinese commercial cryptographic algorithms, the SM cryptographyHTTPS connection should be established first. Take into account both the compliance of SM cryptographyand global common requirements.

Requirements for cryptography upgrade and assessment

In accordance with the Cybersecurity Law, Multi-Level Protection Scheme (MLPS)2.0 and other laws, regulations and national policy regulatory requirements, we will comprehensively assist the financial and key sectors in completing the upgrade and transformation of SM cryptography.

Ensure the security of network communication

It features complete identity authentication and data encryption functions, effectively preventing website phishing and data leakage during transmission, allowing visitors to browse and trade with peace of mind and security.

Solving the application problems of SM cryptography

By using the SM2 SSL certificate, we help important government and enterprise functional departments in our country perfectly break through and solve the existing obstacles in applying domestic cryptographic algorithms from the client side to the server side.

Eliminate the "Unsafe" prompt

Using domestic certificates in SM2-capable browsers effectively removes security warnings and adds the trusted padlock, preventing eavesdropping, forgery and tampering.

Enhance the credibility of government and enterprises

High-intensity monitoring of sensitive information in important functional departments such as critical infrastructure effectively protects privacy and significantly enhances the credibility of enterprises and public institutions.

Improve search engine rankings and be compatible with major companies

Implementing domestic compliant HTTPS security weighting for domestic sites is beneficial for optimizing the natural SEO rankings of search engines such as Baidu. It is also widely compatible with domestic operating systems such as 360, Qianxin, UOS of UnionTech, and KylinOS of China's IT application innovation ecosystem, as well as mainstream secure browser environments.

Enhancing the Security of enterprise websites

Based on the national root certificate and the independently controllable protocol of SM cryptography, we have comprehensively tightened the security red line and built a solid embankment for the security ecosystem of China's IT application innovation ecosystem.

Powerful data encryption

With a self-developed cryptographic matrix that meets national high-standard cryptography evaluation requirements, it establishes a closed secure channel between both ends and locks down exchange privacy.

Enhance the trustworthiness of the website

Fully vetted by well-known domestic CA institutions, it displays an official anti-forgery seal on the digital front and removes users' fraud concerns at the source.

SEO Ranking Optimization

Fully in line with the priority indexing preferences of major search engines for HTTPS domestic alternative sites, it helps the website's main domain gain higher natural weight.

Eliminate browser warnings

On trusted domestic browsers such as 360 Secure Browser and QiAnXin, it keeps the green padlock on, removes jarring blocking pop-ups and greatly reduces page abandonment.

User Privacy Protection

Implement high-resilience privacy-level full-process isolation and protection for registration passwords, real-name files, and sensitive transaction data that flow through core e-government and state-owned enterprise gateways.

Display the security lock level

After successful configuration, the exclusive security lock logo of SM cryptographywill be prominently displayed in the address bar of the built-in browsers of all China's IT application innovation ecosystemsystems, highlighting the seamless compliance signal externally.

Frequently Asked Questions

What is the SM2 SSL certificate? What are the differences from ordinary SSL certificates?

The SM2 SSL certificate adopts the SM2/SM3/SM4 commercial cryptographic algorithms independently designed in China and is issued based on the national root certificate system, meeting the requirements of Multi-Level Protection Scheme (MLPS)2.0 and cryptographic evaluation compliance. Ordinary SSL certificates use the RSA/ECC international algorithm. The encryption strength of the two is comparable, with the difference lying in the algorithm system and regulatory compliance attributes.

Do both the SM2 certificate and the international certificate need to be installed?

Depending on business requirements: For internal network systems that are only targeted at domestic browsers, SM2 certificates can be deployed separately. For websites facing the public, it is recommended to adopt the SM2+RSA dual-certificate adaptive solution. The server automatically negotiates based on the client - domestic browsers use SM cryptography, while international browsers such as Chrome, Edge, and Safari use RSA, achieving both compliance and compatibility.

Which browsers support the SM2 certificate?

360 Security Browser, Qianxin Trusted Browser, Red Lotus and other SM cryptographybrowsers natively support the SM2 algorithm; At present, the mainstream international browsers do not recognize the SM2 certificate. They need to provide an RSA international certificate through a dual-certificate adaptive solution to ensure that users around the world can access it normally.

Is the modification of SM cryptographya hard requirement for the compliance of Multi-Level Protection Scheme (MLPS)?

The Multi-Level Protection Scheme (MLPS)2.0 and the "Cryptography Law" require that critical information infrastructure, important networks and information systems such as government affairs and finance be protected by commercial cryptography. In the security assessment of commercial cryptography applications (cryptography evaluation), network communication encryption is a key item under examination. Deploying the SM2 SSL certificate is one of the basic measures to meet the requirements of the cryptography evaluation.

What types and specifications of SM2 certificates are available for selection?

Consistent with international certificates, it offers three verification levels: DV/OV/EV, supports single domain name, multiple domain name, wildcard and other specifications, covers domestic brands such as CFCA and Wotong, and can be flexibly selected according to business scenarios and compliance requirements.

From Manual Certificate Operations to Automation

From SSL/TLS certificate discovery, enrollment and deployment to continuous monitoring, alerting and automatic renewal, sslTrus helps enterprises build a unified certificate automation platform—reducing the operational burden of growing certificate inventories and shorter validity periods.

  • Overview
  • Certificate Requests
  • Certificate Deployment
  • Discovery Agents
  • Compliance & Alerts
  • Settings
Global Overview
Total Certificates
12,458
Pending
34
Expiring in 30 Days
15
Expired
2
Automated Deployments · 30 Days
Expiration Risk · Next 6 Months
Overall Compliance Rate
96%

Certificates Meet the Latest Security Baseline

Device & Cloud Asset Mix
Alibaba Cloud (40%)
AWS (25%)
Azure (15%)
F5 (10%)
Cisco (10%)