Selecting SSL Certificates Based on Certificate Encryption Algorithm
Racent's SSL certificates support different algorithms, including international algorithms RSA, ECC, and the Guomi (SM cryptography) algorithm SM2. You can choose based on the algorithms required by your business and systems.
International Standard Algorithms
The international standard algorithms commonly used in SSL certificates are RSA and ECC encryption algorithms. RSA is a widely used asymmetric encryption algorithm (using public and private keys for secure data transmission and verification). Compared to RSA, ECC (Elliptic Curve Cryptography) is a more advanced and secure encryption algorithm (faster encryption speed, higher efficiency, lower server resource consumption) and has been promoted in mainstream browsers. Between the two, RSA has stronger advantages in compatibility and universal applicability.
Guomi Standard Algorithm
The Guomi algorithm applied to SSL certificates is primarily SM2. The SM2 algorithm is an elliptic curve public key cryptographic algorithm standard published by the State Cryptography Administration of China, and is part of the Guomi algorithm system (GB/T 32918). SSL certificates using the SM2 algorithm are suitable for users who need to meet Guomi compliance requirements (such as cryptographic evaluation and cryptographic transformation).
Encryption Algorithm Comparison Table
| Comparison Item | RSA | ECC | SM2 |
|---|---|---|---|
| Key Length | *1024-bit: Basic security (no longer recommended) *2048-bit: Current standard (equivalent to 112-bit symmetric key strength) *3072-bit: Higher security (equivalent to 128-bit symmetric key strength) *4096-bit: Extremely high security requirements | *256-bit: Equivalent to the security provided by RSA 2048-bit keys. *384-bit: Equivalent to the security provided by RSA 3072-bit keys. | *256-bit, equivalent to RSA 3072-bit *384-bit, equivalent to RSA 7680-bit *512-bit, equivalent to RSA 15360-bit *SSL certificate applications mainly use 256-bit keys |
| Security Features | *One of the earliest public key encryption algorithms *The most widely used asymmetric encryption algorithm *Performance directly affects the efficiency of many security protocols and systems | *Asymmetric encryption algorithm based on elliptic curve mathematical theory *Shorter key length and higher computational efficiency | *Based on the Elliptic Curve Discrete Logarithm Problem (ECDLP), with no known sub-exponential time algorithm to solve it currently *Uses special elliptic curve parameters carefully designed by the State Cryptography Administration of China *Supports Perfect Forward Secrecy |
| Memory and CPU usage | High | Low | Low |
| Compatibility | Broader compatibility with systems, browsers, and applications | Good compatibility, but not as good as RSA | Only compatible with Guomi (SM cryptography) browsers and systems |
| Features | Widely used, good compatibility Supports encryption and signing High computational load, slower than symmetric encryption Constantly growing key length requirements Vulnerable to quantum computing | Fast encryption/decryption, performs better in resource-constrained environments such as mobile devices and IoT devices. | Higher security/length ratio Better computational efficiency Lower bandwidth requirements Limited compatibility |
Supported encryption algorithms by brand:
Encryption algorithms
| Certificate type | RSA SHA256withRSA | RSA SHA384withRSA | ECC SHA256withECDSA | ECC SHA384withECDSA | SM2 SM3withSM2 |
|---|---|---|---|---|---|
| sslTrus DV | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| sslTrus OV | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| sslTrus EV | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Sectigo DV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| Sectigo OV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| Sectigo EV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| Digicert (Symantec) OV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| Digicert (Symantec) EV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| GeoTrust OV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| GeoTrust EV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| RapidSSL DV | ✔️ | ✔️ | ❌ | ❌ | ❌ |
| Globalsign DV | ✔️ | ✔️ | ❌ | ❌ | ❌ |
| Globalsign OV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| Globalsign EV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| CFCA (China Root) OV | ✔️ | ✔️ | ❌ | ❌ | ✔️ |
| CFCA (China Root) EV | ✔️ | ✔️ | ❌ | ❌ | ❌ |
Key Length
| Certificate Type | RSA 2048 | RSA 4096 | ECC prime256v1 | ECC secp384r1 | SM2 sm2p256v1 |
|---|---|---|---|---|---|
| sslTrus DV | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| sslTrus OV | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| sslTrus EV | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Sectigo DV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| Sectigo OV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| Sectigo EV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| Digicert (Symantec) OV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| Digicert (Symantec) EV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| GeoTrust OV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| GeoTrust EV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| RapidSSL DV | ✔️ | ✔️ | ❌ | ❌ | ❌ |
| Globalsign DV | ✔️ | ✔️ | ❌ | ❌ | ❌ |
| Globalsign OV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| Globalsign EV | ✔️ | ✔️ | ✔️ | ✔️ | ❌ |
| CFCA (China Root) OV | ✔️ | ✔️ | ❌ | ❌ | ✔️ |
| CFCA (China Root) EV | ✔️ | ✔️ | ❌ | ❌ | ❌ |