📄️ What is OCSP
This article provides an in-depth analysis of the core mechanism of the OCSP protocol, explains how it improves HTTPS security through real-time certificate status queries, analyzes OCSP's advantages over CRL in terms of performance and resource utilization, and recommends SSL certificate brands (such as sslTrus, CFCA) that support domestic OCSP signature verification to help enterprises optimize website security and access efficiency
📄️ What are Public Key and Private Key
This article analyzes the core differences between public keys and private keys (encryption/decryption, publicity/confidentiality), elaborates on their generation logic based on RSA/ECC algorithms, practical application scenarios in SSL certificates and digital signatures, and explains how to secure data transmission through the Public Key Infrastructure (PKI)
📄️ What are the advantages of sslTrus certificates
Advantages of sslTrus SSL certificates, domestic SSL certificate recommendations, OCSP local signature verification, cost-effective SSL certificates, certificate monitoring and security services
📄️ How to Check the OCSP of an SSL Certificate
This article provides detailed steps (with illustrated tutorials) to check the OCSP address of an SSL certificate, and explains how to determine the location of the OCSP server by domain name or IP. For users in Chinese mainland, we recommend SSL certificate brands that support local OCSP response verification (such as sslTrus, CFCA, etc.) to resolve HTTPS access latency issues and improve the speed and stability of certificate verification.
📄️ Is there a trial version of SSL certificates
sslTrus SSL certificates do not have a standalone trial version. This article details the application process and refund rules for using formal certificates for testing purposes, and provides zero-cost test certificate alternatives and risk prevention guidelines.
📄️ What Is the Difference Between HTTPS and HTTP
HTTP, fully known as HyperText Transfer Protocol, is an application-layer protocol for distributed, collaborative and hypermedia information systems. It is used to enable communication between client browsers and web servers, and serves as the foundation of network data communication
📄️ Which Browsers Support Guomi Certificates
Browsers that currently support Guomi certificates (i.e., SSL/TLS certificates compliant with the GM/T 0024-2014 standard and using SM2/SM3/SM4 algorithms) are mainly domestic Chinese browsers and some browsers specifically built to support Guomi standards. Mainstream international browsers (such as Chrome, Firefox, Edge, and Safari) do not support the Guomi algorithm stack by default.
📄️ Which Websites Must Enable HTTPS Encryption
In today's era where cybersecurity is highly valued, deploying an SSL certificate for a website is an important step to improve website security. It can enable HTTPS encryption and trusted identity authentication, prevent the leakage or tampering of transmitted data, and effectively ensure the security of data in transit
📄️ What are the Differences Between SSL Certificate Brands
Racent provides an in-depth comparison of the core differences among 6 mainstream SSL certificate brands including sslTrus, Sectigo, DigiCert and CFCA, covering validation levels, security assurance, compatibility and pricing strategies, to help you choose the right certificate accurately.
📄️ What are the certificate brands with data not leaving China
In accordance with the requirements of the Cybersecurity Law and the Data Security Law, we recommend SSL certificate brands such as sslTrus (domestic root) and CFCA whose certificates are fully issued and verified within mainland China, which meet the compliance requirements for government, finance and other scenarios.
📄️ Which Domains Are Supported by Wildcard SSL Certificates
A Wildcard SSL Certificate, also known as a wildcard SSL certificate or pan-domain SSL certificate, supports securing one primary domain and its lower-level subdomains, enabling HTTPS encryption for the primary domain and all its subordinate subdomains.
📄️ Maximum Number of Domains Allowed in a Multi-Domain Certificate
SSL multi-domain certificates support up to 250 domains by default, offer elastic scaling solutions, and provide detailed explanations of wildcard domain calculation rules and best practices for multi-certificate deployment in large enterprises.
📄️ Will a website be inaccessible if an SSL certificate is not installed?
Explain in detail the access status of a website when no SSL certificate is installed, analyze browser security warnings and functional restrictions, and provide certificate configuration solutions for HTTPS forced redirection
📄️ Can an IP address and a domain name be included in the same certificate
sslTrus SSL certificates support including both IP addresses and domain names in the same certificate. This article details the conditions for mixed deployment of DV/OV certificates, and provides a unified HTTPS encryption solution for corporate intranet and public network services
📄️ Issuance Restricted Regions and Specific Sanction Lists of CAs
SSL certificate issuance restrictions are jointly determined by international sanction policies, national regulations, and compliance requirements of Certificate Authorities (CAs). The following are common questions about specific restricted regions
📄️ Can I apply for multiple SSL certificates for the same domain
You can apply for multiple SSL certificates for a single domain. Each SSL certificate is independent of one another, with no restrictions on type or quantity. As long as your budget allows, you can apply for multiple SSL certificates of the same or different brands and types
📄️ Differences Between RSA and ECC Encryption Algorithms
The RSA encryption algorithm, whose full English name is Rivest–Shamir–Adleman, is an asymmetric encryption algorithm proposed in 1977 by Ron Rivest, Adi Shamir, and Leonard Adleman. RSA is formed from the initials of the three proposers' surnames.
📄️ What are the differences between Sectigo and Positive certificates
Comprehensively analyze the core differences between the Sectigo main brand and the PositiveSSL sub-brand, covering insurance amounts, validation levels, applicable scenarios and pricing strategies, to help you accurately choose the right SSL certificate.
📄️ Will EV SSL certificates show a green indicator in the browser?
A comprehensive explanation of display solutions after major browsers removed the green address bar for EV certificates, with detailed analysis of how EV certificates present enterprise information in Chrome, Firefox and Safari and their ongoing security value.
📄️ Is Huace Certificate a Domestic Brand
Huace Certificate is a domestic brand provided by Shenzhen CTI Certification and Testing Group (CTI). Founded in 2003, the group is a pioneer of third-party testing and certification services in China. It was listed on the Shenzhen Stock Exchange in 2009 and is headquartered in Shenzhen. It is a compliant choice for domestic SSL certificates.
📄️ Do Sectigo Wildcard Certificates Include the Primary Domain?
When you purchase a wildcard certificate (such as *.domain.com) from Sectigo, PositiveSSL, or sslTrus, the corresponding primary domain (domain.com) is automatically included for free, with no need for extra addition or payment. View the domain coverage rules for wildcard certificates now.
📄️ What Are the Major Domestic SSL Certificate Distributors
Major domestic SSL certificate distributors include: sslTrus (multi-brand distributor), CFCA (domestic certificate original vendor), WoTrus (Guomi (SM cryptography) compliance service provider), etc.
📄️ Can I place a multi-year order for Digicert EV SSL?
Due to compliance requirements, Digicert EV SSL certificates only support a 1-year validity period and cannot be purchased for multiple years; renewal is required every year. For long-term needs, it is recommended to choose Digicert OV Pro certificates (supporting 2-3 year validity), or reduce annual costs through bulk purchase discounts. View the analysis of EV certificate compliance policies.
📄️ Maximum Validity Period for Certificates Purchased for Internal IPs
Internal IP certificates support a maximum one-time purchase of 5 years! Process: 1) Fill in the information after placing the order and save it temporarily; 2) Contact Racent customer service to mark it as an internal IP certificate; 3) The 5-year certificate will be delivered all at once. No annual review required, providing long-term HTTPS encryption protection for internal systems.
📄️ What Are the Differences Between DV Certificates and OV Certificates
Core differences between DV certificates (Domain Validation) and OV certificates (Organization Validation): validation method (domain vs real-name enterprise verification), browser display (padlock only vs enterprise name), trust level (★★ vs ★★★★), price (low vs high), and issuance speed (within minutes vs 1–3 business days). Choose OV for corporate official websites and DV for personal blogs, with a scenario-based decision tree included.
📄️ Differences Between Private IP Certificates and Public IP Certificates
Core differences of IP SSL certificates: 1) Private IP certificates require no validation, are only trusted internally, and have complex deployment (supporting CFCA/sslTrus); 2) Public IP certificates require Domain Control Validation (DCV), are globally trusted, and have simple deployment (supporting Sectigo/Digicert, etc.). For enterprise internal networks, choose domestic private certificates; for public-facing services, use internationally authenticated certificates. A scenario selection matrix is attached.
📄️ Why Is the Validity Period of SSL Certificates Shortened
The validity period of SSL certificates is shortened mainly to reduce the risk of long-term certificate misuse, mitigate potential security vulnerabilities through more frequent updates, and thereby improve the overall security of internet communications and user trust.
📄️ Why CFCA SSL certificates require consistency between the domain name and the organization
The requirement for a CFCA SSL certificate application that the domain name matches the affiliated organization is to confirm that the certificate applicant holds legal ownership or management authority over the domain name, thus ensuring the authenticity and traceability of the server identity, and preventing malicious impersonation and online fraud.
📄️ Why Digicert EV Certificates Only Support Phone Verification
Enterprise verification for Digicert EV certificates can only be completed via phone call mainly to comply with the third-party independent verification requirements of the CA/B Forum. Manual phone verification is required to confirm the authenticity of the enterprise and the application intent, ensuring the strict identity verification standards for EV certificates.
📄️ Differences Between Public SSL Certificates and Internal SSL Certificates
Public SSL certificates are issued by trusted third-party Certificate Authorities (CAs) for use in the internet environment and are trusted by browsers by default; internal SSL certificates are issued by an enterprise's private CA, are limited to internal network use, and require manual trust of the private CA. Learn about the core differences and applicable scenarios of the two.
📄️ SSL Certificate Validity Shortened to Six Months
Per the latest requirements from the CA/Browser Forum, the validity period of SSL certificates has been adjusted to 199 days (approximately six months), a change designed to reduce the risk of long-term certificate misuse and improve internet communication security.
📄️ Can I apply for SSL certificates for ru domains
Currently only the GlobalSign brand supports issuing SSL certificates for ru domains; other CAs do not support this for now. If you need to apply for a certificate for a domain with the .ru suffix, please choose a GlobalSign product.
📄️ What Are the Mainstream SSL Certificate Formats
The mainstream SSL certificate formats include CRT/CER/PEM, PFX, and JKS, covering core scenarios such as web servers, Java, and Windows. Understand the characteristics and applicable scenarios of each format to help you correctly select and manage SSL certificates.
📄️ What are the respective validity periods for Domain Validation and Organization Validation certificates
Domain Validation (DV) SSL certificates have a validity period of 199 days, while Organization Validation (OV) SSL certificates have a validity period of 1 year. Understand the validity period differences of certificates at different validation levels to properly plan for Certificate Lifecycle Management.
📄️ Differences between CFCA China Root Pro and Standard OV certificates
The CFCA China Root Pro OV certificate protects the ordered domain and the complimentary main domain/www subdomain, while the non-Pro version only protects the domain filled in at the time of order. Learn the differences in protection scope between the two and choose the appropriate certificate type.
📄️ What Is CN OCSP and Its Uses
CN OCSP refers to local OCSP validation nodes deployed in the Chinese mainland region, which optimizes the access link for domestic network environments, resolves issues such as slow access, packet loss, and interception of overseas Certificate Authority OCSP servers within China, and improves the speed and stability of HTTPS handshakes.
📄️ Does sslTrus Support Issuing Guomi (SM cryptography) Certificates for Internal IPs
sslTrus currently does not support issuing Guomi (SM cryptography) algorithm certificates for internal IPs. If you need a Guomi (SM cryptography) certificate for an internal IP, you can choose the CFCA brand, which supports issuing Guomi (SM cryptography) algorithm certificates for internal IPs.
📄️ What Algorithms Does CFCA Document Signing Certificate Support
CFCA document signing certificates only support the RSA algorithm. Learn about the algorithm support for CFCA document signing certificates and choose the suitable signing certificate solution.
📄️ Does CFCA Document Signing Certificate include a UKey
The CFCA document signing certificate does not include a UKey. Customers need to use the exclusive two codes (serial number and authorization code) sent via email, and extract the certificate through the link provided in the email.
📄️ Why Are Overseas Nodes Added for Public SSL Certificate DCV
Adding overseas nodes for public SSL certificate Domain Control Validation (DCV) is a mandatory industry standard set by the CA/B Forum. Legitimate publicly trusted SSL certificates must comply with international security specifications, which require global multi-region node validation to prevent hijacking