Which browsers support Guomi (SM cryptography) certificates?
At present, browsers that support Guomi certificates (that is, SSL/TLS certificates that comply with the GM/T 0024-2014 standard and use SM2/SM3/SM4 algorithms) are mainly domestic browsers and some browsers specifically developed to support Guomi standards. Major international browsers (such as Chrome, Firefox, Edge, Safari) do not support the Guomi algorithm stack by default.
The following are the main browsers that support Guomi certificates:
360 Secure Browser:
Support level: It is one of the browsers in China with the most complete Guomi support and the most active promotion. Requirements: A relatively new version (such as v10 or later) is required, and the "Guomi Root Certificate Program" needs to be enabled. When users visit a website deployed with a Guomi certificate, the browser will automatically recognize it and use Guomi algorithms for encrypted communication. Market share: It has a very high market share in China and is the most commonly used option for accessing Guomi-enabled websites.
RedLotus Secure Browser:
Support level: This is a browser developed by Dingxuan Company specifically designed to support Guomi standards. Features: It natively and deeply integrates support for Guomi algorithms (SM2/SM3/SM4) and the Guomi SSL protocol (TLCP). It is an important tool for testing and deploying Guomi environments. Use cases: It is often used in scenarios with extremely high Guomi compliance requirements, such as government and finance sectors.
QQ Browser:
Support level: Relatively new versions (please refer to the latest documentation for the specific version number; generally, a recent version is required) have also added support for Guomi certificates. Requirements: Users may need to confirm or enable relevant settings (which may vary between versions), but the overall support is good.
Sogou Browser:
Support level: Relatively new versions also claim to support Guomi algorithms and certificates. Requirements: Similar to other domestic browsers, it is recommended to use the latest version.
Maxthon Browser:
Support level: Some versions support Guomi certificates, but users may need to confirm the specific support status and configuration method of its latest version.
Other domestic browsers/customized browsers:
Some domestic browsers deeply customized based on the Chromium kernel, or customized browsers used internally in specific industries (such as government affairs, finance), may also integrate Guomi support. Browsers in some Xinchuang (information technology application innovation) environments (such as browsers running on domestic operating systems like Kylin, UnionTech UOS) usually mandate or natively support Guomi algorithms by default.
Important notes and considerations:
International browsers (Chrome, Firefox, Edge, Safari):
They do not support the Guomi algorithm stack by default. They use internationally common algorithms (such as RSA/ECC, SHA-2, AES).
- Accessing Guomi websites: If a website only deploys a Guomi certificate (without deploying an international certificate at the same time), these browsers usually cannot access it and will report a secure connection error (such as ERR_SSL_VERSION_OR_CIPHER_MISMATCH).
- Dual certificate deployment: At present, most Guomi-supporting websites adopt the "dual certificate deployment" strategy, that is, deploying an international certificate (compatible with all browsers) and a Guomi certificate (for Guomi-supporting browsers) at the same time. In this way, international browsers connect using the international certificate, while Guomi browsers preferentially connect using the Guomi certificate, achieving both compatibility and compliance.
Mobile browsers:
- Android: The Android version of 360 Secure Browser, RedLotus Browser, etc. usually also support Guomi. Customized browsers from some mobile phone manufacturers may also support it.
- iOS: Due to Apple system restrictions, third-party browsers on iOS (including the iOS versions of the above-mentioned browsers) usually cannot fully support the Guomi algorithm stack, because they must use the network encryption library provided by the system. It will be difficult to access websites that only deploy Guomi certificates on iOS.
How to verify whether a browser supports Guomi?
Visit a dedicated Guomi test website (such as https://sm2test.ovssl.cn, please pay attention to security and website availability). If you can access the website successfully, a lock icon appears in the browser address bar; click the lock icon to view connection details. If the cipher suite contains terms such as ECC-SM2-SM4, SM2, SM3, SM4, it means the current connection uses Guomi algorithms. In 360 Browser, if the connection is successfully established via Guomi, the word "Guomi" or a corresponding icon is usually displayed next to the lock icon in the address bar.