[Upgrade] Notice on the Activation of New Intermediate Certificates for sslTrus
Dear Valued Customers and Partners:
Hello! Thank you very much for your continued trust and support for Racent.
In accordance with the latest root certificate trust policy of the globally renowned trust store Mozilla and industry specifications, all trusted root certificates of Certificate Authorities (CAs) worldwide must be replaced at least once every 15 years after generation. The Sectigo trusted root certificates that Racent cooperates with will be upgraded in compliance with this policy. Racent plans to gradually activate new intermediate certificates to issue SSL certificate products for users starting from February 2026 for the sslTrus SSL certificates under the Sectigo root series. The new root maintains unchanged compatibility while improving certificate security.
Upgrade Details
sslTrus SSL certificates (Sectigo root series) will be issued using the new intermediate certificate system, with relevant details as follows:
Before the activation of the new intermediate certificates, all previously issued SSL certificates can be used normally;
After the activation of the new intermediate certificates, all newly issued SSL certificates (including new issuance, reissuance, etc.) will be issued under the new intermediate certificate system.
The intermediate certificate upgrade updates are as follows:
| Original Intermediate Certificate | New Intermediate Certificate | Related Certificate Products |
|---|---|---|
| sslTrus (RSA) DV CA | sslTrus RSA DV SSL CA 2 | sslTrus DV Series SSL Certificates (RSA) |
| sslTrus (RSA) OV CA | sslTrus RSA OV SSL CA 2 | sslTrus OV Series SSL Certificates (RSA) |
| sslTrus (RSA) EV CA | sslTrus RSA EV SSL CA 2 | sslTrus EV Series SSL Certificates (RSA) |
| sslTrus (ECC) DV CA | sslTrus ECC DV SSL CA 2 | sslTrus DV Series SSL Certificates (ECC) |
| sslTrus (ECC) OV CA | sslTrus ECC OV SSL CA 2 | sslTrus OV Series SSL Certificates (ECC) |
| sslTrus (ECC) EV CA | sslTrus ECC EV SSL CA 2 | sslTrus EV Series SSL Certificates (ECC) |
Notes
- After the upgrade, Sectigo Public Server Authentication Root R46 will be used as the top-level root by default, which adopts the SHA384 signature algorithm to improve security.
| Comparison Item | Old Root Certificate | New Root Certificate |
|---|---|---|
| Name | USERTrust RSA Certification Authority | Sectigo Public Server Authentication Root R46 |
| Validity Period | February 1, 2010 - January 19, 2038 | March 22, 2021 - March 22, 2046 |
- The new root certificate (Sectigo Public Server Authentication Root R46) has completed cross-certification with the old root certificates (USERTrust RSA Certification Authority and AAA Certificate Services), and is compatible with mainstream operating systems, mobile devices, or JDKs.
Racent will continue to provide you with SSL certificates and SSL certificate automation solutions. If you have any questions about this upgrade, please feel free to contact us, and we will assist you in navigating this process smoothly. You can obtain professional support and services from Racent via online customer service or by calling the service hotline at 400-002-9968. Thank you again for your support and trust!