[Upgrade] Important Notice on Root System Upgrade to G2 and Annual Intermediate Root Update for CFCA Global Trust Server Certificates (China Root Pro, China Root)
Dear valued customers and partners,
We would like to extend our sincere gratitude for your continuous trust and support in Racent.
We have recently received notification from CFCA (China Financial Certification Authority): to comply with the latest compliance requirements of the root certificate programs of mainstream browsers such as Google Chrome, China Financial Certification Authority (CFCA) will soon launch two major security upgrades: the migration of the SSL certificate root system to G2, and the annual intermediate root certificate update mechanism. To ensure a smooth transition of your business, we hereby explain the relevant changes as follows:
1. Overview of Changes
Change 1: SSL Certificate Root System Upgrade to G2
CFCA will migrate the issuance of all publicly trusted SSL/TLS certificates to the dedicated single-purpose G2 root certificate hierarchy. The upgraded certificate issuance paths are as follows:
● EV certificates: CFCA Global RSA ROOT G2 → CFCA EV RSA OCA G2 → Subscriber certificate ● OV certificates: CFCA Global RSA ROOT G2 → CFCA OV RSA OCA G2 → Subscriber certificate
The G2 root certificate has been cross-signed by the current CFCA EV ROOT root certificate, ensuring broad compatibility and trust on mainstream devices and platforms.
Change 2: Annual Intermediate Root Certificate Update Mechanism
CFCA will generate and activate a new intermediate root certificate approximately every 365 days to replace the previous generation intermediate root for subsequent certificate issuance. By shortening the lifecycle of intermediate roots, the overall security level of the certificate chain will be further enhanced.
2. Effective Time
| Change Item | Effective Time | Notes |
|---|---|---|
| Annual intermediate root update (first round) | June 2027 | The final time is subject to CFCA's official announcement |
| G2 root system upgrade | Mid-September 2026 | The final time is subject to CFCA's official announcement |
Note: The final effective time of the G2 root system upgrade is subject to formal confirmation from the Google Chrome Root Program. After receiving final confirmation, CFCA will release the final announcement through its official channel (https://www.cfca.com.cn/xwzx/ywgg/). Please make relevant preparations in advance during this period.
3. Impact and Risks to Your Business
1. Existing certificates — No impact
Certificates issued before the above dates and within their validity period can continue to be used normally. Their browser trust status and security attributes will remain unchanged, and no replacement is required.
2. Newly issued certificates — Automatic adaptation to the new system
Certificates newly applied for, renewed, reissued, or replaced after the effective date will be automatically issued under the G2 root certificate system. A complete certificate chain file will be provided together with the certificate. We recommend that your operation and maintenance personnel configure the latest intermediate root certificate chain simultaneously when deploying new certificates on the server (deploy the new top-level root certificate, intermediate root, and server certificate in combination).
3. Special scenarios — Advance adaptation required, otherwise there is a risk of business interruption
If your business system has any of the following configurations, it may cause certificate validation exceptions during root system migration or intermediate root replacement, and in severe cases, lead to business interruption:
(1) Hard-coded certificates: Root certificates or intermediate root certificates are hard-coded in system code, applications, client SDKs, or configuration files. Hard-coded certificates will become invalid after the root system upgrade, directly causing validation failures.
(2) SSL Pinning: A pinning policy is implemented for root certificates or intermediate root certificates. This mechanism cannot adapt to certificate hierarchy changes, which will seriously affect end-user compatibility and business continuity.
Special note regarding pre-embedded top-level root (intermediate root) certificates on clients: If you have pre-embedded the original top-level root (intermediate root) certificate on clients, new certificates issued under the new root certificate may cause client validation exceptions, which may further lead to service interruptions and other issues. We recommend that you remove the pre-embedded configuration in advance before the old certificates expire, and switch to the system's native trust store for validation.
With the shortening of certificate validity periods and the implementation of various new regulations, traditional certificate management models will face significant challenges. We recommend switching certificate management to an automated management solution as soon as possible. Automated management solutions can automatically complete the update and deployment of certificate chains, effectively reducing business risks.
4. Official Download Channels for Certificate Chains
You can visit the official CFCA website (www.cfca.com.cn) at any time to independently download the latest root certificate, intermediate certificate, and full certificate chain files:
Download path: CFCA official website homepage → Service & Support → Certificate Chain Download → Global Server Certificate Chain
If you have any questions, please feel free to contact our technical support team for assistance.
Racent (www.racent.com) is committed to automated SSL certificate operations and maintenance, providing automated solutions such as sslTrus CLM and CaaS. As a professional digital certificate vendor and compliance agent for world-renowned CAs, Racent also offers trusted digital certificate products.