ZoTrus Dual-Algorithm SSL Certificate Automation Subscription Service

SM2 ACME Client - SM2cerBot Open Source
Free SM2 ACME Public Service for dual-algorithm SSL certificate
Complies with the draft industry standard for "Automatic Certificate Management Specification"
One-click automatic for free SM2 SSL certificates and ECC SSL certificates
One-click automatic for charged SM2 OV SSL / EV SSL certificates

For website administrators, they are dissatisfied that the SSL certificate application and deployment process is very cumbersome and laborious. Our product is a solution for automatic application and deployment of SSL certificates to implement https encryption, which only need to install a client software once, and can permanently and automatically apply for and deploy dual SSL certificates to achieve https encryption, including RSA algorithm https encryption and SM2 algorithm https encryption.

Our solution is not like a traditional CA that only sells SSL certificates to customers, then installs it in the Web server by themselves. We provide customers with client software, and once installed, there is no need to spend time and effort applying for and install SSL certificates. And unlike other ACME clients that only provide RSA algorithm SSL certificates, we provide RSA algorithm and SM2 algorithm dual SSL certificates to meet the application requirements for cryptography compliance and global trust.

ZoTrus not only provides free public SM2 ACME service, but also open-source SM2 ACME client software - SM2cerBot, to provide users with complete dual-algorithm SSL certificate automation services. Users can directly use the open source client software to apply for a completely free dual-algorithm SSL certificate to achieve automatic adaptive algorithm HTTPS encryption, or follow “Automatic Certificate Management Specification” standard, and programming to connect with the certificate automation service provided by ZoTrus Cloud SSL Service System, and automatically complete the certificate application, domain name validation, and certificate retrieve and installation after the certificate issued.

1. Service Introduction

SSL certificate management is often overlooked yet crucial in website maintenance. Statistics show that over 30% of website outages stem from expired SSL certificates, resulting in incalculable annual business losses. Starting March 15, 2026, the validity period of SSL certificates will be shortened from one year to six months. This means that what used to be an annual renewal will now require at least six months, inevitably leading to more website service disruptions. Even more alarming, the validity period will be further reduced to three months on March 15, 2027, and to one and a half months on March 15, 2029.

Faced with this transformation, the traditional manual certificate management model of application, validation, download, and deployment is no longer feasible. Whether for small and medium-sized enterprises or large organizations, an intelligent and automatic solution is needed to cope with the increasingly shorter certificate lifecycles. Currently, international automatic certificate management (ACME) services, such as Let's Encrypt, can only automate the management of SSL certificates using RSA/ECC algorithms, failing to meet the compliance and security requirements of China for SM2 algorithms.

ZoTrus Technology launched the SM2 ACME Public Service based on this real need. It simultaneously provides automatic management of dual algorithm SSL certificates using both the SM2 algorithm and RSA/ECC algorithm. This is not only a technological complement but also a timely solution driven by both policy and market forces. Note the phrase "public service" — it means providing automatic dual-algorithm SSL certificate services free of charge, without discrimination or restrictions. The free automatic configured SM2 SSL certificate (DFCA SM2 root CA) is shown in the left figure below, representing the SM2 certificate chain. The free automatic configured ECC SSL certificate (SSL.com ECC root CA) is shown in the right figure below, representing the ECC certificate chain.

ZoTrus Technology launched the SM2 ACME Public Service ZoTrus Technology launched the SM2 ACME Public Service

The dual SSL certificate auto-configures by ZoTrus free SM2 ACME Public Service are 90-day validity certificates, meeting the validity period compliance requirements in advance, and will automatically switch to 47-day validity certificates before March 2029.

ZoTrus Technology launched the SM2 ACME Public Service ZoTrus Technology launched the SM2 ACME Public Service

2. Practical Path of SSL Certificate Application Ecosystem: The Value of Immediate Action

SSL certificates are essential for implementing HTTPS encryption, which is a core foundation for the security of the Internet of Things. ZoTrus free SM2 ACME Public Service is a much-needed solution for the entire SSL certificate application ecosystem in China.

Practical Path of SSL Certificate Application Ecosystem

2.1 Website owners: Zero barriers to entry usher in the era of automation

For website administrators and small and medium-sized business owners, ZoTrus SM2 ACME service provides the most direct solution with extremely simple operation, automated deployment can be completed in just three steps: download and compile the open-source SM2cerBot client, run the command line to configure the domain name and account email, and set up a scheduled task to automatically renew the certificate.

  • Dual certificate compatibility: The system provides both SM2 algorithm SSL certificates and RSA/ECC algorithm SSL certificates, ensuring global trust and China cryptographic compliance, and guaranteeing barrier-free access for users both domestically and internationally.
  • Maximizing cost-effectiveness: The completely free public service reduces the annual certificate fee of several thousand yuan to zero, while avoiding service interruption losses caused by certificate expiration. Most importantly, it significantly reduces the labor costs of maintenance engineers.

Action Recommendation: If your website does not yet have automatic certificate management enabled, deploy it immediately. With the implementation of the new certificate policy on March 15th, traditional certificate management methods will face significant challenges, and your website may experience service disruptions due to failure to renew certificates on time.

2.2 Cloud service providers: rapidly enhancing product competitiveness

For cloud service providers, ZoTrus open-source solution presents an excellent opportunity to rapidly enhance product competitiveness. The technology integration path is clear: based on the SM2cerBot open-source code, it enables rapid development of certificate management modules adapted to their own platforms, integration of the SM2 ACME protocol support into existing cloud management platforms, and the provision of one-click automatic services for both SM2 and ECC SSL certificates to cloud service customers.

  • Enhancing user engagement: Providing free automatic certificate management can significantly reduce user churn. Data shows that cloud platforms offering integrated certificate automation services see a 23% increase in user renewal rates.
  • Seizing the market opportunity: With the mandatory promotion of SM2 algorithms in government, finance and other industries, cloud platforms that have the ability to automatically manage both SM2 SSL certificates and ECC SSL certificates will have a significant advantage in the high-end market.
  • Diversified business model: Basic certificate automation services are offered for free, while a paid version with advanced features can be launched to create new revenue streams.

Action Recommendation: Cloud service providers' technical teams should immediately evaluate the SM2cerBot code, develop an integration plan within a month, and strive to launch relevant automatic certificate management functions before the full implementation of the new certificate policy, thereby seizing the market opportunity.

2.3 Network security equipment manufacturers: Building next-generation security hardware

For network hardware vendors and cryptographic vendors such as SSL VPN, load balancers, and WAF devices, integrating the SM2 ACME service presents an excellent opportunity for product upgrades. The technical integration path is clear: embedding the core functionality of SM2cerBot into the device firmware, providing a web management interface for configuring automatic certificate services, and enabling automatic certificate management after a device software upgrade and reboot.

  • Product differentiation: Network security devices that support automatic management of dual-algorithm SSL certificates will stand out in a fiercely competitive market with similar products, meeting the compliance requirements of government, finance and other critical information infrastructure industries for SM2 algorithms.
  • Reduced operation and maintenance costs: Integrating completely free automatic certificate services can significantly reduce the overall cost of equipment, while also reducing the certificate service burden on manufacturers and improving customer satisfaction.
  • Forward-looking strategy: As post-quantum cryptography algorithms mature, devices with automatic certificate management capabilities will be able to smoothly transition to the new algorithms, protecting customer investments.

Action Recommendation: Network security equipment manufacturers should immediately launch product integration projects to embed the ZoTrus open-source SM2 ACME client into their next-generation products, forming a complete and advanced solution that combines hardware, software, and services.

2.4 Domestic operating system vendors: Enhancing the native competitiveness of their systems

For domestic operating system manufacturers, integrating the SM2 ACME service is an important means to enhance product competitiveness. The technologically advanced integration path is clear: pre-installing SM2cerBot as a native system component, deeply integrating it with the system's web server, and developing a graphical certificate management interface to lower the user threshold and achieve a closed-loop integration of the domestic operating system and the SM2 SSL certificate ecosystem.

  • Alignment with top operating systems: Major operating systems (such as Windows Server and Linux distributions) already support ACME service. Integrating the SM2 ACME service into domestically developed operating systems not only meets the specific needs of the domestic market but also keeps pace with international technical standards, greatly enhancing the product's market competitiveness.
  • Enhance system security: By default, dual-algorithm SSL certificate automatic management is enabled to ensure that the security of the domestic operating system at the Web service level complies with national standards and meets the needs of high-security scenarios such as government and banks.
  • Promoting the development of the application ecosystem: Providing out-of-the-box automatic certificate management solutions for web applications based on domestic operating systems reduces the difficulty for developers to deploy HTTPS encryption services, while also reducing usage costs, which will greatly promote the prosperity of the entire domestic software ecosystem.

Action Recommendation: Domestic operating system manufacturers should immediately launch a automatic certificate management system integration project, adding SM2cerBot as a standard component to the next system version to form an overall advanced solution of "domestic operating system + SM2 certificate automation".

3. Dual-Algorithm Parallelism: A Smart Choice Balancing Security and Compatibility

ZoTrus SM2 ACME Public Service is its dual-certificate system, which utilizes both Chinese and international cryptographic algorithms. This design aligns with China's commercial cryptography promotion policies while also taking into account the complexity and diversity of real-world network environments. Especially in scenarios involving cross-border access and international business, the dual-certificate system ensures smooth user access.

The dual SSL certificates use elliptic curve algorithms: SM2 for the domestic standard and ECC internationally. Both provide 256-bit security strength, which is roughly equivalent to 3072-bit RSA, with shorter keys, faster computation, and superior performance in high-concurrency scenarios.

Against the backdrop of the looming threat of quantum computing, a dual-algorithm certificate system holds particular strategic significance. It provides a practical framework for a smooth transition to quantum-resistant cryptographic algorithms. Through an automatic management system, websites can implement hybrid PQC algorithm HTTPS encryption simply by upgrading their web servers to support post-quantum cryptographic algorithms, without impacting service. This provides a migration practice for a smooth transition to pure post-quantum cryptographic algorithms.

4. The Power of Open Source: SM2cerBot Will Change the Game

If free SM2 SSL certificate services solved the problem of "what is available", then the completely open-source SM2cerBot solves the crucial problem of "how to use it". The release of this SM2 ACME client software as an open-source project has profound industry significance.

Open source signifies transparency, trustworthiness, and scalability. Anyone can review code security, offer suggestions for improvement, and even develop customized versions to suit their needs. This open model accelerates technological innovation and ecosystem development. Developers can find the complete code for SM2cerBot on the GitCode/AtomGit open-source platform and perform secondary development and feature extensions as needed. This open strategy helps foster a healthy ecosystem for the application of SM2 SSL certificates.

Open-source certificate automation tools extend far beyond certificate management itself; they provide the entire industry with a standardized path to address the challenges of cryptographic algorithm migration. Once post-quantum cryptographic algorithm standards are established, automatic systems based on the ACME protocol can quickly adapt, enabling rapid algorithm upgrades across the entire network.

5. The Future of Automation: From "Managing Certificates" to "Certificate Self-Healing"

ZoTrus SM2 ACME service lies in transforming traditional manual management of SM2 SSL certificates into a fully automated process. This transformation is not merely an improvement in efficiency, but a revolution in security concepts.

Imagine if the application, validation, issuance, deployment, and renewal of all SM2 SSL certificates and RSA/ECC SSL certificates required by critical information system were fully automated. Maintenance personnel would only need to set initial policies, and the system could autonomously manage the entire lifecycle of the dual algorithm SSL certificates. This "set-and-forget" approach not only significantly reduces the possibility of human error but also greatly enhances the security level of critical information system.

From a longer-term perspective, automatic certificate management systems are the infrastructure for building quantum-safe networks. When post-quantum cryptography algorithms mature and need to be fully deployed, automatic systems can coordinate large-scale, complex algorithm migration processes, ensuring a secure and smooth transition for the entire network.

6. Profound Impact: Technological Changes Beyond Certificate Management

ZoTrus SM2 ACME service will extend far beyond certificate management itself; its launch may mark a significant shift across multiple industries. From a policy perspective, this service actively responds to China's policy direction of promoting commercial cryptography. Promoting the application of SM2 SSL certificates in a free and automatic manner will help accelerate the practical application of SM2 algorithms.

From a technological development perspective, the open-source ACME client provides a new reference case for the development of domestically developed basic software. Developers can use this codebase to create versions suitable for various operating systems and environments. From a security strategy perspective, the establishment of an automatic certificate management system provides a foundation for addressing quantum computing threats. Whether algorithm upgrades, key rotations, or certificate policy adjustments, the automatic system ensures that security measures are deployed quickly and consistently across the entire network.

From a business model perspective, ZoTrus "free basic service + paid professional services" model ensures both the accessibility of its services and creates market space for high-quality professional services. Users can flexibly choose according to their own needs, forming a virtuous cycle.

ZoTrus Technology firmly believes that its free ACME certificate service, through open-source software tools, will enable the rapid integration of SM2 algorithms into every layer of encrypted communication on China's Internet, truly ensuring the security of China's cyberspace with domestically developed cryptographic algorithms. More cloud service providers will integrate the SM2cerBot open-source code into their products, and network security equipment manufacturers and domestic operating system vendors will also begin launching product features based on automatic HTTPS encryption using Chinese cryptographic standards. This seemingly minor automation of SM2 SSL certificate management is paving the way for the upgrading of China's internet infrastructure.

This seemingly ordinary corner of digital security is rapidly transforming into one of the most active areas of technological innovation across the entire chain, from daily operations and maintenance to quantum defense. Its true value will gradually emerge over the next five years, laying a solid foundation for the upcoming major migration of cryptographic algorithms.

HTTPS encryption, what you need is automated application, deployment, and renewal of SSL certificate!

The SM2 ACME service not only allows you to automatically deploy SSL certificates, but also deploys dual-algorithm dual-SSL certificates to achieve https encryption globally trust and cryptography compliance!
SSL auto-deploy (SM2)

1 click install, 2 SSL auto-deploy (SM2)

Completely free, one-click installation
One-time installation, permanently and automatically get a free 90-day SM2 SSL certificate
Support charged SM2 OV SSL / EV SSL certificate
Support SM2 Certificate Transparency, full SM2 certificate chain
SSL auto-deploy (ECC)

1 click install, 2 SSL auto-deploy (ECC)

Completely free, one-click installation
One-time installation, permanently and automatically get a free 90-day ECC SSL certificate
Support International Certificate Transparency, full ECC certificate chain
always SM2 https encryption

1 click running, always SM2 https encryption

One-click deployment of SM2 SSL certificate, cryptography protection compliance
One-click running, providing SM2 https encryption service without interruption
Auto-renew certificate to ensure uninterrupted SM2 https encryption services
Support all browsers, self-adaptive encryption algorithm, ZT Browser adopts SM2 algorithm
always ECC https encryption

1 click running, always ECC https encryption

One-click deployment of ECC SSL certificate, cryptography protection compliance
One-click running, providing ECC https encryption service without interruption
Auto-renew certificate to ensure uninterrupted ECC https encryption services
Support all browsers, self-adaptive encryption algorithm, non-SM2 Browser adopts ECC algorithm
Recommended TongsuoSSL Middleware

Recommended TongsuoSSL Middleware

Download TongsuoSSL Middleware
Compile with support for SM2 algorithms
Supports TLS 1.3 SM2 algorithms
Supports hybrid PQC algorithm - SM2MLKEM768
90-day free certificate

Support 90-day free certificate and 1-year paid certificate

Auto-complete domain control validation, auto-configure free 90-day dual SSL certificate (SM2 and ECC)
Automatic application, deployment, and renewal
Need to register for a ZoTrus ACME account, and log into account to order charged service.