GM/T 0043-2024 in English
VALIDInteroperability Testing Specification for Digital Certificates
- Issued on:2024-12-27
- Implemented on:2025-07-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$261.00
| Standard No: | GM/T 0043-2024 |
| Document status: | VALID |
| Title in English: | Interoperability Testing Specification for Digital Certificates |
| Title in Chinese: | 数字证书互操作检测规范 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 1~3 business days |
| Issued on: | 2024-12-27 |
| Implemented on: | 2025-07-01 |
Introduction
Background of Standard Revision and Technological Evolution
GM/T 0043-2024 "Digital Certificate Interoperability Testing Specification," as an important standard for the cryptography industry, is the first comprehensive revision of the 2015 version. While maintaining the original technical framework, this revision focuses on strengthening the testing requirements for the Online Certificate Status Protocol (OCSP), reflecting the shift in the application of cryptographic technology in my country from infrastructure construction to refined operations. The standard was issued by the National Cryptography Administration and jointly drafted by seven organizations, including the Commercial Cryptography Testing and Certification Center, reflecting the wisdom of industry practice.
Technical Analysis of Core Testing Content
Technical Requirements for Root Entry Testing
Root entry testing is the basis for ensuring that the CA system can access the national PKI trust system. The standard requires that the CA system must have a complete functional chain of certificate application, import, and issuance. The CA certificate application document must strictly comply with the GM/T 0092 format specification and use the SM2 algorithm for digital signature. The signature algorithm OID is fixed at 1.2.156.10197.1.501.
| Test items | 2015 version requirements | 2024 version new requirements | Technical significance |
|---|---|---|---|
| CA certificate application | Basic function requirements | Strengthen DN encoding specifications | Ensure certificate subject uniqueness |
| Certificate import function | Basic import capability | Add status verification | Improve system robustness |
| Issuance after root entry | Basic issuance function | Improve trust chain establishment | Ensure system integrity |
Digital certificate format compliance test
Terminal entity certificates must comply with GM/T 0015-2023 latest format requirements. Certificate basic field testing covers core elements such as version number, serial number, and signature algorithm. Of particular note is the certificate validity period encoding rule, which uses the UTCTime type before 2049 and the GeneralizedTime type after 2050. This provision addresses the Y2K38 time overflow issue.
OCSP Conformance Testing Innovation
The highlight of the 2024 version of the standard is the addition of OCSP conformance testing, requiring OCSP services to comply with the GB/T 19713 specification. Testing covers three aspects: request format, response format, and certificate status accuracy. OCSP response certificates must contain the id-kp-OCSPSigning OID to ensure the verifiability of the service identity.
Digital Certificate Interoperability Testing Mechanism
Certificate Trust Chain Establishment
Establishing a trust chain is the foundation of interoperability and requires a complete verification path from the end-entity certificate to the national root CA. The newly added Basic Restrictions Extended Test strengthens certificate permission control and prevents certificate abuse. Both signing and encryption certificates must independently complete trust chain verification to ensure bidirectional security.
Signature Verification Interoperability
Using a smart cryptographic key or hardware cryptographic module as the certificate carrier, it requires calling the GM/T 0016 or GM/T 0018 standard interface. The SM2 signature preprocessing process must strictly comply with the GM/T 0009 specification to ensure signature data compatibility between different systems.
Encryption and Decryption Interoperability
Encryption certificate interoperability testing uses a session key mechanism to simulate actual application scenarios. The test process requires real-time verification of certificate status and trust chain, reflecting the security concept of defense in depth.
Detection methods and judgment rules
| Detection stage | Detection method | Qualification standard | Technical points |
|---|---|---|---|
| Root entry detection | Function verification + file analysis | Full compliance | Base64 encoding verification |
| Format detection | Certificate analysis + CRL download | Strict format compliance | Extended field integrity |
| Interoperability detection | Two-way communication test | Normal function + Complete trust chain | Real-time status verification |
The judgment rule adopts the key item veto mechanism. For systems that provide OCSP services, all test items are considered critical. For those that do not, all test items except 6.2.4 are critical. This differentiated design ensures both security and flexibility in actual deployment.
Standard Implementation Recommendations and Industry Impact
CA System Modification Recommendations
Existing CA systems should prioritize upgrading the OCSP service module to ensure that the request and response formats comply with GB/T 19713. The certificate generation module needs to enhance its ability to handle basic restriction extensions, and the encoding of the DN item must strictly adhere to the rules for using PrintableString, IA5String, and UTF8String.
Testing and Certification Preparation
The submitting entity should prepare complete technical documentation in advance, including system architecture diagrams, topology diagrams, and a list of cryptographic algorithms. A realistic interoperability environment is required during testing, and establishing a test PKI system for pre-testing is recommended.
Industry Application Impact
The implementation of this standard will significantly enhance the interoperability of my country's digital certificate system and lay a technical foundation for cross-domain and cross-system digital identity authentication. This will particularly drive the transformation of cryptographic applications from single-point implementation to systematic development in key areas such as government affairs, finance, and healthcare. Application Case: Cross-Domain Authentication for E-Government A provincial government platform successfully achieved mutual identity recognition with a national platform after adopting testing and certification based on this standard. Through rigorous certificate format compliance testing and trust chain establishment, it ensured identity authenticity and non-repudiation during cross-domain access, processing over 100,000 interoperability requests daily and reducing the failure rate to below 0.01%.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GM/T 0139-2024 in English
Information System Password Application Security Management System
2024-12-27 -

GM/T 0135-2024 in English
Multi-Party Secure Computation Technical Framework
2024-12-27 -

GM/T 0001.4-2024 in English
Zu Chongzhi Sequence Cipher Algorithm Part 4: Authentication Encryption Mechanism
2024-12-27 -

GM/T 0134-2024 in English
Password Module Security Design Guide
2024-12-27 -

GM/T 0047-2024 in English
Security Electronic Signature Password Detection Specification
2024-12-27 -

GM/T 0039-2024 in English
Password Module Security Testing Requirements
2024-12-27 -

GM/T 0138-2024 in English
C-V2X Vehicle Networking Certificate Policy and Authentication Service Statement Framework
2024-12-27 -

GM/T 0136-2024 in English
Password Application HTTP Interface Specification
2024-12-27 -

GM/T 0137-2024 in English
Password Card Technical Requirements
2024-12-27 -

GM/T 0041-2024 in English
Smart IC Card Password Detection Specification
2024-12-27