Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
spandex filament scopethis standard marine weathertight single-leaf steel doors zinc sulfide crystals introductionthis standard
GM/T 0043-2024 in English

GM/T 0043-2024 in English

VALID

Interoperability Testing Specification for Digital Certificates

  • Issued on:2024-12-27
  • Implemented on:2025-07-01
  • File Format:PDF
  • Delivery:Via email within 1~3 business days
Price(USD): $269.00
$261.00
Standard No: GM/T 0043-2024
Document status: VALID
Title in English: Interoperability Testing Specification for Digital Certificates
Title in Chinese: 数字证书互操作检测规范
Language: English
File Format: Electronic (PDF)
Delivery: Via email within 1~3 business days
Issued on: 2024-12-27
Implemented on: 2025-07-01


Introduction

Background of Standard Revision and Technological Evolution

GM/T 0043-2024 "Digital Certificate Interoperability Testing Specification," as an important standard for the cryptography industry, is the first comprehensive revision of the 2015 version. While maintaining the original technical framework, this revision focuses on strengthening the testing requirements for the Online Certificate Status Protocol (OCSP), reflecting the shift in the application of cryptographic technology in my country from infrastructure construction to refined operations. The standard was issued by the National Cryptography Administration and jointly drafted by seven organizations, including the Commercial Cryptography Testing and Certification Center, reflecting the wisdom of industry practice.


Technical Analysis of Core Testing Content

Technical Requirements for Root Entry Testing

Root entry testing is the basis for ensuring that the CA system can access the national PKI trust system. The standard requires that the CA system must have a complete functional chain of certificate application, import, and issuance. The CA certificate application document must strictly comply with the GM/T 0092 format specification and use the SM2 algorithm for digital signature. The signature algorithm OID is fixed at 1.2.156.10197.1.501.

Test items2015 version requirements2024 version new requirementsTechnical significance
CA certificate applicationBasic function requirementsStrengthen DN encoding specificationsEnsure certificate subject uniqueness
Certificate import functionBasic import capabilityAdd status verificationImprove system robustness
Issuance after root entryBasic issuance functionImprove trust chain establishmentEnsure system integrity

Digital certificate format compliance test

Terminal entity certificates must comply with GM/T 0015-2023 latest format requirements. Certificate basic field testing covers core elements such as version number, serial number, and signature algorithm. Of particular note is the certificate validity period encoding rule, which uses the UTCTime type before 2049 and the GeneralizedTime type after 2050. This provision addresses the Y2K38 time overflow issue.

OCSP Conformance Testing Innovation

The highlight of the 2024 version of the standard is the addition of OCSP conformance testing, requiring OCSP services to comply with the GB/T 19713 specification. Testing covers three aspects: request format, response format, and certificate status accuracy. OCSP response certificates must contain the id-kp-OCSPSigning OID to ensure the verifiability of the service identity.


Digital Certificate Interoperability Testing Mechanism

Certificate Trust Chain Establishment

Establishing a trust chain is the foundation of interoperability and requires a complete verification path from the end-entity certificate to the national root CA. The newly added Basic Restrictions Extended Test strengthens certificate permission control and prevents certificate abuse. Both signing and encryption certificates must independently complete trust chain verification to ensure bidirectional security.

Signature Verification Interoperability

Using a smart cryptographic key or hardware cryptographic module as the certificate carrier, it requires calling the GM/T 0016 or GM/T 0018 standard interface. The SM2 signature preprocessing process must strictly comply with the GM/T 0009 specification to ensure signature data compatibility between different systems.

Encryption and Decryption Interoperability

Encryption certificate interoperability testing uses a session key mechanism to simulate actual application scenarios. The test process requires real-time verification of certificate status and trust chain, reflecting the security concept of defense in depth.


Detection methods and judgment rules

Detection stageDetection methodQualification standardTechnical points
Root entry detectionFunction verification + file analysisFull complianceBase64 encoding verification
Format detectionCertificate analysis + CRL downloadStrict format complianceExtended field integrity
Interoperability detectionTwo-way communication testNormal function + Complete trust chainReal-time status verification

The judgment rule adopts the key item veto mechanism. For systems that provide OCSP services, all test items are considered critical. For those that do not, all test items except 6.2.4 are critical. This differentiated design ensures both security and flexibility in actual deployment.


Standard Implementation Recommendations and Industry Impact

CA System Modification Recommendations

Existing CA systems should prioritize upgrading the OCSP service module to ensure that the request and response formats comply with GB/T 19713. The certificate generation module needs to enhance its ability to handle basic restriction extensions, and the encoding of the DN item must strictly adhere to the rules for using PrintableString, IA5String, and UTF8String.

Testing and Certification Preparation

The submitting entity should prepare complete technical documentation in advance, including system architecture diagrams, topology diagrams, and a list of cryptographic algorithms. A realistic interoperability environment is required during testing, and establishing a test PKI system for pre-testing is recommended.

Industry Application Impact

The implementation of this standard will significantly enhance the interoperability of my country's digital certificate system and lay a technical foundation for cross-domain and cross-system digital identity authentication. This will particularly drive the transformation of cryptographic applications from single-point implementation to systematic development in key areas such as government affairs, finance, and healthcare. Application Case: Cross-Domain Authentication for E-Government A provincial government platform successfully achieved mutual identity recognition with a national platform after adopting testing and certification based on this standard. Through rigorous certificate format compliance testing and trust chain establishment, it ensured identity authenticity and non-repudiation during cross-domain access, processing over 100,000 interoperability requests daily and reducing the failure rate to below 0.01%.

Sample only — not a preview of GM/T 0043-2024
Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.

We also recommend