Huawei and TrustAsia propose ACME extension for Chinese SM2 compliance
Huawei and TrustAsia have submitted an IETF informational draft proposing an extension to the ACME protocol. The extension introduces an 'auth-01' challenge type to facilitate the automated issuance of SM2 dual-certificates for compliance within Chinese cryptographic infrastructure.
Key Takeaways
- The draft introduces a new 'auth-01' challenge type for automated SM2 encryption certificate issuance
- The system utilizes two separate orders to manage the mandatory signature and encryption certificate pair
- Proposed extensions add optional 'authKey' and 'includeEnvelope' fields to the standard ACME newOrder request
- The extension maintains compatibility with existing ACME resource models without altering core state machine semantics
Why It Matters
This proposal represents a critical technical bridge for multinational streaming entities operating in China, where SM2 cryptographic standards are legally mandated for data in transit. By automating the management of dual-certificate systems, providers can maintain high-frequency certificate rotation and security without the manual overhead typically associated with localized compliance. As the industry moves toward shorter certificate lifespans and automated PKI, this move ensures that localized regulatory requirements do not become a bottleneck for automated CDN and video delivery workflows. Watch for IETF feedback on the 'auth-01' challenge security model in late 2026.
Additional Context
The proposal aligns with China's tightening regulatory environment regarding commercial cryptography. Under the Cryptography Law of the People's Republic of China, which took effect in January 2020, and subsequent Data Security Management Rules effective January 2025, commercial entities are required to use indigenous SM-series algorithms (SM2, SM3, and SM4) for protecting sensitive data. Per HICOM, November 2025, these mandates are increasingly strictly enforced for data in transit, making traditional international standards like RSA and AES insufficient for full legal compliance in the region. This push for ‘technological sovereignty’ has forced infrastructure providers to adapt global protocols for local use cases. Simultaneously, the global PKI ecosystem is shifting toward a dual-certificate paradigm to address different challenges. Per the IETF, July 2026, there is ongoing standardization for Post-Quantum Traditional (PQ/T) hybrid authentication, which also utilizes two independent certificates to ensure security against quantum computing threats. While the Huawei and TrustAsia draft focuses on localized compliance rather than post-quantum resilience, it utilizes a similar architectural approach by separating signature and encryption functions. This suggests a broader industry trend where systems must accommodate multiple, concurrently valid certificate chains for different functional or regulatory purposes. Automation through ACME is becoming non-negotiable as certificate validity windows shrink. Per SSL Reminder, January 2026, the CA/Browser Forum has initiated a policy to reduce maximum certificate lifespans, with a first step capping new certificates at 200 days as of March 2026. In this high-rotation environment, manual certificate management for regional compliance like SM2 is no longer viable for large-scale streaming operations. The proposed extension therefore bridges a gap between the mandatory automation of the global web and the specific sovereign requirements of the Chinese market.
Read full article at datatracker.ietf.org
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source