Bidirectional Authentication Guarantee (Strict mTLS)
Keeps Client Authentication and Server Authentication extensions enabled by default, simplifying mTLS deployment.
The sector-specific public key infrastructure solution designed for critical machine-to-machine connections, mTLS and API gateways outside web browsers.
DigiCert X9 PKI for TLS is a digital public key infrastructure certificate designed in direct collaboration with the Accredited Standards Committee X9 (ASC X9), the regulatory body for cybersecurity standards for the financial sector in the United States.
Unlike traditional WebPKI certificates—whose policies and lifecycles are regulated by commercial browsers like Chrome, Safari or Edge—DigiCert X9 is governed by an independent certificate policy backed by a common root of trust. This ensures interoperability, long-term technical stability and strict bidirectional authentication in private environments and B2B corporate interconnections.
Keeps Client Authentication and Server Authentication extensions enabled by default, simplifying mTLS deployment.
Avoids operational disruptions caused by sudden changes in everyday browser policies, by operating under ASC X9 standard governance.
Rigorously complies with the requirements and security standards established by the ASC X9 committee for banking transactions and confidential data exchange.
Secures up to 250 domains/subdomains under a single cryptographic piece, with unlimited reissuances and intangibles during the contracted term.
Full compatibility with RSA keys from 2048 to 4096 bits and ECC elliptic curves p-256 / p-384.
Infrastructure designed for mission-critical communications.
Strict bidirectional authentication where both the origin server and the receiving machine mutually validate their identities before exchanging data.
Critical backend integrations between servers from different companies (for example, payment gateways, transaction processors and business partners).
Internal communication channels for banking entities, automated teller machine (ATM) network integration, fund settlement and electronic transfers.
Robust hardware and node authentication in high-security private networks.
| Attribute | Specification |
|---|---|
| Validation Type | Organization (OV — Organization Validation) |
| Governance / Standard | Accredited Standards Committee X9 (ASC X9) |
| Extended Key Usage (EKU) | Client Authentication and Server Authentication (Dual EKU by default) |
| Multi-Domain Capability (SAN) | Includes Primary Domain (FQDN/Wildcard) + up to 249 additional domains |
| Supported Algorithms | RSA and ECC (Elliptic Curve Cryptography) |
| RSA Key Length | 2048-bit, 3072-bit, 4096-bit |
| ECC Key Length | Curve p-256, p-384 |
| Reissuances | Unlimited and free during the validity period |
| Use in Web Browsers | Exclusive for host-to-host applications, APIs, and private networks (not recommended for traditional web consumption) |
Unlike certificates from the public WebPKI of browsers, DigiCert X9 is designed exclusively for machine-to-machine (host-to-host) communications. It is governed under the certificate policy independent of the ASC X9 standard, which prevents it from being affected by changes or restrictions imposed by browsers such as Chrome or Safari for the use of Client Authentication.
This "Dual EKU" configuration comes enabled by default to allow mTLS authentication directly. In this way, both the server sending the information and the client receiving it mutually authenticate their identities in the TLS handshake.
It is not recommended. Although it is issued on a trusted commercial root, consumer browser policies may reject certificates that contain Client Auth by default. For public web pages or e-commerce, it is recommended to use the DigiCert Secure Site (OV/EV) line.
As a certificate with Organization Validation (OV), CertiSur performs verification of the legal, tax, and operational existence of the requesting company. Once the validation process is completed, issuance is performed through the CertiSur Control Panel.
Talk to our cybersecurity specialists to evaluate your organization's architecture and receive a formal proposal tailored to your needs.