DigiCert X9 PKI for TLS

The sector-specific public key infrastructure solution designed for critical machine-to-machine connections, mTLS and API gateways outside web browsers.

OV Issuance with Organization Validation
Dual EKU Client Auth + Server Auth by default
250 SAN domains in a single certificate
RSA · ECC 2048–4096 bit and p-256 / p-384 curves

What is DigiCert X9 PKI for TLS?

DigiCert X9 PKI for TLS is a digital public key infrastructure certificate designed in direct collaboration with the Accredited Standards Committee X9 (ASC X9), the regulatory body for cybersecurity standards for the financial sector in the United States.

Unlike traditional WebPKI certificates—whose policies and lifecycles are regulated by commercial browsers like Chrome, Safari or Edge—DigiCert X9 is governed by an independent certificate policy backed by a common root of trust. This ensures interoperability, long-term technical stability and strict bidirectional authentication in private environments and B2B corporate interconnections.

Key benefits for your organization

Bidirectional Authentication Guarantee (Strict mTLS)

Keeps Client Authentication and Server Authentication extensions enabled by default, simplifying mTLS deployment.

Public WebPKI Isolation

Avoids operational disruptions caused by sudden changes in everyday browser policies, by operating under ASC X9 standard governance.

Financial Regulatory Compliance

Rigorously complies with the requirements and security standards established by the ASC X9 committee for banking transactions and confidential data exchange.

Cost Savings and Scalability

Secures up to 250 domains/subdomains under a single cryptographic piece, with unlimited reissuances and intangibles during the contracted term.

Flexible Cryptographic Algorithms

Full compatibility with RSA keys from 2048 to 4096 bits and ECC elliptic curves p-256 / p-384.

Typical use cases / Applications

Infrastructure designed for mission-critical communications.

Mutual TLS (mTLS)

Strict bidirectional authentication where both the origin server and the receiving machine mutually validate their identities before exchanging data.

API Gateways and B2B Networks

Critical backend integrations between servers from different companies (for example, payment gateways, transaction processors and business partners).

Financial and Interbank Environments

Internal communication channels for banking entities, automated teller machine (ATM) network integration, fund settlement and electronic transfers.

IoT and Infrastructure Devices

Robust hardware and node authentication in high-security private networks.

Technical specifications table

Attribute Specification
Validation Type Organization (OV — Organization Validation)
Governance / Standard Accredited Standards Committee X9 (ASC X9)
Extended Key Usage (EKU) Client Authentication and Server Authentication (Dual EKU by default)
Multi-Domain Capability (SAN) Includes Primary Domain (FQDN/Wildcard) + up to 249 additional domains
Supported Algorithms RSA and ECC (Elliptic Curve Cryptography)
RSA Key Length 2048-bit, 3072-bit, 4096-bit
ECC Key Length Curve p-256, p-384
Reissuances Unlimited and free during the validity period
Use in Web Browsers Exclusive for host-to-host applications, APIs, and private networks (not recommended for traditional web consumption)

Frequently asked questions

  • Unlike certificates from the public WebPKI of browsers, DigiCert X9 is designed exclusively for machine-to-machine (host-to-host) communications. It is governed under the certificate policy independent of the ASC X9 standard, which prevents it from being affected by changes or restrictions imposed by browsers such as Chrome or Safari for the use of Client Authentication.

  • This "Dual EKU" configuration comes enabled by default to allow mTLS authentication directly. In this way, both the server sending the information and the client receiving it mutually authenticate their identities in the TLS handshake.

  • It is not recommended. Although it is issued on a trusted commercial root, consumer browser policies may reject certificates that contain Client Auth by default. For public web pages or e-commerce, it is recommended to use the DigiCert Secure Site (OV/EV) line.

  • As a certificate with Organization Validation (OV), CertiSur performs verification of the legal, tax, and operational existence of the requesting company. Once the validation process is completed, issuance is performed through the CertiSur Control Panel.

Ready to protect your mTLS connections and B2B integrations?

Talk to our cybersecurity specialists to evaluate your organization's architecture and receive a formal proposal tailored to your needs.