A new standard for host-to-host authentication without relying on WebPKI
In an environment where commercial web browser policies (such as Chrome or Safari) constantly modify the rules for public infrastructure certificates (WebPKI), organizations face serious challenges in maintaining the stability of their private connections between servers. To provide an official response to this corporate market need, CertiSur presents the DigiCert X9 PKI for TLS solution, a digital private/sectorial public key infrastructure certificate designed specifically for machine-to-machine (host-to-host) communication. Developed in collaboration with the Accredited Standards Committee X9 (ASC X9), a leading body in defining cybersecurity standards for the financial sector, this certificate operates under an independent issuance policy not affiliated with traditional browsers, guaranteeing operational continuity and maximum interoperability thanks to the support of a common commercial trust root.
The technical architecture behind DigiCert X9
The most significant differentiating value of DigiCert X9 PKI for TLS lies in its technical architecture: it is an Organization Validation (OV) certificate that natively and unconditionally includes Extended Key Usage (EKUs) extension fields for Server Authentication and Client Authentication simultaneously. This characteristic makes it the ideal alternative for implementing mTLS (Mutual TLS), ensuring strict bidirectional authentication where both the origin server and the receiving machine reciprocally validate their cryptographic identity. Additionally, the solution stands out for its high operational flexibility: it allows protecting up to 250 domains in a single unit, supports RSA encryption algorithms (keys of 2048, 3072, and 4096 bits) and ECC (p-256 and p-384 curves), and includes unlimited reissuances and duplicates throughout its entire lifecycle.
Critical use cases: API gateways, banking sector, and corporate IoT
Since it was not designed for everyday open web browsing, the DigiCert X9 certificate is exclusively oriented toward protecting mission-critical environments where security and stability are priorities. Its main applications include secure API gateways for B2B integrations (such as communication between merchants and payment processors), banking and financial environments that operate interbank transfers, automated teller machine (ATM) networks and fund clearing under ASC X9 regulations, and authentication of hardware and IoT devices in high-security private networks. With the incorporation of this technology, companies in the region can simplify the management of their mTLS cryptographic credentials with the support, local expertise, and omnichannel management platform of CertiSur.
Fuente: DigiCert