Skip to content

Security1 publisher2 min readPublished

Under US Treasury sanctions, certificate authorities drop Russian and Iranian banks and state bodies

Russian banks moved to a state-run CA in August after GlobalSign mass-revoked its Russian customers' TLS certificates under May's US Treasury sanctions. Their customers now carry the problem, since Western browsers typically do not trust state-run CAs.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Under US Treasury sanctions, certificate authorities drop Russian and Iranian banks and state bodies
Generated illustration

What happened

  • Certificate authorities have spent three months revoking TLS certificates held by government and critical-sector entities in countries under US sanctions.
  • In July, every major SSL provider refused to issue certificates to Iran's state-run news agency.
  • Iranian banks switched to Chinese certificate providers this month to keep their sites online, according to Risky Bulletin.
  • Affected Russian and Iranian companies and agencies mostly saw short outages before switching to alternative CAs, Risky Bulletin reports.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint A sanctioned state body cannot replace one major CA with another. Its fallback is a state-run or foreign CA that its own users' software may not trust.
  • exposure Customers who already get trust failures from their real bank's site have less reason to stop at the same warning when an interception attempt produces it.
  • precedent CAs acted within about a month of the May rules. Entities named in future US sanctions should plan to lose mainstream certificates on that timescale.

Let's Encrypt set out the rule in June. CAs may still issue certificates in the sanctioned countries, but only to non-governmental people and organizations [8]. "Under applicable sanctions, we are not permitted to issue certificates to certain prohibited or restricted parties," Let's Encrypt wrote [9]. Everyone else is covered by exemptions: "As a result, we have not, and do not, block the use by non-governmental people and entities in comprehensively sanctioned countries and territories where those exemptions and authorizations are in place" [10].

That rule decides who needs a plan for certificate continuity [1][8]. The disruption reported so far has hit government networks, agencies and banks in Russia and Iran [2], plus a state news agency [5]. A foreign company with its own users or offices in those countries is a non-governmental party. On Let's Encrypt's reading, it can still get certificates where the exemptions apply [10].

Outside operators are exposed through what they depend on. Anyone who hosts, integrates with or relies on a sanctioned state body or bank is now dealing with endpoints certified by a Russian state-run CA or by Chinese providers [4][6]. For a merchant or payment processor with Russian or Iranian bank counterparties, those chains are the ones to test.

The detail for both countries comes from a single report, Risky Bulletin. It does not name the banks, the Russian state-run CA or the Chinese providers [4][6]. GlobalSign is the only CA it names, and only in connection with Russia [3]. It attributes the refusals in Iran to all major SSL providers [5].

What to watch

  • Any revocation of certificates held by non-governmental companies or people in Russia or Iran, past the line Let's Encrypt described in June.
  • Whether browser and operating system vendors add the Russian state-run CA or the Chinese CAs used by Iranian banks to their trust stores, or refuse them.
  • Reported certificate revocations for government or critical-sector entities in US-sanctioned countries other than Russia and Iran.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories