Does it mean that russian/iranian web-sites using letsencrypt stop working and need to change their certificate provider?
Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
31–40 of 404 posts
They already revoced certificates for some russian sites
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#32Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#33Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#34the reach is by rough estimates ~2.5–6 million websites globally, 2–5 million of those in Russia and 0.3-1 million in Iran
Whatever USofA, it's not hard to have their own cosmodrome and certificates.
Tangential, in 2026 website certificates feel like nothing, disposable automation artifact, toxic max-security[1], vehicle for those who rent seek, fingerprint.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#35This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership.
It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS.
That's digital tyranny in disguise.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#36Makes sense, they are US company. I am surprised it took them that long.
That's just another reminder that no one from outside of US should deal with US companies.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#37This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.
I always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Most simple services may not need TLS, but with the ISPs eavesdropping on our communication, a form of secure communication is required and the currently best solution we have requires a trust-chain to be built.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#38And now imagine that one of the Trump tantrums contains an announcement of sanctions against the European Union.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#39Can anyone explain me what went wrong with http://www.cacert.org/ and why they are not supported by any major browser ?
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#40How are they going to enforce this?
I would imagine, as a CA that issues only DV certs, they'd disallow issuance to various ccTLDs, and perhaps stop newAccount registrations with email addresses at those ccTLDs. That's about as much as they could do - IP-blocking by region is ineffective and crude at best.