Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

121–130 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#121
Now this is very bad, as bad as it can get. As soon as all local services will stop working in sanctioned countries, those countries' governments will force all users to either install a root certificate or lose access to all local services and websites. And then it will be possible to use that root certificate for MITM attacks. In the worst case scenario, after the majority of users will install the root certificate, state DPIs will MITM all traffic and will block all un-MITMable traffic.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#122
post #111

Earlier quoted context omitted.

Which free CA should I use instead of lets encrypt that has same browser support?

Actalis, based in Italy offers a free tier, with ACME https://www.actalis.com/subscription ZeroSSL from Austria also has a limited free tier. https://zerossl.com/pricing/ I mean really, if you use lets encrypt for anything that runs in a production environment, the responsible thing to do is build a fallback to switch to another provider in case LE has a bad day (or hits a brick wall and needs to say, enforce export…

Worth noting that Actalis requires you to register an account with them in order to acquire the necessary authorization token for their ACME API. This poses a privacy/anonymity issue for some users. Last I checked, Actalis' free tier didn't support SAN either.

Add.: I created an account just now to see "what's what" and also found the notice, "Activate your free 90 days certificates. At the end of the free year, the services associated with the certificates will expire." which sort of sounds like it's just a 1-year free trial.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#123
post #91

Maybe consolidating ~60% of the web's certificates on to a single provider was a mistake.

Well good thing everyone using the provider is using an open protocol and it's stupid easy to switch

can you please suggest any alternatives to switch to? i hardly can find any alternative which provides free service and is a non-profit org at the same time.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#124

Earlier quoted context omitted.

That's just another reminder that no one from outside of US should deal with US companies.

Of course not! just find viable alternatives to Microsoft, Apple, Mozilla, YCombinator, Google, Intel, AMD, ... In all seriousness, as an American I'd love to see a healthier, more well-distributed tech industry, but I don't see many companies stepping up to provide competing services. It's my understanding that china has alternatives to many of these products/services, but I really don't see how anyone in Europe cou…

> but I don't see many companies stepping up to provide competing services

Maybe because the US dropped most of its anti trust regulations, leading to ridiculously monopolistic practices such as "acquire everything that may be threatening".

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#125
post #118

Iran is blocking internet for months, US ...bans creation of secure connections - that'll show 'em! Russian quasi-government structures are spending quadrillion of rubles on a TSPU (censorship system) to spy on Russian residents, US ...helps them by making snooping on what is currently encrypted traffic possible by banning accessible encryption!

Let's Encrypt certificates continue to be available in both Iran and Russia, just not for the Iranian and Russian governments. The terms of service update to clarify what we have always done, comply with relevant law, has not changed the situation for either country.

> Let's Encrypt certificates continue to be available in both Iran and Russia, just not for the Iranian and Russian governments.

According to https://news.ycombinator.com/item?id=48457280 it affects all people ordinarily resident in those territories, not just their governments:

> You are not a person or entity that is:

> (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions;

> [other 'or' conditions]

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#126
post #64
post #28

Earlier quoted context omitted.

It's about time SOME entities start moving from US entirely.

Other countries sanction each other too.

This is not about countries sanctioning each other. This is the US sanctioning a local company because a foreign company doesn’t follow certain US laws in foreign soil, where such laws don’t apply.

It’s a bit like the US arresting your mom at home in Texas because you ate a baggie of magic truffles in Amsterdam.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#127
post #50

Earlier quoted context omitted.

Jumping in here since we’ve been seeing more mentions of ZeroSSL lately, likely related to the recent CA/B Forum discussions around 1‑year certificates and ACME automation. - We’re based in Austria (ZeroSSL GmbH). The company was acquired by HID in 2024, which is part of Assa Abloy (Sweden). - We’re not positioning ourselves as a purely EU-based CA substitute, and we generally don’t market it that way. - For DV certs…

Sectigo used to be Comodo's CA business. If memory serves, that business was purchased by a US PE firm and renamed "Sectigo". Sectigo Inc.'s corporate headquarters is now in Scottsdale, AZ. There's no reason to believe they're any less subject to US jurisdiction than LetsEncrypt.

There were reason to believe they were less subject to US juridiction: their Subscriber Agreement is for "Sectigo Limited, a limited company formed under the laws of England and Wales". See https://www.sectigo.com/uploads/backgrounds/Certificate-Subs...

Sadly, their United Terms and Conditions in section 8.2 are even more restrictive than LE's. They reject any entity "located in, incorporated under the laws of, or owned (meaning 50% or greater ownership interest) or otherwise, directly or indirectly, controlled by, or acting on behalf of, a person located in, residing in, or organized under the laws of any country sanctioned under the laws of the U.S. or E.U." See https://www.sectigo.com/uploads/backgrounds/United-Terms-and...

From a layman point of view, it could even mean that the ICC and the UN are prohibited from using Sectigo. The Customer must have no "affiliates, officers, directors, or employees" that are on sanction lists, and the US have sanctioned some high-profile members of the UN and the ICC that spoke about the genocide in Gaza.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#128
This should be one of those things that should be an quick EU win. Running Let's Encrypt is $3-4mill a year, the EU probably uses that on pencils.

The EU could easily bootstrap a Let's Encrypt competitor if it truly cared about removing dependencies on US based entities.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#129
post #6

Is this a canary? What's gonna happen if I were to begin or continue using one letsencrypt certificate from ... Greenland? Cuba? The EU? Has letsencrypt been served with a subpoena?

> Has letsencrypt been served with a subpoena?

While it's certainly possible that ISRG has been served a subpoena because it appears the US DOJ is now a mix of hacks and incompetent buffoons, it wouldn't matter because the whole point is that they don't know anything - what you told them is literally logged publicly for everybody to see without even knowing how to spell "subpoena" let alone issue one.

Some people have this insane idea that somehow the CA has some secret which either they minted and sent to the CA, or the CA minted and gave them a copy and so the US government could get this secret with a subpoena - but the whole fucking point of a Public Key Infrastructure is that we're using Public Key Encryption, if we were OK with everybody having secrets all over the place this entire thing wouldn't be needed.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#130
post #63
post #6

Is this a canary? What's gonna happen if I were to begin or continue using one letsencrypt certificate from ... Greenland? Cuba? The EU? Has letsencrypt been served with a subpoena?

Neither Greenland nor the EU has been sanctioned by the US.

Have you heard about the judge from international court or whatever it is called?

https://www.france24.com/en/americas/20250820-us-hits-icc-wi...

Post reply on HN