Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

351–360 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#352

Earlier quoted context omitted.

This is not that though. This is literally about a company that has a branch in the USA and another branch in another country, where it's bound by that country's laws. If the foreign entity which just so happens to be commercially linked to the one in the USA has any dealings with countries sanctioned by the US, the US branch is punished. There was a case a few years ago where a public University in Brazil bought lab…

Why didn't the university just ignore the terms of service?

I don't know, and to be fair they might have done just that - and it wouldn't surprise me if that happened with the blessings of the Federal Government.

As I mentioned, I didn't follow up on the story and in fact when I searched for it a few years ago, I couldn't even find the original articles any more.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#353

Earlier quoted context omitted.

Yeah, that's why most countries in EU, as well as US, are in a huge dissarray, politicians have all time low approvals, people vote for something and get the opposite, and the economy and social climate turned to shit... I guess one doing well enough can be oblivious to all this...

Try to read less tabloids.

LOL, talk about out of touch. You need the press to tell you that?

You can also just read "prestige press" - it will tell you the same. Or socio-economic indicators.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#354

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

This is why, as someone who works in security and encryption and has implemented web server TLS stacks and such, I still oppose the "always-https" idea.

TLS is awesome, one of the most valuable developments in Internet history. But, it is important to undewrstand that it is a double edged sword. Requiring a CA, which in practical terms means requiring a publicly known CA, is a choke point of freedom.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#355

Couldn't LE have a branch in Europe or anywhere outside the USA and its minions? Because they're betraying their own goals, as stated in their About page: “It is a service run for the public’s benefit. [...] Anyone who owns a domain name can use Let’s Encrypt to obtain a trusted certificate at zero cost. [...] Let’s Encrypt is a joint effort to benefit the community, beyond the control of any one organization.” Now t…

There are other non-US equivalents to Lets Encrypt.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#356
post #50

Earlier quoted context omitted.

Jumping in here since we’ve been seeing more mentions of ZeroSSL lately, likely related to the recent CA/B Forum discussions around 1‑year certificates and ACME automation. - We’re based in Austria (ZeroSSL GmbH). The company was acquired by HID in 2024, which is part of Assa Abloy (Sweden). - We’re not positioning ourselves as a purely EU-based CA substitute, and we generally don’t market it that way. - For DV certs…

> - We’re not positioning ourselves as a purely EU-based CA substitute, and we generally don’t market it that way. OK, but in the context of this topic thr interesting part isn't your marketing but your jurisdiction. Could you clarify which jurisdiction you operate under and a link on the ZeroSSL website that collaborates that? Thank you <3

[dead]

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#357
post #50

Earlier quoted context omitted.

Jumping in here since we’ve been seeing more mentions of ZeroSSL lately, likely related to the recent CA/B Forum discussions around 1‑year certificates and ACME automation. - We’re based in Austria (ZeroSSL GmbH). The company was acquired by HID in 2024, which is part of Assa Abloy (Sweden). - We’re not positioning ourselves as a purely EU-based CA substitute, and we generally don’t market it that way. - For DV certs…

Any plans on becoming an independent CA? Would certificates issued in your name also risk being affected by US sanctions trough sentigo?

If so, we still need to follow guidelines from our parent Assa Abloy, a public company from Sweden, which has itself a list of restricted countries they are doing business in.

https://help.zerossl.com/hc/en-us/articles/360060119833-Rest...

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#358
post #239

Earlier quoted context omitted.

Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this. Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. This subscriber agreement update was intended to better reflect our legal…

> Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. The agreement very plainly says otherwise: > You are not a person or entity that is: (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions The general population of those countries are absolutely…

They have "clarified" elsewhere on here that the normal citizenry get a legal exemption [waves hands mystically] somehow, and that they're only blocking people when they legally have to.

Obviously (to the rest of us) if the agreement says otherwise, then they're saying that it's LE that is forbidding the citizens of these countries, and it's not (entirely) the government's fault, which completely contradicts what they're trying to say.

We should probably be clear that this document is most likely a backside-covering exercise; it exists so that people can't sue LE for denial of service without a just cause, and so that the US can't prosecute them for intentionally shipping cryptographic services, or some such rubbish.

If you live entirely outside the US legal system, or its multifaceted tendrils, and if you don't make too much noise, you may be fine. Obviously that's a far cry from a "right to free speech" level of protection, but then LE have no obligation to provide that to people outside the US, and arguably non-rich citizens within the US lost that a long time ago.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#359
post #314
post #108

Earlier quoted context omitted.

While it seems like certificate authority has the primary control here, the real control lies in browsers and operative systems in which certificate authorities are trusted. Users also have, at least for the moment, control to add or remove certificate authorities, even if that control is slightly less clear for devices like smart phones. Digital certificates that signs software packages are used to enforce exclusion…

> the real control lies in browsers and operative systems in which certificate authorities are trusted Wasn't Let's encrypt a Mozilla child ? The real control lies at who defines what is trusted.

Local control, maybe. But not the power.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#360
post #239

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this. Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. This subscriber agreement update was intended to better reflect our legal…

You issued a certificate for North Korea's email infrastructure as recently as six days ago:

https://crt.sh/?id=26878583197 (06/04/2026 smtp.star-co.net.kp) https://crt.sh/?id=20256841119 (08/11/2025 *.star.net.kp)

Star Joint Venture is the manager of the .kp TLD and one of DPRK's two email providers (the other is silibank.net.kp) [1], used as the official email for various government bodies ex. ipa817@star-co.net.kp (IP Office), kscost@star-co.net.kp (Sci/Tech Commission), ksf@star-co.net.kp (Ministry of Culture and Sports), mhs-ip@star-co.net.kp (Atomic Energy). It is also widely used by those universities and companies that engage with the outside world.

How did you determine that issuing a certificate to this domain or any .kp domain was compliant with the general ban on exporting goods and services to DPRK?

Post reply on HN