Skip to main content

SSL certificate issuance restriction policies (regions, etc.)

SSL certificate issuance restrictions are primarily determined jointly by international sanctions policies, national regulations, and the compliance requirements of Certificate Authorities (CAs). The following is an analysis of specific restricted regions and their reasons: restrictions from international sanctions lists, restrictions from national regulations, and corresponding solutions.

1. Restrictions from international sanctions lists

Most major international CAs (such as DigiCert, Sectigo, Let's Encrypt) are required to comply with the sanctions lists of the United States, European Union, and United Nations. Certificates generally cannot be issued for the following regions:

Region/CountryReason for restriction
IranSubject to U.S. sanctions (OFAC list)
North KoreaSanctioned by the United Nations and multiple countries; financial and technical services are prohibited
SyriaSubject to U.S. sanctions (on the list of state sponsors of terrorism)
Crimea regionThe international community does not recognize its legitimacy following its annexation by Russia
CubaSubject to long-term U.S. trade embargo (some CAs may provide limited relaxed exceptions)
Impact
  • Unable to request a certificate: Domains or entities located in sanctioned regions cannot obtain certificates from international CAs.
  • Access restrictions: When users access HTTPS websites in these regions, they may encounter browser warnings due to missing certificates.

2. Restrictions from national regulations

Certain countries legally mandate the use of local CAs or specific encryption standards, which indirectly restricts the use of international certificates:

CountryRegulatory requirements
ChinaDomestic websites must use domestic certificates (such as CFCA, Shanghai CA) and complete ICP filing
RussiaCritical industries (government, finance) must use certificates compliant with the GOST encryption standard (such as CryptoPro)
IndiaSome government projects mandate the use of local CAs (such as eMudhra)
South KoreaThe financial sector must use domestically certified certificates (such as Crosscert)
Impact
  • Compliance risk: Using international certificates may violate local laws, resulting in service blocks or fines.
  • Technical restrictions: Some local certificates may not support international standards (such as GOST), requiring additional configuration.

3. Special industry restrictions

Domains in certain sensitive industries (such as military, gambling, adult content) may be restricted from certificate issuance due to CA policies:

IndustryReason for restriction
Gambling/LotteryViolates CA/Browser Forum baseline requirements (some CAs require additional review)
Adult contentSome CAs refuse issuance or require strict real-name verification
Dark web/Illegal activitiesAll legitimate CAs refuse issuance (domains typically use .onion or other illegal suffixes)

4. Solutions to circumvent restrictions

ScenarioSolution
Sanctioned regionsUse a local CA or self-signed certificate (requires manual trust by users, suitable for internal systems)
National regulatory compliance requiredSelect a local CA that complies with local regulations (e.g., CFCA for China, CryptoPro for Russia)
Special industriesLook for a CA that accepts the relevant industry (e.g., Sectigo issues certificates to the gambling industry under specific conditions)

5. How to verify if you are subject to restrictions?

  • CA public policies: Review the sanctioned country list published on the CA's official website (e.g., DigiCert sanctions policy).
  • WHOIS lookup: Check the country code in the domain registration information (for example, Iranian domain names under .ir may be blocked by CAs).
  • Legal counsel: Consult on the compliance requirements of the target country/industry.

6. Frequently Asked Questions

Below are details about commonly inquired restricted regions and specific CA sanction lists. For inquiries about special company names or domain names, please contact your account manager.

  1. Issuance rules for Russia:

    1. Domain names ending with .ru: Only GlobalSign supports issuing DV certificates for .ru domain names; no other CA provides support.

    2. OV certificates for Russian entities (domain names that do not contain .ru but whose company names indicate Russia):

      • A. GlobalSign supports DV certificates but not OV certificates
      • B. CFCA does not provide support
      • C. DigiCert uses the country of business registration as its judgment criterion
      • D. Certum does not provide support
      • E. Sectigo uses the country of business registration as its judgment criterion, and applications from such entities require individual review
  2. Official explanation of Sectigo's restricted issuance list: Restrictions mainly apply to countries including Cuba, Russia, Iran, and North Korea. If there are changes, the official website explanation shall prevail, or you may contact your account manager for inquiries.