SSL certificate issuance restriction policies (regions, etc.)
SSL certificate issuance restrictions are primarily determined jointly by international sanctions policies, national regulations, and the compliance requirements of Certificate Authorities (CAs). The following is an analysis of specific restricted regions and their reasons: restrictions from international sanctions lists, restrictions from national regulations, and corresponding solutions.
1. Restrictions from international sanctions lists
Most major international CAs (such as DigiCert, Sectigo, Let's Encrypt) are required to comply with the sanctions lists of the United States, European Union, and United Nations. Certificates generally cannot be issued for the following regions:
| Region/Country | Reason for restriction |
|---|---|
| Iran | Subject to U.S. sanctions (OFAC list) |
| North Korea | Sanctioned by the United Nations and multiple countries; financial and technical services are prohibited |
| Syria | Subject to U.S. sanctions (on the list of state sponsors of terrorism) |
| Crimea region | The international community does not recognize its legitimacy following its annexation by Russia |
| Cuba | Subject to long-term U.S. trade embargo (some CAs may provide limited relaxed exceptions) |
- Unable to request a certificate: Domains or entities located in sanctioned regions cannot obtain certificates from international CAs.
- Access restrictions: When users access HTTPS websites in these regions, they may encounter browser warnings due to missing certificates.
2. Restrictions from national regulations
Certain countries legally mandate the use of local CAs or specific encryption standards, which indirectly restricts the use of international certificates:
| Country | Regulatory requirements |
|---|---|
| China | Domestic websites must use domestic certificates (such as CFCA, Shanghai CA) and complete ICP filing |
| Russia | Critical industries (government, finance) must use certificates compliant with the GOST encryption standard (such as CryptoPro) |
| India | Some government projects mandate the use of local CAs (such as eMudhra) |
| South Korea | The financial sector must use domestically certified certificates (such as Crosscert) |
- Compliance risk: Using international certificates may violate local laws, resulting in service blocks or fines.
- Technical restrictions: Some local certificates may not support international standards (such as GOST), requiring additional configuration.
3. Special industry restrictions
Domains in certain sensitive industries (such as military, gambling, adult content) may be restricted from certificate issuance due to CA policies:
| Industry | Reason for restriction |
|---|---|
| Gambling/Lottery | Violates CA/Browser Forum baseline requirements (some CAs require additional review) |
| Adult content | Some CAs refuse issuance or require strict real-name verification |
| Dark web/Illegal activities | All legitimate CAs refuse issuance (domains typically use .onion or other illegal suffixes) |
4. Solutions to circumvent restrictions
| Scenario | Solution |
|---|---|
| Sanctioned regions | Use a local CA or self-signed certificate (requires manual trust by users, suitable for internal systems) |
| National regulatory compliance required | Select a local CA that complies with local regulations (e.g., CFCA for China, CryptoPro for Russia) |
| Special industries | Look for a CA that accepts the relevant industry (e.g., Sectigo issues certificates to the gambling industry under specific conditions) |
5. How to verify if you are subject to restrictions?
- CA public policies: Review the sanctioned country list published on the CA's official website (e.g., DigiCert sanctions policy).
- WHOIS lookup: Check the country code in the domain registration information (for example, Iranian domain names under
.irmay be blocked by CAs). - Legal counsel: Consult on the compliance requirements of the target country/industry.
6. Frequently Asked Questions
Below are details about commonly inquired restricted regions and specific CA sanction lists. For inquiries about special company names or domain names, please contact your account manager.
-
Issuance rules for Russia:
-
Domain names ending with
.ru: Only GlobalSign supports issuing DV certificates for.rudomain names; no other CA provides support. -
OV certificates for Russian entities (domain names that do not contain
.rubut whose company names indicate Russia):- A. GlobalSign supports DV certificates but not OV certificates
- B. CFCA does not provide support
- C. DigiCert uses the country of business registration as its judgment criterion
- D. Certum does not provide support
- E. Sectigo uses the country of business registration as its judgment criterion, and applications from such entities require individual review
-
-
Official explanation of Sectigo's restricted issuance list: Restrictions mainly apply to countries including Cuba, Russia, Iran, and North Korea. If there are changes, the official website explanation shall prevail, or you may contact your account manager for inquiries.