Skip to main content

Issuance Restrictions, Regions and Specific CA Sanction Lists for SSL Certificate Applications

SSL certificate issuance restrictions are primarily determined by international sanction policies, national regulations, and the compliance requirements of Certificate Authorities (CAs). Below is a detailed breakdown of restricted regions and their underlying reasons: international sanction list restrictions, national regulatory restrictions, and corresponding solutions. The following are the frequently inquired restricted regions and specific CA sanction lists at present. For special company names or domain names, please contact your account manager for verification.

Issuance rules for Russia:

  1. Domains ending with .ru: Only GlobalSign supports issuing DV certificates for .ru domains; no other CAs provide support.
  2. OV certificates for Russian entities: (The domain contains the string .ru, but the enterprise name does not indicate Russia)
    • A. GlobalSign: Supports DV and OV certificates
    • B. CFCA: Not supported
    • C. DigiCert: Judging criterion is whether the enterprise's registered location is Russia
    • D. Certum: Not supported
    • E. Sectigo: Judging criterion is whether the enterprise's registered location is Russia; the enterprise is subject to separate review

Official description of Sectigo's restricted issuance list

Link to Sectigo restricted issuance list: The restricted regions mainly include countries such as Cuba, Russia, Iran, and North Korea. In case of changes, please refer to the official website description or contact your account manager for inquiries.

How to verify if you are restricted?

  • CA public policies: Check the sanctioned country list published on the CA's official website (e.g., DigiCert sanction policy).
  • WHOIS lookup: Check the country code in the domain registration information (for example, Iranian domains .ir may be blocked by CAs).
  • Legal counsel: Consult on the compliance requirements of the target country/industry.