The GlobalSign certification authority, registered in Belgium and owned by the Japanese GMO Group, has begun revoking SSL certificates that were previously issued to Russian companies subject to the current EU sanctions. In a letter to its partners, sent by the director of the Russian branch, it is stated that the revocation of certificates started on June 13 at 04:10 (MSK) and will be conducted in phases. The reason given is the assertion by the CA/Browser Forum consortium, which serves as a platform for collaborative decision-making considering the interests of browser manufacturers and certification authorities, regarding new requirements for organization verification when issuing certificates.
This concerns extended TLS certificates of the EV (Extended Validation) level, which confirm the declared identification parameters and require not only domain ownership verification but also a certification authority to verify the existence and legal status of the company receiving the certificate. In browsers, when working with sites that have EV certificates and certificates obtained solely through verification, domain, the same icon is displayed.
It is noted that the new version of the EV certificate issuance regulation, which came into effect on May 4, contains a direct prohibition for certification authorities to issue certificates to companies on sanction lists, and the verification against blocking lists has become mandatory rather than recommended.
This information is not accurate, as the mentioned requirements were added by the CA/Browser Forum in an earlier version of the regulation (at least they can be traced back to version 1.7.0 from 2019). No changes have been made to sections 3.2.2.12.2 and 4.1.1.1, which mandate verification against sanction lists, in the new version of the document (version 2.0.2 from May 4, 2026, version 2.0.1 from May 6, 2024).
In section 4.1.1.1, among the conditions for passing the verification to obtain an EV certificate, it is mentioned that the verifying company must not be listed among the restricted organizations or those subject to embargoes, according to the legislation of the country where the certification authority is registered. Section 3.2.2.12.2 states that the certification authority is required to verify the presence of the organization requesting the certificate in lists of prohibited individuals and organizations operating in the country where the certification authority is located, as well as in the countries where the certification authority carries out its activities.
The certification authority must not issue an EV certificate if the requesting organization is present in such lists or if it operates or is registered in a country where business is prohibited by the legislation of the country where the certification authority is registered.
GlobalSign is registered in Belgium and is required to comply with the sanctions in effect in the European Union. In addition to individual sanctions, the European Union also enforces a ban on the provision of corporate software and IT services to Russian legal entities, introduced in the 14th sanctions package. It is assumed that GlobalSign has not complied with these requirements until today, utilizing an exception in legislation that allowed providing services to sanctioned companies for the security of the entire internet. Now the issuance of SSL-certificates is qualified by GlobalSign's lawyers or regulatory authorities as the provision of commercial IT services, which falls under the sanctions prohibitions.
Source: opennet.ru
