Sanctions compliance has reached a layer of the internet most people never think about: the certificates that let browsers trust a website. Recent reporting, including a Risky Bulletin item titled "Sanctions force CAs to revoke TLS certs in Iran, Russia," describes certificate authorities (CAs) pulling TLS certificates from sanctioned entities. This post looks at how TLS certificate revocation in Iran and Russia works, who feels it, and where a VPN fits in.
What the certificate revocations actually do
A TLS certificate is a digital credential, issued by a CA, that proves a website is who it claims to be. Browsers ship with a list of CAs they trust. When a CA revokes a certificate, browsers that check revocation status will warn users or refuse to load the site over HTTPS.
According to search coverage of the story, GlobalSign mass-revoked TLS certificates for Russian customers in June, as it implemented US and EU sanctions. Other reports describe Iranian banks' certificates being revoked as well, and a sanctioned Iranian maritime authority's website becoming unreachable in standard browsers after it lost its certificates. Moscow Exchange has also warned that foreign certificate revocations could disrupt websites, APIs, and trading systems unless trust-store changes are made.
The key point is that revocation does not remove a website or block traffic. It removes the cryptographic proof of identity that modern browsers expect. The site may still be online, but the browser treats it as untrustworthy.
How ordinary users in Iran and Russia are affected
Most people affected are not the sanctioned entities themselves. They are customers of banks, exchanges, and other services that relied on the revoked certificates.
When a certificate is revoked or expires without a valid replacement, users may see full-page browser warnings. Automated systems that connect over TLS, such as APIs and payment integrations, can simply fail. Reports say Russian banks had to switch to a state-run certificate authority in August. That fixes the warnings only for people whose devices trust the new authority, and Russian officials have reportedly urged citizens to install national security certificates.
That creates a difficult tradeoff. A user can keep seeing errors, or install a certificate from a domestic authority. Installing a root certificate that a state controls can widen what that authority is technically able to vouch for, and some commentators have raised concerns about interception. We have not independently verified those claims, and readers should treat them as concerns rather than established facts. Still, the general principle is sound: any root certificate you add to your device becomes something your device will trust.
Where VPNs help and where they don't
This is where the topic often gets confused. A VPN and HTTPS solve different problems.
What a VPN can do:
- Encrypt traffic between your device and the VPN server, hiding your browsing from your local network or internet provider.
- Change the network path and apparent location of your connection, which can help reach services blocked at the network level.
What a VPN cannot do:
- Restore a revoked certificate. If a site's certificate has been revoked, your browser will still object regardless of the network you use.
- Replace the identity check that HTTPS provides. A VPN does not tell your browser that a website is genuine.
- Make a site trustworthy. Once traffic leaves the VPN server, it travels to the destination, and HTTPS is what protects that final leg.
In short, a VPN protects the road, while a certificate vouches for the destination. Bypassing a certificate warning is not a VPN feature, and clicking through such warnings removes protection against impersonation. If a site you rely on shows a certificate error, the safest assumption is that something is wrong until you can confirm otherwise through another channel.
What this means for trust in the certificate system
The web's trust model depends on a relatively small number of CAs that browsers agree to trust. Those CAs are companies operating under national laws, so sanctions obligations can apply to them. The reported revocations show that this technical trust system is also exposed to legal and political pressure.
It also shows a possible response: countries may build parallel systems. Reports of a state-run CA in Russia and of a China-based CA issuing a certificate to a sanctioned Iranian entity point to a more fragmented certificate ecosystem. Whether browsers will trust such alternatives is a separate decision made by browser vendors and operating system makers, and it has consequences for everyone who uses those products.
For security teams, it is a reminder that certificate dependencies are supply chain dependencies. An organisation that relies on a single CA can lose secure access quickly if that CA's obligations change.
What This Means For You
If you live in or do business with Iran or Russia, you may see certificate errors on financial and government sites. Even if you are elsewhere, the story matters if your organisation works with sanctioned regions, since integrations can break when certificates are pulled.
For most readers outside those situations, nothing changes day to day. The lesson is about understanding what each security tool protects.
Actionable takeaways
- Do not click through browser certificate warnings on banking or login pages.
- Think carefully before installing any new root certificate, especially one issued by a government or an unfamiliar authority.
- Remember that a VPN encrypts your connection to the VPN server; it does not fix or replace HTTPS trust.
- If you run services, know which CA issues your certificates and have a plan for switching if one becomes unavailable.
- Keep browsers and operating systems updated, since trust-store changes arrive through updates.
The broader point of TLS certificate revocation in Iran and Russia is that HTTPS trust and VPN encryption are separate layers. Understanding the difference will help you judge which risks a given tool actually addresses.




