RC RANDOM CHAOS

Let's Encrypt updates subscriber agreement to bar use in US-sanctioned territories

· via Hacker News

Original source

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

Hacker News →

Let’s Encrypt has revised its Subscriber Agreement (version 1.7, dated June 4, 2026) to prohibit the use of its certificates in territories under US sanctions. The change, published as a redline diff to the legal agreement that every certificate requester accepts, formalizes compliance obligations that apply to Let’s Encrypt’s parent, the Internet Security Research Group, as a US-based nonprofit subject to OFAC export and sanctions rules.

The move matters because Let’s Encrypt is the dominant certificate authority on the web, issuing free TLS certificates that underpin HTTPS for hundreds of millions of sites. A usage ban tied to sanctioned territories — which under current US policy includes regions such as Cuba, Iran, North Korea, Syria, and Russian-occupied areas of Ukraine — raises the prospect that site operators and users in those areas could lose access to free, automated certificate issuance, pushing them toward self-signed certificates, plaintext HTTP, or less trustworthy CAs.

Critics have long argued that applying sanctions law to basic encryption infrastructure undermines the security of ordinary users rather than sanctioned governments, since TLS protects readers and site visitors as much as operators. The agreement change positions enforcement at the legal layer; how aggressively Let’s Encrypt will operationalize it — for example, via geographic issuance blocks or revocations — is not spelled out in the diff itself.

Read the full article

Continue reading at Hacker News →

This is an AI-generated summary. Read the original for the full story.