Mozilla Bugzilla / public incident report

HARICA Faces Scrutiny Over Certificates Issued to Sanctioned Russian Banks

HARICA Faces Scrutiny Over Certificates Issued to Sanctioned Russian Banks

A security researcher filed a public report on Mozilla's Bugzilla platform documenting valid, active TLS certificates that HARICA — the Greek Academic and Research Institutions certificate authority — had issued to entities under EU sanctions, including Sberbank, VTB, and several others. The researcher reported having flagged the same domains to HARICA directly roughly a month earlier, receiving a response that the certificates were domain-validated, that issuance was automated, and that no policy violation had occurred absent an official directive from a competent authority.

Why "it was just DV" isn't the whole answer

Domain validation confirms control of a domain — it doesn't determine whether issuing to that domain is otherwise appropriate. (Our DV vs OV vs EV guide covers what each validation tier actually checks, and what it doesn't.) Sanctions compliance obligations apply to the entity providing a service, regardless of how automated or minimally-vetted that service's issuance process is. The dispute became less about whether these specific certificates should exist and more about whether a CA can treat "our validation was automated and technically correct" as a complete defense against a compliance obligation that sits outside the validation process entirely.

Why this became a bigger story than one CA's dispute

Root store programs — the lists Chrome, Mozilla, Apple, and Microsoft each maintain to decide which CAs are trusted by default — exist specifically to hold CAs accountable to more than just their own internal validation logic. A CA's willingness (or reluctance) to act on a legitimate compliance concern outside the narrow bounds of domain validation is exactly the kind of judgment call root programs are designed to evaluate.

Where this connects to HARICA's other rough month

This controversy surfaced in the same general window as HARICA's separate, larger compliance incident — two unrelated CP/CPS violations requiring mass certificate revocation, covered as its own story. Together, they made for a genuinely difficult stretch for one CA's standing in the ecosystem.

This is our own summary and analysis of publicly reported news, written independently — not a reproduction of any single source's article. Where we reference a specific announcement, we link to it or name the organization directly.