- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,253
Under the cleaning fell 15-20 thousand domains - and this is only the beginning.

GlobalSign has started withdrawing SSL certificates issued to Russian companies. For some sites and applications, this can result in browser alerts, login errors and urgent replacement of certificates. The procedure started on the morning of June 13 and, according to market participants, will be proceeding in stages.
SSL certificate does not need a site for beauty and not only for the lock icon in the address bar. It confirms that the user connects to this site, not a fake, and encrypts the data exchange between the browser and the server. If the certificate is withdrawn, the browser sees it in the list of invalid and begins to warn of an unsafe connection or completely block the access.
The reason for the withdrawal is related to the new requirements of the CA/Browser Forum - an international association that sets the rules for certification centers and browser developers. This forum includes the largest market players, including Google, Apple, Microsoft and Mozilla. The updated rules have stepped up the verification of organizations and made mandatory reconciliation with the sanctions lists of the United States and Europe.
GlobalSign belongs to the Japanese GMO Internet Group, but the certification authority itself was founded in Belgium and is obliged to comply with European sanctions restrictions. After the introduction of new requirements, the company conducted an audit of the already issued certificates and began to revoke part of the certificates from customers from Russia.
Russian legal entity “Gleb-O Global Sain Rush” warned partners that it cannot influence the decision of the global certification center. In a letter from the general director Dmitry Ryzhikov, it is said that the review began on June 13 at 02:10 British summer time, that is, at 04:10 Moscow time.
The first warnings users received in the morning. T-Bank sent out parts of SMS customers about possible problems with entering some Russian sites and applications. Rosselkhozbank separately warned that the old version of the Android application can work with errors.
For the average user, the consequences look simple: the site opens with a red alert, the browser writes that the connection is not secure, and the application can stop connecting to the server. In corporate systems, the situation is tougher: access can be blocked automatically, without the ability to quickly continue working through a warning.
The scale is still evaluated differently. The Ministry of Finance believes that the share of GlobalSign in Runet does not exceed 5%, so the mass shutdown of sites should not be expected. In the market of commercial certificates, the picture is different: according to Astra Cloud, among the Western commercial certificates, GlobalSign held about 90% in Russia.
One of the interlocutors of the market estimated the list of domains of the second level, which fell under the review, about 15-20 thousand. But a second-level domain often hides tens, hundreds or thousands of subdomains. Large banks, technology platforms, government services and large corporate systems certificates can protect individual personal accounts, APIs, internal panels, mobile services and payment modules. Therefore, the real number of affected certificates can be much higher.
GlobalSign has long been a special case for the Russian market. Many international certification centers have stopped issuing certificates for Russian and Belarusian domains back in March 2022. GlobalSign continued to work with Russian clients and actually remained the last major commercial international center, which fully served this segment.
At the same time, the globalSign world retains a huge weight. According to W3Techs as of June 2026, the company ranks second in terms of the number of valid certificates with a share of 20.4%. Only the free Let's Encrypt, which accounts for 68.2%. Among the commercial certification centers, GlobalSign remains the largest.
Russian companies will now urgently look for a replacement. The most obvious option for sites within the country is the certificates of the National Certification Center of the Ministry of Digital Development. They are issued to legal entities free of charge through the State Services. But this solution has a limitation: foreign browsers do not trust the Russian root certificate by default. For some audience outside the Russian ecosystem, the problem may persist.
Other options are not perfect either. Certificates of centers from China or CIS countries can cost significantly more and do not give complete protection against new sanctions decisions. The free Let’s Encrypt remains user-friendly for many sites, but for companies under sanctions risk and large infrastructure projects, its use through bypass schemes can create separate legal and technical problems.
The most difficult will be for mobile applications where the certificate pinning is used - a rigid binding to a specific certificate or a certification center. If the old certificate is revoked, the application may simply stop trusting the server. In this case, it is not enough to replace the certificate on the site: you need to release an update of the application. And it is not always possible to quickly renew through foreign stores now.
A similar problem arises in applications with built-in browser components WebView. If pages or personal accounts linked to the revoked certificate are opened inside the application, the user may be mistaken even when the main site has already been transferred to a new certificate.
A separate risk is associated with certificates for the signature of the program code. Such certificates are needed so that operating systems trust applications and installers. If Russian developers lose access to international code signature certificates and find a steady replacement, the distribution of programs for Windows, macOS and iOS will become more difficult.
Market experts believe that the current review will not be the last. The new rules require stricter checking organizations on sanctions lists, which means that other companies can hit. Some of the major players were preparing for such a scenario in advance, but for medium-sized businesses, which until the last held for foreign certificates for the sake of compatibility with foreign browsers and customers, the transition can be painful.
The market is already discussing emergency temporary measures, including ways to postpone the verification of the status of withdrawn certificates. But such solutions do not close the problem and can reduce the level of security. They give only a short pause so that the owners of sites, banking services and applications have time to release new certificates and update the infrastructure.
The main result for the Runet is unpleasant: there is no more universal solution. The certificates of the Ministry of Digital Resources are suitable for the Russian infrastructure, but do not work as a full-fledged international replacement. Foreign centers can become more expensive and riskier. And large services will have to separate the audience, applications and chain of trust in advance so that the next review of certificates does not turn into an urgent night fire.

GlobalSign has started withdrawing SSL certificates issued to Russian companies. For some sites and applications, this can result in browser alerts, login errors and urgent replacement of certificates. The procedure started on the morning of June 13 and, according to market participants, will be proceeding in stages.
SSL certificate does not need a site for beauty and not only for the lock icon in the address bar. It confirms that the user connects to this site, not a fake, and encrypts the data exchange between the browser and the server. If the certificate is withdrawn, the browser sees it in the list of invalid and begins to warn of an unsafe connection or completely block the access.
The reason for the withdrawal is related to the new requirements of the CA/Browser Forum - an international association that sets the rules for certification centers and browser developers. This forum includes the largest market players, including Google, Apple, Microsoft and Mozilla. The updated rules have stepped up the verification of organizations and made mandatory reconciliation with the sanctions lists of the United States and Europe.
GlobalSign belongs to the Japanese GMO Internet Group, but the certification authority itself was founded in Belgium and is obliged to comply with European sanctions restrictions. After the introduction of new requirements, the company conducted an audit of the already issued certificates and began to revoke part of the certificates from customers from Russia.
Russian legal entity “Gleb-O Global Sain Rush” warned partners that it cannot influence the decision of the global certification center. In a letter from the general director Dmitry Ryzhikov, it is said that the review began on June 13 at 02:10 British summer time, that is, at 04:10 Moscow time.
The first warnings users received in the morning. T-Bank sent out parts of SMS customers about possible problems with entering some Russian sites and applications. Rosselkhozbank separately warned that the old version of the Android application can work with errors.
For the average user, the consequences look simple: the site opens with a red alert, the browser writes that the connection is not secure, and the application can stop connecting to the server. In corporate systems, the situation is tougher: access can be blocked automatically, without the ability to quickly continue working through a warning.
The scale is still evaluated differently. The Ministry of Finance believes that the share of GlobalSign in Runet does not exceed 5%, so the mass shutdown of sites should not be expected. In the market of commercial certificates, the picture is different: according to Astra Cloud, among the Western commercial certificates, GlobalSign held about 90% in Russia.
One of the interlocutors of the market estimated the list of domains of the second level, which fell under the review, about 15-20 thousand. But a second-level domain often hides tens, hundreds or thousands of subdomains. Large banks, technology platforms, government services and large corporate systems certificates can protect individual personal accounts, APIs, internal panels, mobile services and payment modules. Therefore, the real number of affected certificates can be much higher.
GlobalSign has long been a special case for the Russian market. Many international certification centers have stopped issuing certificates for Russian and Belarusian domains back in March 2022. GlobalSign continued to work with Russian clients and actually remained the last major commercial international center, which fully served this segment.
At the same time, the globalSign world retains a huge weight. According to W3Techs as of June 2026, the company ranks second in terms of the number of valid certificates with a share of 20.4%. Only the free Let's Encrypt, which accounts for 68.2%. Among the commercial certification centers, GlobalSign remains the largest.
Russian companies will now urgently look for a replacement. The most obvious option for sites within the country is the certificates of the National Certification Center of the Ministry of Digital Development. They are issued to legal entities free of charge through the State Services. But this solution has a limitation: foreign browsers do not trust the Russian root certificate by default. For some audience outside the Russian ecosystem, the problem may persist.
Other options are not perfect either. Certificates of centers from China or CIS countries can cost significantly more and do not give complete protection against new sanctions decisions. The free Let’s Encrypt remains user-friendly for many sites, but for companies under sanctions risk and large infrastructure projects, its use through bypass schemes can create separate legal and technical problems.
The most difficult will be for mobile applications where the certificate pinning is used - a rigid binding to a specific certificate or a certification center. If the old certificate is revoked, the application may simply stop trusting the server. In this case, it is not enough to replace the certificate on the site: you need to release an update of the application. And it is not always possible to quickly renew through foreign stores now.
A similar problem arises in applications with built-in browser components WebView. If pages or personal accounts linked to the revoked certificate are opened inside the application, the user may be mistaken even when the main site has already been transferred to a new certificate.
A separate risk is associated with certificates for the signature of the program code. Such certificates are needed so that operating systems trust applications and installers. If Russian developers lose access to international code signature certificates and find a steady replacement, the distribution of programs for Windows, macOS and iOS will become more difficult.
Market experts believe that the current review will not be the last. The new rules require stricter checking organizations on sanctions lists, which means that other companies can hit. Some of the major players were preparing for such a scenario in advance, but for medium-sized businesses, which until the last held for foreign certificates for the sake of compatibility with foreign browsers and customers, the transition can be painful.
The market is already discussing emergency temporary measures, including ways to postpone the verification of the status of withdrawn certificates. But such solutions do not close the problem and can reduce the level of security. They give only a short pause so that the owners of sites, banking services and applications have time to release new certificates and update the infrastructure.
The main result for the Runet is unpleasant: there is no more universal solution. The certificates of the Ministry of Digital Resources are suitable for the Russian infrastructure, but do not work as a full-fledged international replacement. Foreign centers can become more expensive and riskier. And large services will have to separate the audience, applications and chain of trust in advance so that the next review of certificates does not turn into an urgent night fire.