Forcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs? Great, that'll show them.
This was the most anti-colonialist move America had ever made, but you can’t keep tiptoeing around your enemy forever.
Just like in russia and exactly because of sanctions. Excellent job, dear west.
CAs is the problem. Not who runs them...
> Forcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs?
How's the support for X.509 "Name Constraints" these days:
* https://datatracker.ietf.org/doc/html/rfc5280#section-4.2.1....
Would restricting it to only dot-ir domains be a mitigation?
* https://en.wikipedia.org/wiki/.ir