- HARICA, a Greek CA, is issuing TLS certificates to EU-sanctioned Russian entities such as Sberbank, VTB, and KAMAZ, despite reported violations.
- HARICA refused to revoke these certificates, arguing that DV certificates require no identity verification and thus no sanctions screening.
- Researchers identified over 170 active HARICA certificates for sanctioned entities, including state banks, defense contractors, and cyber-related organizations.
- HARICA's stance contrasts with other CAs like Let's Encrypt and GlobalSign, which revoked similar certificates upon notification.