Russia has created its own trusted TLS certificate authority (CA) to resolve website access issues that have accumulated after certificate renewals were prevented due to sanctions.

See also: PlayStation suspends all hardware and software shipments to Russia
Sanctions imposed by Western companies and governments prevent Russian websites from renewing existing TLS certificates, resulting in browsers blocking access to websites with expired certificates.
TLS certificates help the web browser confirm that a domain belongs to a verified entity and that the exchange of information between the user and the server is encrypted.
Signing authorities based in countries that have imposed sanctions on Russia can no longer accept payments for their services, leaving many websites without a practical means of renewing expiring certificates.
After a certificate expires, web browsers like Google Chrome, Safari, Microsoft Edge, and Mozilla Firefox will display full-page warnings that the pages are insecure, which can turn many users away from the website.
The Russian state has envisioned a solution to a domestic certificate authority for the independent issuance and renewal of TLS certificates.
“It will replace the foreign security certificate if it is revoked or expires. The Ministry of Digital Development will provide a domestic analogue free of charge. The service is provided to legal entities – website owners upon request within 5 business days,” explains the Russian public services portal, Gosuslugi.
See also: Amazon stops shipments to Russia and discontinues Prime Video
However, for new certificate authorities (CAs) to be trusted by web browsers, they first had to be vetted by various companies, which can take a long time.

Currently, the only web browsers that recognize Russia's new CA as trusted are the Yandex browser and Russia-based Atom products, so Russian users are urged to use these instead of Chrome, Firefox, Edge, etc.
Websites that have already received and are currently using these state-issued certificates include Sberbank, VTB , and the Russian Central Bank.
Russian media also released a list of 198 domains that have reportedly received notice for using the domestic TLS certificate, but for now, its use has not been made mandatory.
Users of other browsers like Chrome or Firefox can manually add the new Russia certificate to continue using Russian websites that have the state-issued certificate.
However, this raises concerns that Russia could misuse the CA certificate to conduct HTTPS traffic interception and man-in-the-middle attacks .
This abuse will eventually lead to the new certificate being added to the certificate revocation list (CRL).
See also: US: Sanctions on Chinese companies that help Russia
This would invalidate these domestic certificates and Chrome, Edge, and Firefox would block access to any websites that use them.
Certificate authorities are supposed to be globally trusted. However, as Russia currently does not enjoy any level of trust, it is unlikely that major browser vendors will add them to their certificate stores.
