World

How an Automated Certificate Restored Iran’s Sanctioned Maritime Portal

An automated TLS certificate reopened Iran’s Strait of Hormuz maritime portal before TrustAsia revoked it

WASHINGTON — The Strait of Hormuz, bounded by Iran to the north and Oman and the United Arab Emirates to the south, carries approximately 20 percent to 30 percent of global petroleum liquids and liquefied natural gas (LNG). The narrow waterway connects the oilfields of the Persian Gulf to the Gulf of Oman and the Arabian Sea.

U.S. officials maintain that the Persian Gulf Straits Authority (PGSA) acts as an operational front for the Islamic Revolutionary Guard Corps Navy (IRGCN), using web-based tracking and fee-collection portals to extract toll revenues from commercial vessels navigating international shipping lanes.

When the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) added the PGSA to its Specially Designated Nationals (SDN) list on May 27, major Western web certificate authorities revoked the digital credentials supporting the authority’s encrypted web portal. The Tehran-backed portal became inaccessible through standard web browsers, temporarily disrupting the online system used to vet commercial shipping vessels and collect transshipment tolls in the Strait of Hormuz.

Digital encryption depends on Transport Layer Security (TLS) and Secure Sockets Layer (SSL) certificates issued by trusted Certificate Authorities (CAs). The certificates authenticate website identities and establish encrypted HTTPS connections, preventing third parties from eavesdropping on or altering data in transit.

“Iran’s IRGC extorts vessels transiting the Strait of Hormuz through the so-called Persian Gulf Strait Authority,” the Treasury Department stated upon designating the entity in May, warning that the organization “spearheads an Iranian-controlled scheme that flagrantly violates international law and U.S. sanctions.”

Modern browsers including Google Chrome, Microsoft Edge, Apple Safari, and Mozilla Firefox display severe security warnings when a domain loses its SSL/TLS certificate. They block normal traffic unless users manually override the protection protocols or downgrade to unencrypted HTTP connections.

According to global internet monitor NetBlocks, the expiration and revocation of PGSA’s credentials after the May 27 U.S. sanctions forced commercial shipping companies attempting to access pgsa.ir onto unsecure, unencrypted connections.

“The net result was that the website was more difficult to access, because most web browsers strongly encourage the use of secure HTTPS,” NetBlocks Chief Executive Officer Alp Toker said. He noted that form submissions on the unencrypted domain could be easily intercepted while in transit.

“This is a class of vulnerability open to government exploitation, rather than a corporate breach or personal data leak,” Toker explained, adding that traffic routed through unencrypted channels allowed external monitoring of foreign shipping entities communicating with the Iranian agency.

The disruption prompted a public admission from Tehran. On Aug. 10, the PGSA acknowledged via social media platform X that its website had been disrupted, citing “the enemy’s political influence on the internet service provision systems.”

Six days later, on Aug. 17, the authority announced that secure online access had been fully restored. It directed maritime operators back to its encrypted domain while advising that an unencrypted HTTP backup would remain available via the Firefox browser if further disruptions occurred.

The restoration came through an automated certificate issued by Shanghai-based TrustAsia Technologies. The company generated a new Domain Validated (DV) TLS certificate for pgsa.ir, temporarily restoring secure online access for the PGSA and exposing compliance gaps in global Public Key Infrastructure (PKI) while raising questions about secondary sanctions risks for foreign technology vendors.

Unlike Organization Validated (OV) or Extended Validation (EV) credentials, which require human verification of an entity’s legal identity, physical address, and corporate standing, Domain Validated certificates rely on fully automated server-to-server checks. Those protocols verify only whether the applicant controls the underlying domain, bypassing manual vetting, background checks, or automated screening against international sanctions lists.

Treasury officials warned international maritime operators that “anyone cooperating with the so-called strait authority may be providing support to and receiving services from the IRGC, which ultimately benefits from this attempted extortion, and may therefore be exposed to sanctions risk.”

Under U.S. regulatory frameworks, providing technical services to a sanctioned entity exposes foreign companies to severe enforcement action, regardless of whether the service was rendered through an automated system.

Jeremy Paner, a partner at law firm Hughes Hubbard & Reed and a former sanctions officer at OFAC, emphasized that U.S. enforcement authority under Executive Order 13224—the primary counterterrorism sanctions authority amended to target the IRGC and its affiliates—does not require proof of deliberate intent or knowledge.

“The U.S. has incredibly broad authority to impose sanctions on non-Iranian companies that provide any sorts of services to sanctioned Iranian companies,” Paner said. “Many times, that authority will be abbreviated or explained as being providers of material support to sanctioned Iranian companies. But in fact, any level of services whatsoever could be the basis for the United States imposing sanctions against the company for providing services to Iran.”

TrustAsia Technologies describes itself as a professionally certified certification authority centered on trusted cryptographic communications. In response to inquiries regarding the issuance, the company stated on Aug. 20 that the certificate was generated automatically without human identity verification.

“DV certificates are issued through automated validation of control over the requested domain names,” a TrustAsia spokesperson said. “This process does not verify or assert the legal identity, affiliation, or sanctions status of the entity operating or benefiting from the domain. As a result, the relationship described in your inquiry was not identified during the automated issuance process.”

Paner said the automated nature of certificate issuing platforms offers no legal defense under U.S. secondary sanctions laws. “Restoration of the certificate is unequivocally sanctionable,” he said. “That authority does not in any way require that the service be ‘knowingly’ provided to the PGSA. In other words, the automated nature of the service is irrelevant and does not make the service any less sanctionable.”

After reviewing the matter, TrustAsia said it took precautionary compliance and risk-control steps by placing pgsa.ir on its restricted issuance list to block future requests or renewals and moving to revoke the active credential.

“These actions are precautionary compliance and risk-control measures,” the firm noted, adding they “should not be interpreted as a finding that the certificate was technically misissued.”

NetBlocks confirmed that TrustAsia formally revoked the certificate on Aug. 21 at 12:15:25 UTC. By publishing the revocation signal to public Certificate Transparency (CT) logs and Online Certificate Status Protocol (OCSP) responders, browsers were instructed to withdraw trust from the domain, forcing the PGSA portal offline for standard HTTPS traffic once again.

Major Western certificate authorities align their issuance rules with U.S. sanctions list updates, while Chinese tech firms operate in a complex regulatory environment. TrustAsia’s root certificates are embedded in global web browser trust stores, including those maintained by U.S. tech giants Google, Microsoft, and Apple. Failure to comply with global security standards or sanctions risks broader technical retaliation, such as browser vendors untrusting the root authority entirely.

“Almost all of these root authorities do business with the U.S., so they tend to comply with U.S. sanctions,” Toker said, noting that while TrustAsia has sought to build a regional footprint, its integration with international root programs keeps it tied to global compliance realities.

When asked about the incident, a spokesperson for the Chinese Embassy in Washington stated: “I am not aware of the specifics you mentioned. I have no information to provide.”

The digital tug-of-war over the PGSA domain comes amid a heightened enforcement campaign by Washington aimed at shutting down Tehran’s shadow banking and revenue collection streams. On Aug. 24, U.S. Treasury Secretary Scott Bessent announced a major sanctions package targeting nearly 60 individuals, foreign entities, and commercial vessels linked to Iran.

Bessent characterized the executive action as part of “Operation Economic Outcast,” an initiative designed to sever the IRGC’s foreign operational capabilities and deny Tehran access to international financial and logistical networks.

Although TrustAsia was not among the targets listed in the Aug. 24 actions, legal experts note that OFAC continually monitors foreign technical and financial service providers for potential secondary sanctions designations.

“Iran’s attempt to extort the world in the movement of oil through the Strait of Hormuz is of the utmost importance to OFAC,” Paner noted, adding that foreign corporations providing critical infrastructure or technical services to IRGC entities face severe regulatory exposure. “When it’s a Chinese tech company providing necessary services to the IRGC, I’m confident that the U.S. government is going to forego any sort of balancing in that regard.”

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *