Ministry of Digital Development talks about Russian security certificates

Ministry of Digital Development talks about Russian security certificates

Starting from March 1, 2027, Russia will start operating a new security certificate system – it provides ten types of certificates for network resources, classified by tasks and algorithms. Russian certificates cannot replace international certificates because foreign operating systems do not trust them.

    Image credit: Philipp Katzenberger / unsplash.com

Image credit: Philipp Katzenberger / unsplash.com

A draft order of the Ministry of Digital Development released for public discussion sets out the operational plan for the National Certification Center (NCC) security certificate system, specifying ten types of certificates. In addition to authentication tools for websites, the solution also provides credentials for signing code in enterprise systems. The department clarified the requirements for root and intermediate certificates issued by the NCA – each requiring a specific set of fields. The new plan will be implemented on March 1, 2027.

NCA now issues DV and OV type TLS certificates of RSA and GOST versions through Gosuslugi. The need for them became acute this summer when foreign certification authorities began revoking Russian companies’ SSL/TLS certificates due to sanctions. The plan does not provide fundamental changes for businesses and website owners – the draft order only establishes mechanisms for submitting applications, identifying applicants, and checking the set of information shown in documents and certificates.

Russian RSA certificates provide public logging (transparency mechanism) in CT logs, that is, they will be able to function in foreign operating systems and browsers. The GOST option is only available on Russian infrastructure, and it provides binding to a specific category of CIPF (Cryptographic Information Protection Facility) with the required encryption level.

Currently, Russian cryptography is only supported by the Yandex browser and the open source Chromium GOST; interviewees said it already works in some government systems and users have become accustomed to these solutions.merchant» Expert. But large-scale transformation will require additional measures, such as customized workspaces. Using Russian certificates on the global market is not easy – foreign operating systems do not include them in trust lists, and software with such certificates is marked as signed by an “unknown publisher”.

If you find an error, select it with your mouse and press CTRL+ENTER.

Exit mobile version