Back
Let's Encrypt Adds U.S. Sanctions Warranty to Subscriber Agreement
SiTech AI Team3 წთ. საკითხავი

Let's Encrypt Adds U.S. Sanctions Warranty to Subscriber Agreement

Version 1.7 of the Subscriber Agreement, dated 4 June 2026, requires anyone requesting a certificate to warrant that they are not located in, organised under the laws of, or resident in a territory targeted by comprehensive U.S. sanctions.

Let's Encrypt has updated the legal terms that govern its free TLS certificates. Version 1.7 of the Subscriber Agreement, dated 4 June 2026, adds a new warranty under which anyone requesting a certificate must confirm that they are not subject to U.S. sanctions. The document was published as a redline against the previous version.

What the new clause says

The change sits in Section 3.1, which lists the warranties a subscriber accepts when requesting, accepting or using a Let's Encrypt certificate. The added text reads: "You are not a person or entity that is: (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions; (b) a prohibited or restricted party under U.S. or other applicable sanctions and export control laws and regulations; or (c) owned or controlled by or acting on behalf of anyone described in (a) or (b)." Subscribers also agree to use the certificates and any services provided by or on behalf of ISRG in compliance with applicable U.S. export control and sanctions laws.

What happens to existing certificates

The agreement takes effect as soon as a certificate is requested and stays in force for as long as any of the subscriber's certificates are valid, including automatic renewals. Section 3.2 states that if any of the Section 3.1 warranties stops being true, the subscriber must immediately ask ISRG to revoke the affected certificates. Replacement certificates may be requested before that revocation, provided the warranties hold for the replacements.

The rest of the terms are unchanged. Certificates remain the property of ISRG, which grants a royalty-free licence to reproduce and distribute them in full; ISRG may refuse a request or revoke a certificate at its sole discretion; and subscribers may not use certificates in software or hardware architectures that provide facilities for interference with encrypted communications, such as active eavesdropping or traffic management of domains they do not own or control.

Why it matters

Let's Encrypt is operated by the Internet Security Research Group, a U.S. non-profit, and its certificates secure a large share of the web's HTTPS traffic. The clause is written as a warranty made by the subscriber rather than a description of an automatic technical filter, so its practical effect depends on how the terms are enforced. The agreement can be amended: new versions are posted at least fourteen days before they take effect, and major changes are flagged with a new Subscriber Agreement version number in the ACME protocol, which client software can be configured to watch. Governing law is California, with claims to be brought in San Jose within one year of the alleged harm.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.