Iran's Persian Gulf Straits Authority (PGSA) briefly regained secure online access after a Shanghai-based internet security firm, TrustAsia, issued and then revoked its web credentials. This allowed Tehran to vet vessels and collect tolls at the Strait of Hormuz despite U. S. sanctions, according to global internet monitors.
The PGSA's website had been inaccessible since it was added to the U. S. Office of Foreign Assets Control (OFAC) sanctions list on May 27. The absence of standard SSL/TLS certificates forced shipping firms to use unencrypted connections, raising concerns about data vulnerability. Although no breaches have been reported, the site's inaccessibility led to a shift to insecure protocols, CEO of NetBlocks.
TrustAsia issued a domain-validated certificate, a routine process that verifies control of a website domain through server checks. This automated process typically does not involve manual vetting or background checks. However, U. S. sanctions experts, including Jeremy Paner of Hughes Hubbard & Reed, have urged TrustAsia to review its compliance program, warning of potential sanctions risks.
The PGSA had initially reported on August 10 that its website was disrupted due to political influence on the internet service provision systems. By August 17, the PGSA announced that its secure domain was once again available for use.
Despite the temporary restoration of secure access, the Treasury Department has warned that cooperating with the PGSA could expose entities to sanctions risks. The department stated that the PGSA is involved in an Iranian-controlled scheme that violates international law and U. S. sanctions.
TrustAsia, which describes itself as a certification authority in China, confirmed that it issued a Domain Validated TLS certificate for pgsa.ir. The company clarified that its automated process does not verify the legal identity or sanctions status of the entity operating the domain. Following a review, TrustAsia added the entire pgsa.ir domain to its restricted-issuance list and began revoking the existing certificate.
Toker confirmed that the TrustAsia certificate's privilege was withdrawn on August 21. He noted that this revocation signals that the PGSA certificate should no longer be trusted, usually indicating customer misuse or breached terms of use.
Paner emphasized that the U. S. has broad authority to impose sanctions on non-Iranian companies providing services to sanctioned Iranian entities. He noted that any level of service could be the basis for sanctions, regardless of whether the service was knowingly provided.
TrustAsia's actions are seen as precautionary compliance and risk-control measures. The company stated that these should not be interpreted as a finding that the certificate was technically misissued. However, the incident has drawn attention to the complexities of compliance with U. S. sanctions and the potential consequences for companies involved.
The revocation of the certificate means that the PGSA's secure website will stop working in most browsers unless a new certificate authority is found. This development underscores the ongoing challenges faced by Iranian entities under U. S. sanctions and the potential implications for international firms interacting with them.















