Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

China Firm Gives Iran Strait Authority a Lifeline Then Pulls the Plug

A Chinese certificate authority briefly restored Iran's Hormuz tolls website before pulling the plug amid US sanctions warnings.

By mitch·7 min read
A cracked digital certificate icon symbolizes the revocation of a website's security credential.

The standing of Iran’s maritime authority briefly regained secure online access to its website after a Chinese certificate authority issued it a new digital credential — then revoked that credential, leaving the site’ has yet to be settled. The action followed weeks after the entity was placed on the OFAC sanctions list.

On Aug. 10, the Persian Gulf Straits Authority (PGSA) reported that its website had been disrupted, citing “the enemy’s political influence on the internet service provision systems.”. Six days later, on Aug. 17, the authority announced that the problem had been fixed and that the secure domain https://pgsa.ir was back online. The statement also noted that should the issue return in the future, the HTTP domain would once again be made temporarily accessible through the Firefox browser.

How the Certificate Worked

The PGSA received a new Domain Validated TLS certificate from TrustAsia Technologies, a certificate authority based in Shanghai. This automated issuance confirms ownership of a website domain through server checks alone, with no manual vetting or background checks involved.

Advertisement

Alp Toker, who runs NetBlocks, confirmed that Iran had turned to TrustAsia. The certificate restored secure access to the PGSA website, he said.

When the certificate expired, the site became exposed. The usual SSL/TLS certificates vanished, leaving the PGSA website unable to be reached through ordinary browsers. Carriers had no choice but to resort to connections without encryption. No data breaches tied to the use of these unprotected links have come to light, nor has any case where a carrier’s information was captured and turned against it due to the certificate expiring been reported.

The site’s lack of access drove a change toward what Toker called “insecure protocols.”, which he described as “a class of vulnerability open to government exploitation, rather than a corporate breach or personal data leak.”.

He said the website was more difficult to access because most web browsers strongly encourage the use of secure HTTPS. Any form submissions could have been easily “eavesdropped on because they’re no longer encrypted in transit.”

The Sanctions Warning

In May, the U.S. Treasury labeled the entity, stating that Iran’s IRGC forces ships passing through the Strait of Hormuz to pay via the so-called Persian Gulf Strait Authority. The Treasury further said that the PGSA “spearheads an Iranian-controlled scheme that flagrantly violates international law and U.S. sanctions.”

The Treasury warned anyone cooperating with the PGSA “may be providing support to and receiving services from the IRGC, which ultimately benefits from this attempted extortion, and may therefore be exposed to sanctions risk.”

Jeremy Paner, a U.S. sanctions expert and partner at Hughes Hubbard & Reed, advised TrustAsia to examine its compliance program before proceeding with any additional services for the maritime authority tied to the IRGC. He cautioned TrustAsia to take action “before it is too late.”.

Paner explained that the U.S. holds vast power to punish foreign firms that supply any kind of services to Iranian companies already marked by sanctions. He also noted that even a small amount of services can serve as grounds for the U.S. to impose sanctions on a company for aiding Iran.

He made it clear that restoring the certificate is sanctioned territory. He explained that giving the certificate back to the PGSA counts as a service that can support sanctions under Executive Order 13224, as amended. He also stated that the fact that the service happens automatically carries no weight and does nothing to change its sanctionable status.

The Brief Window of Secure Access

For four days, the PGSA had secure online access restored when TrustAsia gave it its web credentials, before revoking them. That certificate put the website back in working order, so shipping firms could send requests from any browser.

The period of stability did not last long. TrustAsia took away the credentials, which left the site’s secure status without any clear standing.

Event Date Details
Website disruption announced Aug. 10 PGSA blamed “the enemy’s political influence on the internet service provision systems”
Certificate issued Not specified TrustAsia provided a Domain Validated TLS certificate
Secure access restored Four-day window PGSA website accessible using standard browsers
Credentials revoked Within days Certificate revoked
Issue resolved announced Aug. 17 PGSA said the secure domain https://pgsa.ir was once again available

The Chinese Angle

TrustAsia bills itself as a “leading and professionally certified certification authority in China with its focus on trusted, secure and cryptographic communications in the digital world.” Its mission is to “Build trust everywhere in the digital world.”

Toker pointed out that nearly all of these root authorities work with the U.S., which means they usually go along with U.S. sanctions. He also observed that TrustAsia had “gone its own way, building a China-first certificate infrastructure that sidesteps the West.”.

TrustAsia was described by him as having “simply gone ahead and issued Iran’s PGSA with a new certificate, and Iran was once again collecting revenue from ships passing the Strait via its secure online portal.”.

On Aug. 20, a spokesperson for TrustAsia told Fox News Digital that the firm had issued a “Domain Validated TLS certificate for pgsa.ir.”. The spokesperson said the company was grateful to Fox for raising the issue, and explained that DV certificates are given out after automatic checks confirm control of the requested domain names.

What This Means for Shipping Firms

Firms caught between the two governments now find themselves in a practical bind. They must send requests to the PGSA, yet the site’s inability to be reached compels them to rely on less secure means.

The certificate expiration introduced a weakness that could be taken advantage of by governments or other parties who can see what moves across the network. Toker explained that the action pushed the traffic into a form that was simple to capture.

The PGSA’s Aug. 17 statement proposes a short-term solution: should the problem come back, the HTTP domain will once more be made available through the Firefox browser. This is a backup plan, not a permanent solution.

Paner issued a warning about the danger to TrustAsia. The U.S. Treasury holds wide power to impose sanctions on firms that supply services to sanctioned Iranian entities, and the fact that TrustAsia’s service runs automatically offers no protection against that danger.

The Bottom Line

A certificate was handed out to an entity under sanction by TrustAsia, which later took it away. That four-day stretch during which secure access was available actually happened, but it came to a close when the Chinese company withdrew the credentials.

The Treasury of the United States has stated its view: those who provide services to the PGSA place themselves at risk of falling under sanctions.

Paner put it plainly: restoration of the certificate is unequivocally sanctionable.

The PGSA’s website still carries vulnerabilities. Companies that rely on it for shipping requests must decide whether the risk of exposing their data outweighs the necessity of submitting those requests.

Secure access has ended for now. The open questions are whether TrustAsia will produce another certificate — and whether the U.S. Treasury will answer with action.

Where the paper stands

The paper backs the small certificate authority that issued the credential and is against the big certificate authority that revoked it. A certificate authority that issues a credential to a sanctioned entity is acting against the public interest, while the authority that then takes the credential away is doing the right thing, however belatedly.

The paper opposes rules that raise the cost of entry for small businesses, and it sees certificate authorities as a field where such rules are often written by the biggest players. A certificate authority that operates outside the usual Western alignment and issues a credential to a sanctioned entity is acting like a small business that has simply ignored the rules — which is a different matter entirely from a large, established player that helps write the rules it then enforces.

The paper supports small business against both the agency and the giant. In this case, the small certificate authority acted on its own, while the larger authority — the one that revoked the credential — is the one that deserves support. The revocation shows that even a small actor can face consequences when it ignores the law.

Source material: “China firm gave Iran lifeline to collect Hormuz tolls before pulling plug amid US warning,” Fox News.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.