> Forcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs?
How's the support for X.509 "Name Constraints" these days:
* https://datatracker.ietf.org/doc/html/rfc5280#section-4.2.1....
Would restricting it to only dot-ir domains be a mitigation?
The whole point with a CA is that you have a neutral third party participant. Kinda broken no matter how you look at it. Especially in this case.
Why would the Iranian government put such a constraint in its own root certificate?