CAnttRUst by ISAIandCO
Restricts the use of the Russian Trusted Root CA and verifies Russian CT logs.
Extension Metadata
Screenshots
About this extension
CAnttRUst is a Firefox extension that restricts the scope of the Russian Trusted Root CA and additionally verifies Certificate Transparency for websites that use this certificate authority.
The extension does not add or remove certificates from the system trust store and does not replace Firefox's built-in TLS verification.
When a top-level HTTPS page is opened, the extension locally inspects the certificate chain provided by Firefox.
If the Russian Trusted Root CA is found in the chain:
The certificate authority is identified by the SHA-256 fingerprint of the DER-encoded certificate, not by the displayed issuer name.
CAnttRUst does not collect or transmit browsing history, page addresses, certificates, or other user data to the developer.
Only the following data is stored locally:
URLs of blocked pages and certificate details are not written to disk. One-time bypasses are stored only in the extension's memory and expire automatically.
During normal operation, the extension does not send requests to the developer's servers.
This permission is required so that the extension can inspect top-level HTTPS navigations and obtain TLS connection information from Firefox.
The extension does not read page contents or inject scripts into websites.
The project is open source and distributed under the GPL-3.0-only license.
Source code:
https://github.com/ISAIandCO/CAnttRUst
Privacy policy:
https://github.com/ISAIandCO/CAnttRUst/blob/main/PRIVACY.md
The extension does not add or remove certificates from the system trust store and does not replace Firefox's built-in TLS verification.
When a top-level HTTPS page is opened, the extension locally inspects the certificate chain provided by Firefox.
If the Russian Trusted Root CA is found in the chain:
- navigation is blocked with a warning page outside the
.ru,.su, and.рфdomain zones; - within the allowed zones, the embedded SCT is verified;
- the SCT must be cryptographically valid and belong to one of the pinned Russian CT logs;
- if the result is negative or inconclusive, a warning is displayed.
The certificate authority is identified by the SHA-256 fingerprint of the DER-encoded certificate, not by the displayed issuer name.
- local TLS certificate chain inspection;
- verification of embedded SCTs from Russian CT logs;
- dedicated warning page;
- per-host exceptions for exact DNS names;
- one-time warning bypass;
- settings export and import;
- no analytics, advertising, or remote code.
CAnttRUst does not collect or transmit browsing history, page addresses, certificates, or other user data to the developer.
Only the following data is stored locally:
- extension state;
- selected CT verification mode;
- user-created exceptions for exact DNS names.
URLs of blocked pages and certificate details are not written to disk. One-time bypasses are stored only in the extension's memory and expire automatically.
During normal operation, the extension does not send requests to the developer's servers.
This permission is required so that the extension can inspect top-level HTTPS navigations and obtain TLS connection information from Firefox.
The extension does not read page contents or inject scripts into websites.
- Only the Russian Trusted Root CA specified in the built-in policy is checked.
- Only SCTs embedded in the end-entity certificate are verified.
- SCTs delivered via TLS or OCSP are not checked by the current version.
- Verification depends on Firefox providing the full certificate chain and DER-encoded certificates.
- The extension does not override Firefox's standard certificate errors and does not make an untrusted certificate trusted.
The project is open source and distributed under the GPL-3.0-only license.
Source code:
https://github.com/ISAIandCO/CAnttRUst
Privacy policy:
https://github.com/ISAIandCO/CAnttRUst/blob/main/PRIVACY.md
Rated 0 by 0 reviewers
Permissions and data
Required permissions:
- Access your data for all websites
Data collection:
- The developer says this extension doesn't require data collection.
More information
- Add-on Links
- Version
- 0.1.1
- Size
- 117.38 KB
- Last updated
- 9 days ago (Aug 25, 2026)
- Related Categories
- Version History
- Add to collection