Our support inbox keeps getting the same message: "The VPN is connected, but Sber's website still won't open — the browser says the connection is not secure." That is not a VPN failure and not a configuration mistake. Since early August 2026 the problem has a different cause, and it is fixed on your device, not on the network.
What happened
In early August 2026, the major Russian banks moved their websites from TLS certificates issued by the Chinese authority TrustAsia to certificates from the Russian National Certification Authority run by Mintsifry (reported by iPhones.ru). The switch covers:
- Sberbank
- VTB
- Alfa-Bank
- T-Bank (tinkoff.ru)
- Rosselkhozbank
- Promsvyazbank
- Uralsib
- Bank Saint Petersburg
Safari, Chrome and Edge don't know the Russian certification authority and treat these sites as unsafe: instead of your online banking you get a red warning along the lines of "Your connection is not private", or an ERR_CERT_AUTHORITY_INVALID error.
Why the VPN is not at fault
Reaching a Russian bank from abroad now involves two independent locks, opened by different keys:
Lock 1 — the IP address. The banks block foreign IPs: anti-fraud systems refuse connections from outside Russia. This lock is opened by a VPN with a Russian server.
Lock 2 — certificate trust. Once the site is reachable, the browser checks its TLS certificate against its own list of trusted authorities. The Mintsifry authority is not on that list in Safari, Chrome or Edge — so the browser refuses to render the page. The network plays no part here: the same error pops up in Moscow on any device without the Russian certificates installed.
So "switch on the VPN" opens the first lock but is powerless against the second. And the reverse: installing a certificate won't get you in from a foreign IP. You need both.
The fix: three ways
Option 1. Yandex Browser — the fastest
The Russian certificates ship inside Yandex Browser. Install it, switch the VPN on — and the web versions of every bank listed above open without warnings. The one downside: your banking now lives in a separate browser.
Option 2. Install the Mintsifry certificates system-wide
For those who want to stay in their usual browser:
- Open gosuslugi.ru/crt — the page works without a Russian IP.
- Download both certificates: Russian Trusted Root CA and Russian Trusted Sub CA.
- macOS: open both files — they land in Keychain Access; find them there and set "Always Trust". Windows: double-click to install into the "Trusted Root Certification Authorities" store.
- Restart the browser.
Firefox is a special case: it keeps its own certificate store. Either enable "Use OS certificates" in the privacy settings, or import both files via Settings → Certificates → Import.
Important: download the certificates only from the official gosuslugi.ru — never from third-party sites or forwarded files.
Option 3. The bank's mobile app
The change affects web versions only — the mobile apps keep working: the certificates they need are built in. If the app is already on your phone, all it needs is a VPN with a Russian IP. One catch: some banks' apps have been removed from the stores and are hard to install on a new device — in that case, fall back to options 1–2.
The complete setup
- VPN Russia — opens lock №1 (a Russian IP)
- Yandex Browser or the Mintsifry certificates — opens lock №2 (browser trust)
- SMS codes — a separate story about your SIM that neither the VPN nor the certificates solve
Three pieces — and your bank works again from any country: the site, the app, the transfers.