Wow, so would non-gov-signed certs be completely banned? Like if a website used Let's Encrypt, then would the government just ban people from accessing it? How would that even play out with VPNs? This seems so completely unenforceable, unless Spain decided to enact a China-style Great Firewall, and even then this would be an entirely different level.
They tried to do that in Kazakhstan in 2019. Mandate a root cert installed everywhere, then MITM everything.
Ofc the attempt failed.
They stopped?
Technically still end-to-end but in that case you can’t trust one end.
So spain would have to make a certificate for EVERY website? How would it work, when you would visit a canadian or brasilian website?