[DNSOP] Re: draft-ietf-dnsop-integration text on ASCII-or-no t

"Kaizer, Andrew" <[email protected]> Tue, 21 Jul 2026 08:52:13 +0000
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
Thanks for the proposed text, Ben! Based on Andrew Sullivan's note, would the following update to the last sentence still address your point:

   When interacting with non-technical users, applications should
   present and accept domain names in Unicode "u-label" format
   [RFC5890].  Special care must be taken to avoid homograph attacks in
   the user interface.  In the DNS wire format, applications should only
   use domain names that conform to the "Preferred Name Syntax"
   [RFC1034] or the Attrleaf syntax [RFC8553].  Domain names in wire-
   format should be checked for alignment with such syntax to avoid
   security risks and user confusion.

-- Andrew Kaizer

On 7/20/26, 10:28 PM, "Andrew Sullivan" <[email protected] <mailto:[email protected]>> wrote:


Caution: This email originated from outside the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe. 


On Mon, Jul 20, 2026 at 02:45:24PM -0500, Ben Schwartz wrote:
> Domain names in wire-format should be checked for non-compliant
>characters (e.g.
> labels containing ".", uppercase, whitespace, or non-ASCII characters) due to
> security risks.


I'd be pretty surprised to learn that labels containing uppercase characters have wire-format labels that are not compliant. The protocol documents explicitly say you're supposed to preserve the case but ignore it for matching purposes.


A


-- 
Andrew Sullivan
[email protected] <mailto:[email protected]>


_______________________________________________
DNSOP mailing list -- [email protected] <mailto:[email protected]>
To unsubscribe send an email to [email protected] <mailto:[email protected]>



_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]