Re: IDNA2008 and PKIX certificates
Sean Turner <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Nikos, I asked about this in 2011 and here’s the response I got from an “apps” person (shared with permission): spt > On Apr 13, 2011, at 14:51, Pete Resnick <[email protected]> wrote: > >> I'm curious if there's something that lists the differences between the IDNA 2003 and 2008 for a layman. I've got a WG that wants to update the references, but I don't think it's just as easy as that. > > It is most certainly *not* as easy as that. You could send them to RFC 5894, but that's not a list of differences; it's an entirely new design philosophy. If you've got a WG that wants to update references, send them to PRECIS. We're here to help.™ > > pr > On Nov 22, 2016, at 05:02, Nikos Mavrogiannopoulos <[email protected]> wrote: > > Hi, > RFC5280 and its update (6818), reference IDNA2003 (rfc3490) for > storing internationalized DNS names. However, IDNA2003 is already > obsolete standard (it seems it was already deprecated when RFC6818 was > published [0]) and in practice phased out. What is the current best > practice on internationalized names with certificates? > > Is it transparently switch to IDNA2008 (rfc5890), and let software > figure out the reverse mappings to utf8 somehow? > > Or is it store UTF-8 dns names on the certificate, and let the software > comparing DNS names do any mapping it deems necessary prior to > comparison? > > regards, > Nikos > > [0]. https://www.ietf.org/mail-archive/web/pkix/current/msg28386.html > > _______________________________________________ > pkix mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/pkix _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix