Re: [Spasm] IDNA2008 and PKIX certificates
Russ Housley <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Nikos: RFC 5280 only needs to convert to punycode. The punycode form is carried in certificate, and the punycode form is used to compare two domain names. RFC 5280 refers to Section 4 of RFC 3490 for the conversion. In addition, Section 7.2 of RFC 5280 provides some guidance about the flags used in that process. RFC 5891 also referes to RFC 3490 for the conversion to punycode. I don't see a problem with RFC 5280 with respect to IDNA. Russ On Nov 25, 2016, at 3:35 AM, Nikos Mavrogiannopoulos <[email protected]> wrote: > Hi, > RFC5280 and its update (6818), reference IDNA2003 (rfc3490) for > storing internationalized DNS names. However, IDNA2003 is already > obsolete standard (it seems it was already deprecated when RFC6818 was > published [0]), in practice phased out, and incompatible with IDNA2008. > My understanding is that the situation with internationalized names in > certificates/https is not at a good state (you are lucky if it works). > > Is there some plan to update RFC5280 to fix that situation? an example > would be to switch to IDNA2008 and to the corresponding ToUnicode > operation for the reverse mapping. > > regards, > Nikos > > > PS. Originally posted in PKIX-list and precis groups. _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix