Re: [Spasm] IDNA2008 and PKIX certificates

Russ Housley <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Nikos:

RFC 5280 only needs to convert to punycode.  The punycode form is
carried in certificate, and the punycode form is used to compare two
domain names.

RFC 5280 refers to Section 4 of RFC 3490 for the conversion.  In
addition, Section 7.2 of RFC 5280 provides some guidance about the flags
used in that process.

RFC 5891 also referes to RFC 3490 for the conversion to punycode.

I don't see a problem with RFC 5280 with respect to IDNA.

Russ


On Nov 25, 2016, at 3:35 AM, Nikos Mavrogiannopoulos <[email protected]> wrote:

> Hi,
>  RFC5280 and its update (6818), reference IDNA2003 (rfc3490) for
> storing internationalized DNS names. However, IDNA2003 is already
> obsolete standard (it seems it was already deprecated when RFC6818 was
> published [0]), in practice phased out, and incompatible with IDNA2008.
> My understanding is that the situation with internationalized names in
> certificates/https is not at a good state (you are lucky if it works).
> 
> Is there some plan to update RFC5280 to fix that situation? an example
> would be to switch to IDNA2008 and to the corresponding ToUnicode
> operation for the reverse mapping.
> 
> regards,
> Nikos
> 
> 
> PS. Originally posted in PKIX-list and precis groups.

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.