Re: [Spasm] IDNA2008 and PKIX certificates
Alexey Melnikov <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Hi Russ, On 19/12/2016 17:17, Russ Housley wrote: > Nikos: > > RFC 5280 only needs to convert to punycode. The punycode form is > carried in certificate, and the punycode form is used to compare two > domain names. > > RFC 5280 refers to Section 4 of RFC 3490 for the conversion. In > addition, Section 7.2 of RFC 5280 provides some guidance about the flags > used in that process. > > RFC 5891 also referes to RFC 3490 for the conversion to punycode. > > I don't see a problem with RFC 5280 with respect to IDNA. I think RFC 5280 should be updated to say that RFC 5891 applies. This is not a big update, but it needs doing. Best Regards, Alexey > Russ > > > On Nov 25, 2016, at 3:35 AM, Nikos Mavrogiannopoulos <[email protected]> wrote: > >> Hi, >> RFC5280 and its update (6818), reference IDNA2003 (rfc3490) for >> storing internationalized DNS names. However, IDNA2003 is already >> obsolete standard (it seems it was already deprecated when RFC6818 was >> published [0]), in practice phased out, and incompatible with IDNA2008. >> My understanding is that the situation with internationalized names in >> certificates/https is not at a good state (you are lucky if it works). >> >> Is there some plan to update RFC5280 to fix that situation? an example >> would be to switch to IDNA2008 and to the corresponding ToUnicode >> operation for the reverse mapping. >> >> regards, >> Nikos >> >> >> PS. Originally posted in PKIX-list and precis groups. > _______________________________________________ > Spasm mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/spasm _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix