Re: [Servercert-wg] IDNA2003 vs IDNA2008 usage

2024-03-19 Thread Corey Bonnell via Servercert-wg
Hi Martijn, The same Punycode algorithm as defined in RFC 3492 is used by IDNA2003, 2008, and more to convey Unicode code points in domain labels in a way that conforms to the LDH syntax. The BRs currently require that any labels that are prefixed with “xn—” contain valid Punycode-encoded

Re: [Servercert-wg] Ballot to introduce linting in the TLS BRs

2024-03-19 Thread Dimitris Zacharopoulos (HARICA) via Servercert-wg
On 19/3/2024 6:31 μ.μ., Ben Wilson wrote: Hi Dimitris, You can add me. Thanks Ben, Ballot SC-73 has been assigned to address this issue. Best regards, Dimitris. Thanks, Ben On Tue, Mar 19, 2024 at 9:01 AM Dimitris Zacharopoulos (HARICA) via Servercert-wg wrote: On 19/3/2024

Re: [Servercert-wg] Ballot to introduce linting in the TLS BRs

2024-03-19 Thread Ben Wilson via Servercert-wg
Hi Dimitris, You can add me. Thanks, Ben On Tue, Mar 19, 2024 at 9:01 AM Dimitris Zacharopoulos (HARICA) via Servercert-wg wrote: > > > On 19/3/2024 5:27 π.μ., Corey Bonnell wrote: > > Hi Dimitris, > > I’d be happy to endorse and help flesh out the language. > > > Thank you Corey, I added your

Re: [Servercert-wg] Discussion Period Begins - Ballot SC-067 V1: "Require domain validation and CAA checks to be performed from multiple Network Perspectives”

2024-03-19 Thread Ben Wilson via Servercert-wg
Greetings Antti, Somehow, our group (working on the Subscriber Agreement/Terms of Use ballot) had selected ballot number 67 on the wiki, but there were two different wiki pages with ballot numbers that people were unaware of (which led to a second selection of #67 by Chris and Ryan). So Dustin,

Re: [Servercert-wg] Ballot to introduce linting in the TLS BRs

2024-03-19 Thread Dimitris Zacharopoulos (HARICA) via Servercert-wg
On 19/3/2024 5:27 π.μ., Corey Bonnell wrote: Hi Dimitris, I’d be happy to endorse and help flesh out the language. Thank you Corey, I added your name on the table with future ballots. Is there anyone else? Best regards, Dimitris. Thanks, Corey *From:*Servercert-wg *On Behalf Of

Re: [Servercert-wg] Discussion Period Begins - Ballot SC-067 V1: "Require domain validation and CAA checks to be performed from multiple Network Perspectives”

2024-03-19 Thread Dimitris Zacharopoulos (HARICA) via Servercert-wg
Hi Chris, On 18/3/2024 5:32 μ.μ., Chris Clements via Servercert-wg wrote: Intellectual Property (IP) Disclosure: - While not a Server Certificate Working Group Member, researchers from Princeton University presented at Face-to-Face 58, provided academic expertise, and highlighted

Re: [Servercert-wg] Discussion Period Begins - Ballot SC-067 V1: "Require domain validation and CAA checks to be performed from multiple Network Perspectives”

2024-03-19 Thread Dimitris Zacharopoulos (HARICA) via Servercert-wg
Hi Antti, The ballot number seems to be ok. Check out https://wiki.cabforum.org/books/server-certificate-wg/page/scwg-ballots-wuG It looks like Ben and Dustin need to get a new number and add a row to the corresponding table. Thanks, Dimitris. On 19/3/2024 7:19 π.μ., Backman, Antti

[Servercert-wg] IDNA2003 vs IDNA2008 usage

2024-03-19 Thread Martijn Katerbarg via Servercert-wg
All, We’ve recently become aware that some CAs have issued certificates containing punycode encoded domain labels compatible with IDNA2008, that are not compatible with IDNA2003. Our own interpretation is that IDNA2008 is currently not permitted. While the LDH, Non-Reserved LDH and XN