My understanding is that the punycode issue is not altered by this ballot, because the current definitions state: Domain Name: The label assigned to a node in the Domain Name System.
and in the DNS, the label assigned to a node with an internationalised domain name is encoded in punycode. So it is not allowed to produce certificates with UTF-encoded IDNs today. I think that if GDCA is serious about this concern, they should propose a ballot which removes the restriction that commonName must match one of the subjectAltNames. I don’t know if the world is ready for such a ballot yet, but I think the resulting discussion would be beneficial. Perhaps the ballot could propose some additional restriction(s), such as that the commonName must contain a space, or a character higher than 0x00FF in unicode, or must not contain a period, so that the commonName couldn’t be mistaken for a domain name.
smime.p7s
Description: S/MIME cryptographic signature
_______________________________________________ Public mailing list [email protected] https://cabforum.org/mailman/listinfo/public
