← Internet Security Research Group cases
Bugzilla #1966515
Certificate Problem Report
Let's Encrypt: Issuance for Invalid Internationalized Domain Name
RESOLVED
INVALID
Internet Security Research Group
AI Summary
This case discusses the issuance of a certificate by Let's Encrypt that contained an Internationalized Domain Name (IDN) with a disallowed Unicode character (U+200E, LEFT-TO-RIGHT MARK). While the certificate technically complies with the Baseline Requirements due to an exception allowing certain Punycode representations, it raises significant concerns regarding user safety and potential domain spoofing. The discussion concluded that the issuance does not violate any current policies, but it highlights the need for clearer guidelines to prevent misuse of such characters in domain names.
Chronology
- Preliminary report filed by Let's Encrypt.
- Community discussion on the compliance of the certificate.
- Support for closing the bug as INVALID expressed by Chrome Root Program.
- Mozilla expresses concerns about user safety and trust.
- Final call for comments before closure.
Participants
Aaron Gable
Dimitris Zacharopoulos
Chrome Root Program
Mozilla
External References
Similar Local Cases
Let's Encrypt: Duplicate Serial Numbers
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
Let's Encrypt: Delay updating OCSP responses
Let's Encrypt: Failure to provide OCSP Responses for some certificates
Let's Encrypt: Failure to Document Analysis of Detected Vulnerabilities
Let's Encrypt: TLS Using ALPN TLS Version and OID
Let's Encrypt: Incomplete and Inconsistent CRLs
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS