Message299812
| Author |
alex |
| Recipients |
Socob, abracadaber, alex, christian.heimes, kedare, njs, tialaramex, yselivanov |
| Date |
2017年08月06日.19:46:39 |
| SpamBayes Score |
-1.0 |
| Marked as misclassified |
Yes |
| Message-id |
<1502048799.45.0.294675741208.issue28414@psf.upfronthosting.co.za> |
| In-reply-to |
| Content |
This came up on m.d.s.p. today: https://groups.google.com/d/msg/mozilla.dev.security.policy/K3sk5ZMv2DE/fx6c3WWFBgAJ
I haven't dug in deeply, but it sounds like we handle IDNs in CNs and SANs differently?
I think we should look for a way to solve that specific problem, without biting off the whole thing -- one solution would be to simply drop support for CNs in match_hostname, as both Chrome and Firefox have already done :-) |
|