Re: TURKTRUST root CA certificate inclusion request

2007-11-27 Thread Eddy Nigg (StartCom Ltd.)
Frank Hecker wrote: > I honestly don't know what the current status is, either with regard to > support for non US-ASCII strings within certs, or use of such strings by > CAs. I've made a note of this on the "CA recommended practices" wiki > page, as a reminder. > Frank, I used the "Discussio

Re: TURKTRUST root CA certificate inclusion request

2007-11-27 Thread Frank Hecker
Jean-Marc Desperrier wrote re using different character sets within certificates: > Maybe it would be adequate to require that the CA applies a policy that > lowers the risk of homograph spoofing attacks. Nameprep and the IDN > language-specific registration policy applicable to the language(s)

Re: TURKTRUST root CA certificate inclusion request

2007-11-27 Thread Jean-Marc Desperrier
Frank Hecker wrote: > Given that, why should we object to CAs putting Chinese, etc., names in > end entity certificates, as long as there is an appropriate technical > mechanism to make this work? [...] > [...] Since most of those users won't speak English, it makes sense > for domain names, na