IDN processing-related security considerations for draft-ietf-websec-strict-transport-sec

Frank Ellermann hmdmhdfmhdjmzdtjmzdtzktdkztdjz at gmail.com
Fri Sep 30 21:39:19 CEST 2011


On 30 September 2011 21:18, Peter Saint-Andre wrote:

> Adam Barth can provide more accurate insights than I can
> regarding the state and future of the browsers in this regard.

It would be interesting to have a set of RFC 5890 test pages
(with an intentionally dumb web server) at IETF.org:

http://xn--cocacola.idnatest.ietf.org/
http://na--whatever.idnatest.ietf.org/
http://_underscore.idnatest.ietf.org/
http://under_score.idnatest.ietf.org/
http://-non-ldh.idnatest.ietf.org/
http://non-ldh-.idnatest.ietf.org/

All I can immediately offer is <http://xn--xyzzy.dyndns.org>
and <http://xn--80akhbyknj4f.boldlygoingnowhere.org/>, but
that is technically boring (= valid in both IDNA versions).

-Frank


More information about the Idna-update mailing list