[DNSOP] Re: draft-ietf-dnsop-integration text on ASCII-or-not
Ben Schwartz <bemasc@meta.com> Thu, 23 July 2026 16:38 UTC
Return-Path: <prvs=5664b15bfe=bemasc@meta.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 8E6EC11D99C2F for <dnsop@mail2.ietf.org>; Thu, 23 Jul 2026 09:38:36 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784824716; bh=G4+2vu2RClDYEVOnpUIrJ+dOsOpY4NBFhD9WSvI2wP4=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=m7bOrr8Wz4oroFAsIUA8LqgDLPj4mkIKvCAoWjBmo7F+KRZLgzK/sljAcXtUDmlxT yDw9/lmVoTqtAWiQvweC4iA4aHCJ8JA9VBWIQzPxScx9eQ383GoyrpaPtYo0yRV6Mp 3JIUPjc9I8eQGgkG6ucNVEQ5BVItUttoQ4LT5QmI=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.794
X-Spam-Level:
X-Spam-Status: No, score=-2.794 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=meta.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id am5X2dTyGfca for <dnsop@mail2.ietf.org>; Thu, 23 Jul 2026 09:38:36 -0700 (PDT)
Received: from mx0a-00082601.pphosted.com (mx0a-00082601.pphosted.com [67.231.145.42]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id EA44B11D99C26 for <dnsop@ietf.org>; Thu, 23 Jul 2026 09:38:35 -0700 (PDT)
Received: from pps.filterd (m0109334.ppops.net [127.0.0.1]) by mx0a-00082601.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66NFVu9e3086431 for <dnsop@ietf.org>; Thu, 23 Jul 2026 09:38:34 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=meta.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=s2048-2025-q2; bh=CP55/Oqt6JmDg+lRR2ukii9Yi8intt1rlZJRYgBP4XQ=; b=cacOfNuxe714 40ZNz2edtnJ3+OaouyFqm2rHWwueGG/qy3XNxWWMK6eKwqchcSB5fPRTR2PN3wCN NepoJOozrNbCyZR7GQFuP/dwpl5U/uZqJhKGDt/TKXe2aEiC65zRllQDgNjP16cz 8h8+1p4gCkTUxa0hm5FsNYrypXF6IhHku5Tgt+n4o9BjcCFrAUI8SRlUepUsMqh4 zFriyaTcSW4MH6/Zfo7LC/jHVd1nWiQBazpbK34E7wV5/BhdPynmc6NsTL4VIVde e/IJGfkvukm8MzMVtxRBqRu0MTaEaDrHyZaidzu4K52aQkPHto16M+xmHZeE285D TdFda5AQ8g==
Received: from mail-yw1-f200.google.com (mail-yw1-f200.google.com [209.85.128.200]) by mx0a-00082601.pphosted.com (PPS) with ESMTPS id 4fjejhx8ex-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for <dnsop@ietf.org>; Thu, 23 Jul 2026 09:38:34 -0700 (PDT)
Received: by mail-yw1-f200.google.com with SMTP id 00721157ae682-7f5b54da461so13337367b3.3 for <dnsop@ietf.org>; Thu, 23 Jul 2026 09:38:33 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1784824713; cv=none; d=google.com; s=arc-20260327; b=VeFKLHD/dwkQDg5fPdRX4p7glBU1LnfJnCs5F57VhobPAg6pJdyxm4Uz9/qIVDV3pi qaVC5LF0H9lok3LW6NEIgNkomoX1O7Jm9KeE0us13qBNfqarQYXpB7lJWjEA6hwm+X1e V5PCnki2AZ5iHTEBQz8FGuJFlc1Vo6AYxvf/8k7s3fRCQf+js0My7laBPdLqKAf07Pmr vyWpEgMPFIbYEi3wJIptt/TXSmt5eRgTd46BjbmxiDw7P/QtarnQF32VY4Da13S4KIGz 9wNTVm6iJcj7wkSyOeXrPDeVHNPJnSuYA75PJmLvYQWl1egiZzrUv4R0HJqn94yuRGrR gRig==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version; bh=Wx8pXgeBiXup4WiKYRaQteuk9V++fXKxQ+f+BrdOMfs=; fh=lYCaZ6+FJMh+ewxkOFBoIAwPmubkMy74QGfopl1KMs4=; b=j8bIB2oQ96hPyJq2L700KWVg9QAOUnI+/S6aYCL5wUibB48ijBovk00g6kpgmUkmjq SJxM8pS9cpWMQE6x/UvFwFWNM/9X+50CxqYpB+jo2xrMbhNnIiOmULNFdZ/3uJv9JVa/ ooOBM+TR/agc3IppW0c6RNSoZiuiLjMzq/biELqCz+OT42c3pR6ympGW8ilsLSLRQQNf qNsnH1BsfwUQYj8qE+RBymJ7EcNN4Kbcb8yBoPkpEm+S2N417SzN+wouTwJUfMb2Q9Bl uXFrIBx0Hs+/9TRcoNvY4VVOl0qWoigKjyhgTHwPL3+L6FGcBVlQR7lOf3ejuyuDoK2d LATg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784824713; x=1785429513; h=content-transfer-encoding:content-type:cc:to:subject:message-id :date:from:in-reply-to:references:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Wx8pXgeBiXup4WiKYRaQteuk9V++fXKxQ+f+BrdOMfs=; b=WjdJ01jeeb4lADcBaKDKhDkdxy/P5JZkh3uCDhFG1PyKa6dEFLXn+kkZWa63N1A6xv RF1OdN9rJ/EU49ZZVeSCoyzP9AWRrUxb+iBzM8d/DgWa74+uhvOtDUJe11kn5VLZcDvm z7QZOkq950xrykEvtr4h8aizXZrjiDalOY4JdJFTtPmBLPe1M7IhvXYZfpA1uBCTEpYV 6wET/zLP7p0upZLCHzczJUHWSSisltmHou2zauSvbucjI/HTSDehL4afQinw8AmVEPDS 68j5kisGZHes1FdhcR88saRWUW027NmrZwppZiTQVj5f0JWoD8m8azqrTQK0sikuNnn6 ZFHA==
X-Forwarded-Encrypted: i=1; AHgh+Rq+01YT1xdcq18ueEOzzc/TD4ossEE5UWAEtyVmtWejRX4JEaNgzzd3ff5BW6Frhly4ofODKQ==@ietf.org
X-Gm-Message-State: AOJu0Yxq4HOdyqG5YAR3aDOtxKj8on2Vdcs+Nino4/W51/EdBXOKzRQw 1bSkYPRUF2T49F0tpTq2qtdVVcDkL2WcuUdDpC/6rx1mC7drlGd3yuRp4432D0zINGcx4EGyzNk byYIMr6zq2Uqh0EpUgl7bWlbyd9crbkvWkqVbtcug11pvMkYitmuLVq+GoU/HBCZBEafeTmGuv0 cOLzSE5U4Ufh/emedPNrbt6Qf4k9s6
X-Gm-Gg: AR+sD10/9fHPxKjhf7532V+CJHFVS27uaMWWHsAD5vqra/+7BFOPAOs2HByJG3ZfE/R 6h/7ZG5uCeW0PH1GNKSQz2zgyfQvx0MF0D7qYh+cfVO7qyVfwTso8z/n6EUHTnKn0AFmq5rwpwZ lfLw8k/480JJIZV+Rk96nxA2kLuwpPgZJEWC+wUALqUCh33CB3m/+2oK/fWfKsf/644Y1ObLPlf L9hkGOeY8W7T6Jx
X-Received: by 2002:a05:690c:498d:b0:814:6ca5:ef99 with SMTP id 00721157ae682-81f4c15e628mr12349987b3.16.1784824712815; Thu, 23 Jul 2026 09:38:32 -0700 (PDT)
X-Received: by 2002:a05:690c:498d:b0:814:6ca5:ef99 with SMTP id 00721157ae682-81f4c15e628mr12349837b3.16.1784824712071; Thu, 23 Jul 2026 09:38:32 -0700 (PDT)
MIME-Version: 1.0
References: <CAOdQrVO7jgYk6JW4oCTYCJRXmYvUGR0kNFUYq_9T4BLzCoe5nw@mail.gmail.com> <al6EPN2VuUS6jv7K@crankycanuck.ca> <7784D8D5-4387-4505-A125-D2702B64D2EA@verisign.com> <CAOdQrVNm4qL3cuCFKmev5UJo=DEuO5gAwG902UfNqag5XP7XvA@mail.gmail.com> <A2E11F72-3A68-4774-A686-901528585ABF@verisign.com>
In-Reply-To: <A2E11F72-3A68-4774-A686-901528585ABF@verisign.com>
From: Ben Schwartz <bemasc@meta.com>
Date: Thu, 23 Jul 2026 12:38:20 -0400
X-Gm-Features: AUfX_mwHF3gfJ33wg4lu9kvUDJO_w8Puk02bZhxy_6417Fp9W-YiiTfbrrb99rY
Message-ID: <CAOdQrVO1LMK5WGkZsD_n+TbSTTN6ZmD7WHxDwy0eyA+bkZ_E3w@mail.gmail.com>
To: "Kaizer, Andrew" <akaizer=40verisign.com@dmarc.ietf.org>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Proofpoint-GUID: haR_IsOMlKaA4XTutRZQM9f64FAEp9JC
X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzIzMDE2MyBTYWx0ZWRfXx3fEe7E4TgWC PgY+retd5KqmUHf05zZFbqaBcTCYfXuKuFSvelffRvLuMj0qgCW4uysnQMP46JAIxxZk/o1vWA7 NfNvhyZP1stSJQcdXo+Y/keE+UnXl3W1vC2Wcg6yGl8NpOUCXKAb1w7oDkPkzsVS/LEWr5zlRGV GGYt++JwXm+rhgeyMIDoNGQtyHwn2QxE7Yn+1XfLMORA/uJiQ5Ei1+Wwkqmx4zOdRcsDym7Xzpx FPlLnKFTuW2erd3az/jAHrgQbJncx6Yk8p8iZ2UYBzwFp3HW+sNgSdcNhVjJz8BMUiSSpklUgXR saJtvagGi6DPI6eiOdijqzm+m59TohE6szIUu5E+9yV09SHgKAhv/w3mc7QZAVc4cctyYBEWgw6 KfKOfAitMDnIHUWdgOjHibVOjpLR9uSMdPTq6LUkWg1RbIcY7aQ/dFx5TzH4XePe+9GAJ+fsJPv uhi01rMhOoBvvKHE5eQ==
X-Authority-Analysis: v=2.4 cv=fsPsol4f c=1 sm=1 tr=0 ts=6a62438a cx=c_pps a=NMvoxGxYzVyQPkMeJjVPKg==:117 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=7x6HtfJdh03M6CCDgxCd:22 a=crHB47gyY4rKiduisYu9:22 a=48vgC7mUAAAA:8 a=SSmOFEACAAAA:8 a=Pf6QpW2kAAAA:8 a=JmD40u4PrPhGYGXFUx0A:9 a=lqcHg5cX4UMA:10 a=QEXdDO2ut3YA:10 a=kLokIza1BN8a-hAJ3hfR:22 a=aScfhB3owP0e7kdt9tb6:22
X-Proofpoint-Spam-Info: AW1haW4tMjYwNzIzMDE2MyBTYWx0ZWRfXwykS4kqHnOcu ITdZsu2jGrSBPjbS8cwrxsq1T8tGNm8RZjib6UNAdFTRNMN9qNgnsWY0FYTLH/x2ath0i7AqtMF q4rgsOt5wIb4QieEsgCvQV7J/yFpRtk=
X-Proofpoint-ORIG-GUID: haR_IsOMlKaA4XTutRZQM9f64FAEp9JC
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-23_04,2026-07-22_02,2025-10-01_01
Message-ID-Hash: MLT3KPFEUB6TBB5HKNXIFDOP5NCSV7TM
X-Message-ID-Hash: MLT3KPFEUB6TBB5HKNXIFDOP5NCSV7TM
X-MailFrom: prvs=5664b15bfe=bemasc@meta.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "ajs@anvilwalrusden.com" <ajs@anvilwalrusden.com>, "dnsop@ietf.org" <dnsop@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: draft-ietf-dnsop-integration text on ASCII-or-not
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/noF0QuM6YFAsSN5g1QiwIl1YU2Q>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
Looks good to me. On Thu, Jul 23, 2026 at 12:20 PM Kaizer, Andrew <akaizer=40verisign.com@dmarc.ietf.org> wrote: > > > > Thanks for the text. How about the following for the last paragraph: > > Displaying, normalizing, comparing, encoding, and decoding of domain > names requires special processing, and cannot rely on generic string > operations alone. In the user interface, applications should take > care to prevent potential attacks related to visually similar > characters as described in Section 4.4 of [RFC5890]. Other security > risks include improper use of case-sensitive comparison and failure > to reject names whose labels contain non-preferred characters. > > I would prefer to keep the references to IETF documents as possible, so RFC5890 4.4 seems most applicable. I also updated the second paragraph to state RFC1034 which has a definition for "preferred name syntax" which I did not find in RFC1123. > > --Andrew Kaizer > > On 7/23/26, 4:16 PM, "Ben Schwartz" <bemasc=40meta.com@dmarc.ietf.org <mailto:40meta.com@dmarc.ietf.org>> wrote: > > > Caution: This email originated from outside the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe. > > > Here's an updated proposal: > > > DNS integrations should be aware that the list of valid global > DNS TLDs can change, so should not hard code a list of accepted TLDs. > If applications want a list of currently valid TLDs, they can use a > routinely updated list of public suffixes such as that provided by > IANA [IANA-PSL]. Failure to account for new TLDs may lead > to inadvertent exclusion which could also lead to registrant and user > confusion. > > > When interacting with non-technical users, applications should present and > accept domain names in Unicode "u-label" format [RFC5890]. > In the DNS wire format, applications should only use domain names that > conform to the "Preferred Name Syntax" [RFC1123] or the Attrleaf > syntax [RFC8553]. Applications should store and display names only in > fully-qualified form without the final ".", unless they also > require access to > network-local search domains [RFC3397]. > > > Displaying, normalizing, comparing, encoding, and decoding of domain names > requires special processing, and cannot rely on generic string > operations alone. > In the user interface, applications should take care to prevent > homograph attacks > (https://urldefense.com/v3/__https://www.w3.org/International/articles/idn-and-iri/Overview.en*phishing__;Iw!!Bt8RZUm9aw!6bQH6nmitBR-l_XMJgu5ct-g_cY60OBIR88K4zlRRcLGzJi__uCaDd5wm5USqbgqjNNNavMlM7fUVv0vJqR4JFUM5eo$ <https://urldefense.com/v3/__https://www.w3.org/International/articles/idn-and-iri/Overview.en*phishing__;Iw!!Bt8RZUm9aw!6bQH6nmitBR-l_XMJgu5ct-g_cY60OBIR88K4zlRRcLGzJi__uCaDd5wm5USqbgqjNNNavMlM7fUVv0vJqR4JFUM5eo$ >). > Other security risks include improper use of case-sensitive comparison > and failure to reject names whose labels contain non-preferred characters. > > > On Tue, Jul 21, 2026 at 4:52 AM Kaizer, Andrew > <akaizer=40verisign.com@dmarc.ietf.org <mailto:40verisign.com@dmarc.ietf.org>> wrote: > > > > > > > Thanks for the proposed text, Ben! Based on Andrew Sullivan's note, would the following update to the last sentence still address your point: > > > > When interacting with non-technical users, applications should > > present and accept domain names in Unicode "u-label" format > > [RFC5890]. Special care must be taken to avoid homograph attacks in > > the user interface. In the DNS wire format, applications should only > > use domain names that conform to the "Preferred Name Syntax" > > [RFC1034] or the Attrleaf syntax [RFC8553]. Domain names in wire- > > format should be checked for alignment with such syntax to avoid > > security risks and user confusion. > > > > -- Andrew Kaizer > > > > On 7/20/26, 10:28 PM, "Andrew Sullivan" <ajs@anvilwalrusden.com <mailto:ajs@anvilwalrusden.com> <mailto:ajs@anvilwalrusden.com <mailto:ajs@anvilwalrusden.com>>> wrote: > > > > > > Caution: This email originated from outside the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe. > > > > > > On Mon, Jul 20, 2026 at 02:45:24PM -0500, Ben Schwartz wrote: > > > Domain names in wire-format should be checked for non-compliant > > >characters (e.g. > > > labels containing ".", uppercase, whitespace, or non-ASCII characters) due to > > > security risks. > > > > > > I'd be pretty surprised to learn that labels containing uppercase characters have wire-format labels that are not compliant. The protocol documents explicitly say you're supposed to preserve the case but ignore it for matching purposes. > > > > > > A > > > > > > -- > > Andrew Sullivan > > ajs@anvilwalrusden.com <mailto:ajs@anvilwalrusden.com> <mailto:ajs@anvilwalrusden.com <mailto:ajs@anvilwalrusden.com>> > > > > > > _______________________________________________ > > DNSOP mailing list -- dnsop@ietf.org <mailto:dnsop@ietf.org> <mailto:dnsop@ietf.org <mailto:dnsop@ietf.org>> > > To unsubscribe send an email to dnsop-leave@ietf.org <mailto:dnsop-leave@ietf.org> <mailto:dnsop-leave@ietf.org <mailto:dnsop-leave@ietf.org>> > > > > > > > > _______________________________________________ > > DNSOP mailing list -- dnsop@ietf.org <mailto:dnsop@ietf.org> > > To unsubscribe send an email to dnsop-leave@ietf.org <mailto:dnsop-leave@ietf.org> > > >
- [DNSOP] draft-ietf-dnsop-integration text on ASCI… Ben Schwartz
- [DNSOP] Re: draft-ietf-dnsop-integration text on … Andrew Sullivan
- [DNSOP] Re: draft-ietf-dnsop-integration text on … Kaizer, Andrew
- [DNSOP] Re: draft-ietf-dnsop-integration text on … Ben Schwartz
- [DNSOP] Re: draft-ietf-dnsop-integration text on … Kaizer, Andrew
- [DNSOP] Re: draft-ietf-dnsop-integration text on … Ben Schwartz
- [DNSOP] Re: draft-ietf-dnsop-integration text on … John Levine
- [DNSOP] Re: DNSOPdraft-ietf-dnsop-integration tex… Wes Hardaker