# IDN domain problem

**URL:** <https://community.letsencrypt.org/t/idn-domain-problem/217093>\
**Category:** Help\
**Created:** [April 24, 2024, 10:57am UTC](https://community.letsencrypt.org/t/idn-domain-problem/217093 "2024-04-24T10:57:30Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![oneman](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/oneman/32/79333_2.png) [@oneman](https://community.letsencrypt.org/u/oneman)\
**Post date:** [April 24, 2024, 10:57am UTC](https://community.letsencrypt.org/t/idn-domain-problem/217093/1 "2024-04-24T10:57:30Z")

</div>

I have have had enough and I am not going to take it anymore! Look I have used letsencypt 26 times exactly according to my logbook since the great awarness that if you don't encrpyt then you can't even hope to tell you have been pwned. Every single time I used it, it eventually worked but it was always a new way to have to fiddle in the middle, ANYway this is the current fail. Situation involves use of a IDN specifically a カ\*sカ.tokyo domain. The fail is a something something punycode and go beg for help so I have now done that. I am fixable.

> <https://gist.github.com/oneman/786d45dbda8510f3bc5b6b0486cc9548>

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [April 24, 2024, 11:39am UTC](https://community.letsencrypt.org/t/idn-domain-problem/217093/2 "2024-04-24T11:39:18Z")

</div>

The error is quite clear I'd say?:

> Non-ASCII domain names not supported. To issue for an Internationalized Domain Name, use Punycode.

Punycode was not used in this log:

> 2024-04-24 10:11:12,490:DEBUG:certbot.\_internal.main:Arguments: ['-v', '-d', 'サイバー.tokyo']

Have you tried `xn--eck7a4e3h.tokyo` as the hostname? (I used [Punycode Converter - IDN Converter - Punycode to Unicode](https://dnschecker.org/idn-punycode-converter.php) for the conversion.)

Also, while probably (hopefully) your thread title was meant to be comically, I've edited it to something which makes more sense to the readers..

---

<div class="post-metadata">

**Author:** ![rmbolger](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rmbolger/32/27474_2.png) [@rmbolger](https://community.letsencrypt.org/u/rmbolger)\
**Post date:** [April 24, 2024, 3:22pm UTC](https://community.letsencrypt.org/t/idn-domain-problem/217093/3 "2024-04-24T15:22:42Z")

</div>

> [@oneman](#):
>
> if you don't encrpyt then you can't even hope to tell you have been pwned

Not to sidetrack, but certificates on a website do absolutely nothing to prevent a site from being compromised. Vulnerabilities exist in application code whether there is a cert encrypting the traffic to it or not.

Similarly, most malicious sites use valid certificates. But the certificate has no impact regarding whether the site can compromise clients connecting to them.

---

<div class="post-metadata">

**Author:** ![jvanasco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jvanasco/32/55900_2.png) [@jvanasco](https://community.letsencrypt.org/u/jvanasco)\
**Post date:** [April 24, 2024, 4:05pm UTC](https://community.letsencrypt.org/t/idn-domain-problem/217093/4 "2024-04-24T16:05:44Z")

</div>

> [@Osiris](#):
>
> Have you tried `xn--eck7a4e3h.tokyo` as the hostname?

Just for background...

[Internationalized Domain Names](https://en.wikipedia.org/wiki/Internationalized_domain_name) use a form of [Punycode](https://en.wikipedia.org/wiki/Punycode) in which the prefix `xn--` is prepended to the punycode encoded domain name.

Browsers and many code libraries will use the punycode ascii-encoding under the hood, while they display the internationalized unicode on most visible interfaces.

@oneman you should familiarize yourself with punycode conversion for troubleshooting and maintenance. You don't need to learn the algorithms, you just need to get comfortable with the online converters that encode and decode.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [April 25, 2024, 1:58am UTC](https://community.letsencrypt.org/t/idn-domain-problem/217093/5 "2024-04-25T01:58:47Z")

</div>

> [@rmbolger](#):
>
> Not to sidetrack, but certificates on a website do absolutely nothing to prevent a site from being compromised. Vulnerabilities exist in application code whether there is a cert encrypting the traffic to it or not.

"You have been pwned" could be used more broadly in this case, to include network attacks that HTTPS _does_ protect against. I find it kind of ambiguous between the two!

---

<div class="post-metadata">

**Author:** ![oneman](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/oneman/32/79333_2.png) [@oneman](https://community.letsencrypt.org/u/oneman)\
**Post date:** [April 25, 2024, 2:23am UTC](https://community.letsencrypt.org/t/idn-domain-problem/217093/6 "2024-04-25T02:23:02Z")

</div>

We are all pwned as a matter of fact EFI recall intel correctly. None the less, lets settle this one, I am lazy and ignorant and I have been told to begin my education at a word I can type into google or pedia. I will deal with this personal matter off the air. When I get a proper clue, I will provide a report on my learnings. Thank you for your kind gentle machine gun hands.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [May 25, 2024, 2:23am UTC](https://community.letsencrypt.org/t/idn-domain-problem/217093/7 "2024-05-25T02:23:13Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
