# IDN Support enabled

**URL:** <https://community.letsencrypt.org/t/idn-support-enabled/21469>\
**Category:** Issuance Policy\
**Created:** [October 20, 2016, 10:30pm UTC](https://community.letsencrypt.org/t/idn-support-enabled/21469 "2016-10-20T22:30:12Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [October 20, 2016, 10:30pm UTC](https://community.letsencrypt.org/t/idn-support-enabled/21469/1 "2016-10-20T22:30:12Z")

</div>

I’m pleased to announce that Let’s Encrypt now supports issuance for [Internationalized Domain Names](https://tools.ietf.org/html/rfc5890) (IDNs).

Note that the currently-released Certbot version (0.9.2) has a built-in check that prevents issuance for IDNs. To issue certificates with Certbot that contain IDNs, you can follow the [developer instructions](http://letsencrypt.readthedocs.io/en/latest/contributing.html#running-a-local-copy-of-the-client) to install the latest development version. Or you can wait for the next Certbot release, currently planned for end of October / early November, or use an [alternate client](https://letsencrypt.org/docs/client-options/).

Let’s Encrypt (and the ACME protocol) accept IDNs only as A-labels (ASCII labels, starting with `xn--`, also known as Punycode), not as U-labels (Unicode labels). You can convert between U-labels and A-labels using [https://github.com/bestiejs/punycode.js/](https://github.com/bestiejs/punycode.js/) or [https://www.punycoder.com/](https://www.punycoder.com/). Note that [https://www.punycoder.com/](https://www.punycoder.com/) supports the older IDNA the older IDNA2003 spec, while Boulder implements the newer IDNA2008 spec, and so may reject some names converted by that site.

Also note that registries impose some limits on what IDNs may be registered, and browsers impose additional constraints on which IDNs will be represented in their U-label form. If you are thinking of purchasing a domain name, you should ensure it will render the way you want on the browsers that you care about.

---

<div class="post-metadata">

**Author:** ![mrtux](https://avatars.discourse-cdn.com/v4/letter/m/9de0a6/32.png) [@mrtux](https://community.letsencrypt.org/u/mrtux)\
**Post date:** [October 21, 2016, 12:25am UTC](https://community.letsencrypt.org/t/idn-support-enabled/21469/2 "2016-10-21T00:25:09Z")

</div>

Thanks!!! Works like a charm for me!

It’s great that it was enabled before the deadline!

---

<div class="post-metadata">

**Author:** ![r0uzic](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/r0uzic/32/9170_2.png) [@r0uzic](https://community.letsencrypt.org/u/r0uzic)\
**Post date:** [October 22, 2016, 2:10am UTC](https://community.letsencrypt.org/t/idn-support-enabled/21469/3 "2016-10-22T02:10:09Z")

</div>

When it will be possible to use it? I upgrade let’s encrypt repo and still can’t use it :-/

---

<div class="post-metadata">

**Author:** ![pfg](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/pfg/32/1924_2.png) [@pfg](https://community.letsencrypt.org/u/pfg)\
**Post date:** [October 22, 2016, 2:21am UTC](https://community.letsencrypt.org/t/idn-support-enabled/21469/4 "2016-10-22T02:21:04Z")

</div>

The CA servers are already issuing IDN certificates. As for clients, if you’re using `certbot`, you’ll need to switch to a development version as described [here](http://letsencrypt.readthedocs.io/en/latest/contributing.html#running-a-local-copy-of-the-client). Note that this is _not_ the same thing as just running `git pull` for your local clone - that’ll still give you the released version of `certbot`, which does not support IDNs yet. Using one of the [alternative clients](https://letsencrypt.org/docs/client-options/) might work too (not sure which of them support IDNs already).

---

<div class="post-metadata">

**Author:** ![wangqiliang](https://avatars.discourse-cdn.com/v4/letter/w/c5a1d2/32.png) [@wangqiliang](https://community.letsencrypt.org/u/wangqiliang)\
**Post date:** [October 22, 2016, 7:13am UTC](https://community.letsencrypt.org/t/idn-support-enabled/21469/5 "2016-10-22T07:13:36Z")

</div>

> [@Chinese IDN Issurance Requests Malformed?](https://community.letsencrypt.org/t/chinese-idn-issurance-requests-malformed/21528/2):
>
> a…

---

<div class="post-metadata">

**Author:** ![Neilpang](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/neilpang/32/20232_2.png) [@Neilpang](https://community.letsencrypt.org/u/Neilpang)\
**Post date:** [October 23, 2016, 6:59am UTC](https://community.letsencrypt.org/t/idn-support-enabled/21469/6 "2016-10-23T06:59:41Z")

</div>

[acme.sh](http://acme.sh) supports IDN now.

> <https://github.com/Neilpang/acme.sh/issues/331>

---

<div class="post-metadata">

**Author:** ![Ascendor](https://avatars.discourse-cdn.com/v4/letter/a/a9adbd/32.png) [@Ascendor](https://community.letsencrypt.org/u/Ascendor)\
**Post date:** [October 31, 2016, 9:47pm UTC](https://community.letsencrypt.org/t/idn-support-enabled/21469/7 "2016-10-31T21:47:46Z")

</div>

I tested “getssl” today and it worked fine using the PunyCode version of my IDN domain.

---

<div class="post-metadata">

**Author:** ![Bloof](https://avatars.discourse-cdn.com/v4/letter/b/3e96dc/32.png) [@Bloof](https://community.letsencrypt.org/u/Bloof)\
**Post date:** [November 6, 2016, 9:16pm UTC](https://community.letsencrypt.org/t/idn-support-enabled/21469/8 "2016-11-06T21:16:57Z")

</div>

IDN support looks good, but when I try to acquire certificate for my domain “[блуф.рф](http://xn--90auye.xn--p1ai)” (using [acme.sh](http://acme.sh) or gethttpsforfree clients), I receive API error 400: “Name does not end in a public suffix”. Suffix “.рф” is presented here [https://publicsuffix.org/list/effective\_tld\_names.dat](https://publicsuffix.org/list/effective_tld_names.dat). What did I do wrong?

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [November 6, 2016, 9:22pm UTC](https://community.letsencrypt.org/t/idn-support-enabled/21469/9 "2016-11-06T21:22:20Z")

</div>

This is a bug in Boulder: [https://github.com/letsencrypt/boulder/issues/2277](https://github.com/letsencrypt/boulder/issues/2277). We’re working on it! Thanks for your patience.

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [November 22, 2016, 9:35pm UTC](https://community.letsencrypt.org/t/idn-support-enabled/21469/10 "2016-11-22T21:35:39Z")

</div>

A post was split to a new topic: [Certbot reporting Punycode unsupported](https://community.letsencrypt.org/t/certbot-reporting-punycode-unsupported/23012)

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [December 9, 2016, 1:13am UTC](https://community.letsencrypt.org/t/idn-support-enabled/21469/11 "2016-12-09T01:13:43Z")

</div>

The fix to that bug was rolled out today; I’m just following up on each thread that mentions it to let the people who encountered it know that they can now go ahead with issuing their certs. So, @Bloof, you can go ahead and get your certificate for [блуф.рф](http://xn--90auye.xn--p1ai) now!

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [January 8, 2017, 1:14am UTC](https://community.letsencrypt.org/t/idn-support-enabled/21469/12 "2017-01-08T01:14:06Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
