# Internationalized Domain Names

**URL:** <https://community.letsencrypt.org/t/internationalized-domain-names/94>\
**Category:** Issuance Policy\
**Created:** [August 13, 2015, 8:19pm UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94 "2015-08-13T20:19:46Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Spambuster](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/spambuster/32/682_2.png) [@Spambuster](https://community.letsencrypt.org/u/Spambuster)\
**Post date:** [August 13, 2015, 8:19pm UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/1 "2015-08-13T20:19:46Z")

</div>

Is there going to be support for that?

---

<div class="post-metadata">

**Author:** ![riking](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/riking/32/92126_2.png) [@riking](https://community.letsencrypt.org/u/riking)\
**Post date:** [August 13, 2015, 8:53pm UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/2 "2015-08-13T20:53:02Z")

</div>

If anything, all the support you should need should be in the client, to automatically perform the punycode (xn–) transformation.

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [August 13, 2015, 9:31pm UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/3 "2015-08-13T21:31:44Z")

</div>

We’re still deciding whether we can include this for launch. The answer is probably no, because there are some tricky issues that need to be figured out, particularly with homoglyphs. We would like to support them eventually.

---

<div class="post-metadata">

**Author:** ![riking](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/riking/32/92126_2.png) [@riking](https://community.letsencrypt.org/u/riking)\
**Post date:** [August 13, 2015, 10:07pm UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/4 "2015-08-13T22:07:23Z")

</div>

Ah, but that would be a policy decision on the server side. At launch, you could return an error document saying “name not allowed” etc.

---

<div class="post-metadata">

**Author:** ![Spambuster](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/spambuster/32/682_2.png) [@Spambuster](https://community.letsencrypt.org/u/Spambuster)\
**Post date:** [August 14, 2015, 5:47am UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/5 "2015-08-14T05:47:45Z")

</div>

Only need support for the danish æøå letters 😄

---

<div class="post-metadata">

**Author:** ![idn](https://avatars.discourse-cdn.com/v4/letter/i/d6d6ee/32.png) [@idn](https://community.letsencrypt.org/u/idn)\
**Post date:** [August 17, 2015, 11:56pm UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/6 "2015-08-17T23:56:26Z")

</div>

I am also very interested in Internationalized Domain Names support.

Please add them as soon as possible ;).

---

<div class="post-metadata">

**Author:** ![Biker](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/biker/32/49_2.png) [@Biker](https://community.letsencrypt.org/u/Biker)\
**Post date:** [August 19, 2015, 7:30pm UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/7 "2015-08-19T19:30:04Z")

</div>

@Spambuster

Then, what about Swedish letters? And German letters? 🙂

I live in France, where we have another set of accented letters. You don’t need to go very far before the need increases almost logarithmic.

The world grew so much with the global adoption of the Internet. 😉

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [August 19, 2015, 11:50pm UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/8 "2015-08-19T23:50:43Z")

</div>

@Biker: I think @Spambuster was just joking around. 😉

---

<div class="post-metadata">

**Author:** ![Biker](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/biker/32/49_2.png) [@Biker](https://community.letsencrypt.org/u/Biker)\
**Post date:** [August 20, 2015, 7:22am UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/9 "2015-08-20T07:22:34Z")

</div>

That’s how I read his message as well. I’ve added a few smilies to indicate that I was in the same mood.

---

<div class="post-metadata">

**Author:** ![Spambuster](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/spambuster/32/682_2.png) [@Spambuster](https://community.letsencrypt.org/u/Spambuster)\
**Post date:** [August 21, 2015, 6:00pm UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/10 "2015-08-21T18:00:37Z")

</div>

They should get it too 😄

---

<div class="post-metadata">

**Author:** ![fernandosantucci](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/fernandosantucci/32/253_2.png) [@fernandosantucci](https://community.letsencrypt.org/u/fernandosantucci)\
**Post date:** [August 21, 2015, 6:24pm UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/11 "2015-08-21T18:24:16Z")

</div>

My brazilian domain haven’t accents, just [http://vitree.com.br](http://vitree.com.br) running with Node.js Angular.js [MEAN.io](http://MEAN.io) application.

It has support to TLS digital certificated?

If not, how long to be released?

---

<div class="post-metadata">

**Author:** ![NOYB](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/noyb/32/247_2.png) [@NOYB](https://community.letsencrypt.org/u/NOYB)\
**Post date:** [August 21, 2015, 6:33pm UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/12 "2015-08-21T18:33:27Z")

</div>

> [@fernandosantucci](#):
>
> My brazilian domain haven't accents, just [http://vitree.com.br](http://vitree.com.br)

That's not an internationalized domain name (IDN).

IDN: [Internationalized domain name - Wikipedia](https://en.wikipedia.org/wiki/Internationalized_domain_name)  
Punycode: [Punycode - Wikipedia](https://en.wikipedia.org/wiki/Punycode)

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [August 21, 2015, 6:51pm UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/13 "2015-08-21T18:51:38Z")

</div>

@fernandosantucci, as @NOYB says, that’s a different issue and not a problem for you. 😄

Aqui se fala dos nomes de domínio _internacionalizados_ (ou seja, com acentuação gráfica ou conjunto de caracteres não-ASCII), e não dos _internacionais_ (tais como .br).

---

<div class="post-metadata">

**Author:** ![Jeroen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jeroen/32/270_2.png) [@Jeroen](https://community.letsencrypt.org/u/Jeroen)\
**Post date:** [August 23, 2015, 12:44am UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/14 "2015-08-23T00:44:41Z")

</div>

I think thаt IDNs will not be implemented for а while, for obvious reаsons thаt you cаn eаsily present а domаin thаt looks like one а bank has аnd get а certificаte issued.

I аm quite confident thаt you hаven’t noticed that аll of my A’s in the previous аnd this sentence аre Cyrillic A’s.

Compаrison

- Common A: а
- Cyrillic A: а

  
  
  
  
  
  
  
  
  
  
  
  


Got you аgаin, this is a reаl compаrison between the common A аnd the Cyrillic A.  
Common: a  
Cyrillic: а

---

<div class="post-metadata">

**Author:** ![idn](https://avatars.discourse-cdn.com/v4/letter/i/d6d6ee/32.png) [@idn](https://community.letsencrypt.org/u/idn)\
**Post date:** [August 23, 2015, 4:33am UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/15 "2015-08-23T04:33:48Z")

</div>

By the way, what are the issues exactly? I can understand there can be issues with the client (inputing the '+e é instead of the native é). But if I input it in the xn–\* form (as I still have to do for most mail clients anyway…), it should look like just like a regular domain name to the CA.

---

<div class="post-metadata">

**Author:** ![roland](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/roland/32/33298_2.png) [@roland](https://community.letsencrypt.org/u/roland)\
**Post date:** [August 23, 2015, 5:19am UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/16 "2015-08-23T05:19:16Z")

</div>

As @jsha previously pointed out the main concern is homoglyphs, characters that visually look alike but have different code points. This basically means somebody might be able to create a domain name that looks exactly like a high-value domain name but if you did a string comparison between the two domains they wouldn’t match and could point to two different websites.

This means we could accidentally issue a certificate for a domain that looks like `google.com` even though that name is already part of a high-value anti-phishing blacklist.

(Wikipedia has a pretty good article on duplicate unicode characters, which are part of the concern, here – [https://en.wikipedia.org/wiki/Duplicate\_characters\_in\_Unicode](https://en.wikipedia.org/wiki/Duplicate_characters_in_Unicode))

---

<div class="post-metadata">

**Author:** ![Taubin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/taubin/32/297_2.png) [@Taubin](https://community.letsencrypt.org/u/Taubin)\
**Post date:** [September 1, 2015, 8:41am UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/17 "2015-09-01T08:41:38Z")

</div>

This is possibly a stupid question, but do the newer TLD’s such as .app .docs .beer etc fall under “international” domains as well? Or will the be supported at launch? I have a few domains that utilize some of the new TLDs that were introduced this year.

Sorry, I just saw the reply here [Do You Support Free Domains](https://community.letsencrypt.org/t/do-you-support-free-domains/249/3) stating they should be supported at launch.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [September 1, 2015, 8:13pm UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/18 "2015-09-01T20:13:18Z")

</div>

@Taubin, that’s right! There’s a distinction between _international_ domain names (fully supported) and _internationalized_ domain names (not currently supported). The international domain names are those under a foreign-based country-code top-level domain (like .de, .ru, .za, .uk) and the internationalized domain names are those that contain a non-ASCII character (like [παράδειγμα.com](http://xn--hxajbheg2az3al.com) or [例子.com](http://xn--fsqu00a.com)).

---

<div class="post-metadata">

**Author:** ![NOYB](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/noyb/32/247_2.png) [@NOYB](https://community.letsencrypt.org/u/NOYB)\
**Post date:** [September 1, 2015, 8:24pm UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/19 "2015-09-01T20:24:21Z")

</div>

@Taubin

Also a couple of good Wikipedia page links that may assist with clarifying the Internationalized Domain Names (IDN) distinction are provided earlier in this thread.

> [@Internationalized Domain Names](https://community.letsencrypt.org/t/internationalized-domain-names/94/12):
>
> …

---

<div class="post-metadata">

**Author:** ![eih](https://avatars.discourse-cdn.com/v4/letter/e/2bfe46/32.png) [@eih](https://community.letsencrypt.org/u/eih)\
**Post date:** [September 4, 2015, 10:20am UTC](https://community.letsencrypt.org/t/internationalized-domain-names/94/20 "2015-09-04T10:20:38Z")

</div>

What about internationalized domain names under sensible ccTLDs which do not allow homoglyphs?

Like it is not possible to register [аbc.de](http://xn--bc-6kc.de) or [аbc.fi](http://xn--bc-6kc.fi) ([аbc.de](http://xn--bc-6kc.de) or [аbc.fi](http://xn--bc-6kc.fi)) containing a Cyrillic a as these ccTLDs accept only a limited set of accented letters and such but not symbols, other scripts or anything like that.

For this kind of ccTLDs there are no need for extra homoglyph tests, as registry authorities have prevented them altogether.

[Next page](https://community.letsencrypt.org/t/internationalized-domain-names/94.md?page=2)
