Missing TLD [xn--4dbrk0ce / .ישראל]

Why do we even need a "public suffix list"? Seems like a completely useless check to me. LE uses the challenges to check for domain control. That should be enough. A TLD that doesn't exist won't be in the DNS root zone.

Then you need to read a bit more on that.
It does serve a purpose.

4 Likes

The PSL is important for us for determining what wildcard certs can be issued. For example, *.example.com can be issued but *.co.uk cannot. If we don't know about the TLD, it's safest to simply figure that out -- new country-code TLDs are quite rare, and generic TLDs already automatically update in the PSL.

I've closed this thread as the original topic is resolved.

8 Likes