Unicode Normalization Compliance Incident

Do Let's Encrypt use automated tools to detect invalid certificates?

For example, for that incident:

Certlint did detect that error:


ERROR: Internationalized domain names must be in unicode normalization form C

Boulder itself checks for many properties of an invalid certificate.

I think you can ascertain from that fact that we don’t run Certlint against our certificates presently. This is certainly something we’re considering as a take-away from yesterday’s IDNA incident.


