Handling of wildcard certificates (ACTION-519)

Hello,

during today's call, we realized that RFC 2818 seems underspecified in  
terms of what's permissible in wildcard certificates; Yngve told us  
that Opera only accepts the wildcard in the first label of a DNS name  
that appears in a certificate.

I.e., *.bar.com can match foo.bar.com, but foo.*.com wouldn't match  
foo.bar.com, in Opera.

How do Mozilla and Chrome and Konqueror behave?

Thanks,
-- 
Thomas Roessler, W3C   <tlr@w3.org>

Received on Wednesday, 24 September 2008 16:16:20 UTC