Gervase Markham gerv at mozilla.org
Mon Mar 21 11:59:52 UTC 2016

On 21/03/16 11:53, Rob Stradling wrote:
> On 21/03/16 11:39, Gervase Markham wrote:
> <snip>
>> Can someone give me a concrete example of why someone would want an _ in
>> a hostname in a cert? An all-Microsoft shop using it for an internal
>> name which nevertheless was an FQDN? my_server.corp.fooco.com?
> https://crt.sh/?cablint=62&minNotBefore=2016-01-01

That tells me that people _are_ doing it, but not why. My current
understanding is that this is an interoperability problem, in that it
works with one vendor's software and not with others, and that seems
like a good reason to discourage it, rather than allow it.


