<html xmlns="http://www.w3.org/1999/xhtml"><head></head><body><figure class="quote"><figcaption><p><anchor-end xmlns="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:anchor="1" xmlns:a0="urn:x-suika-fam-cx:markup:suikawiki:0:9:">[1]</anchor-end> <cite xml:lang="en">RFC 6125 - Representation and Verification of Domain-Based Application Service Identity within Internet Public Key Infrastructure Using X.509 (PKIX) Certificates in the Context of Transport Layer Security (TLS)</cite>
(<time>2015-03-13 22:27:53 +09:00</time> 版)
<anchor-external xmlns="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:resScheme="URI" xmlns:a0="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:resParameter="https://tools.ietf.org/html/rfc6125#section-1.8">https://tools.ietf.org/html/rfc6125#section-1.8</anchor-external></p></figcaption><blockquote><p>reference identifier:  An identifier, constructed from a source</p><p>domain and optionally an application service type, used by the</p><p>client for matching purposes when examining presented identifiers.</p></blockquote></figure><figure class="quote"><figcaption><p><anchor-end xmlns="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:anchor="2" xmlns:a0="urn:x-suika-fam-cx:markup:suikawiki:0:9:">[2]</anchor-end> <cite xml:lang="en">RFC 7525 - Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</cite>
(<time>2015-05-29 03:22:56 +09:00</time> 版)
<anchor-external xmlns="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:resScheme="URI" xmlns:a0="urn:x-suika-fam-cx:markup:suikawiki:0:9:" a0:resParameter="https://tools.ietf.org/html/rfc7525#section-6.1">https://tools.ietf.org/html/rfc7525#section-6.1</anchor-external></p></figcaption><blockquote><p>If the host name is discovered indirectly and in an insecure manner</p><p>(e.g., by an insecure DNS query for an MX or SRV record), it SHOULD</p><p>NOT be used as a reference identifier <strong>[</strong>RFC6125<strong>]</strong> even when it matches</p><p>the presented certificate.  This proviso does not apply if the host</p><p>name is discovered securely (for further discussion, see <strong>[</strong>DANE-SRV<strong>]</strong></p><p>and <strong>[</strong>DANE-SMTP<strong>]</strong>).</p></blockquote></figure></body></html>