[1] [CITE@en[RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile]]
([TIME[2015-02-22 15:44:10 +09:00]] 版)
<http://tools.ietf.org/html/rfc5280#section-4>

[FIG(quote)[
[FIGCAPTION[
[2] [CITE@en[RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile]]
([TIME[2015-02-22 15:44:10 +09:00]] 版)
<http://tools.ietf.org/html/rfc5280#section-4.1.2.4>
]FIGCAPTION]

>  In addition, implementations of this specification MUST be prepared
>    to receive the domainComponent attribute, as defined in '''['''RFC4519''']'''.
>    The Domain Name System (DNS) provides a hierarchical resource
>    labeling system.  This attribute provides a convenient mechanism for
>    organizations that wish to use DNs that parallel their DNS names.
>    This is not a replacement for the dNSName component of the
>    alternative name extensions.  Implementations are not required to
>    convert such names into DNS names.  The syntax and associated OID for
>    this attribute type are provided in the ASN.1 modules in Appendix A.
>    Rules for encoding internationalized domain names for use with the
>    domainComponent attribute type are specified in Section 7.3.

]FIG]


[FIG(quote)[
[FIGCAPTION[
[3] [CITE@en[RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile]]
([TIME[2015-02-22 15:44:10 +09:00]] 版)
<http://tools.ietf.org/html/rfc5280#section-4.2.1.6>
]FIGCAPTION]

> a DNS name MAY also be
>    represented in the subject field using the domainComponent attribute
>    as described in Section 4.1.2.4.  Note that where such names are
>    represented in the subject field implementations are not required to
>    convert them into DNS names.

]FIG]


[FIG(quote)[
[FIGCAPTION[
[4] [CITE@en[RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile]]
([TIME[2015-02-22 15:44:10 +09:00]] 版)
<http://tools.ietf.org/html/rfc5280#section-7.1>
]FIGCAPTION]

> 
>    Comparisons of domainComponent attributes MUST be performed as
>    specified in Section 7.3.

]FIG]


[FIG(quote)[
[FIGCAPTION[
[5] [CITE@en[RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile]]
([TIME[2015-02-22 15:44:10 +09:00]] 版)
<http://tools.ietf.org/html/rfc5280#section-7.3>
]FIGCAPTION]

> Each domainComponent attribute represents a
>    single label.  To represent a label from an IDN in the distinguished
>    name, the implementation MUST perform the "ToASCII" label conversion
>    specified in Section 4.1 of RFC 3490.  The label SHALL be considered
>    a "stored string".  That is, the AllowUnassigned flag SHALL NOT be
>    set.
>    Conforming implementations shall perform a case-insensitive exact
>    match when comparing domainComponent attributes in distinguished
>    names, as described in Section 7.2.
>    Implementations should convert ACE labels to Unicode before display.
>    Specifically, conforming implementations should perform the
>    "ToUnicode" conversion operation specified, as described in Section
>    7.2, on each ACE label before displaying the name.

]FIG]


[6] [CITE@en[RFC 4519 - Lightweight Directory Access Protocol (LDAP): Schema for User Applications]]
([TIME[2015-01-04 15:23:19 +09:00]] 版)
<http://tools.ietf.org/html/rfc4519#section-2.4>

[7] [CITE@en[RFC 6818 - Updates to the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile]]
([TIME[2015-03-24 03:47:50 +09:00]] 版)
<https://tools.ietf.org/html/rfc6818#section-5>