normalize trailing-dot DNS names before name-constraint matching
Fixed in: Java 1.85 and C# 2.7.0
details
- Finding IDs
- F-BC-NC-TRAILINGDOT-001
- Status
- fixed publicly
- Fixed in
- Java 1.85 and C# 2.7.0
- Reported via
- security contact
- Note
- A terminal DNS root-label dot could make an otherwise matching certificate DNS name miss an excluded name constraint. The Java change of 13 May 2026 normalizes one trailing dot on both the tested DNS name and constraint before exact and subtree comparison. Java 1.85 contains this check; C# 2.7.0 applies corresponding normalization in NameConstraintDns. This replaces the previous main-only, release-unconfirmed status. The record covers the original DNS comparison issue, not every email or URI normalization change in the same release; no CVE is borrowed from an adjacent fix. This is source/version confirmation, not a new certificate-chain retest.
F-BC-NC-TRAILINGDOT-001: Verification failures. Trailing-dot DNS normalization is inconsistent with name-constraint enforcement. Reviewed 26 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-BC-NC-TRAILINGDOT-001
Security area (1seal assessment): Identity. DNS name-constraint comparison normalizes the root-label trailing dot before matching certificate identities. Reviewed 26 Sep 2026.