const _tls_common = require('_tls_common');
const _tls_wrap = require('_tls_wrap');
const { createSecurePair } = require('internal/tls/secure-pair');
+const { domainToASCII } = require('internal/url');
+const { validateString } = require('internal/validators');
// Allow {CLIENT_RENEG_LIMIT} client-initiated session renegotiations
// every {CLIENT_RENEG_WINDOW} seconds. An error event is emitted if more
const ips = [];
hostname = '' + hostname;
+ const hostnameASCII = domainToASCII(hostname);
+
+ // Remove trailing dots for error messages and matching.
+ hostname = unfqdn(hostname);
+ const hostnameASCIIWithoutFQDN = unfqdn(hostnameASCII);
if (altNames) {
const splitAltNames = StringPrototypeIncludes(altNames, '"') ?
let valid = false;
let reason = 'Unknown reason';
- hostname = unfqdn(hostname); // Remove trailing dot for error messages.
-
- if (net.isIP(hostname)) {
- valid = ArrayPrototypeIncludes(ips, canonicalizeIP(hostname));
- if (!valid)
- reason = `IP: ${hostname} is not in the cert's list: ` +
- ArrayPrototypeJoin(ips, ', ');
+ if (net.isIP(hostnameASCIIWithoutFQDN)) {
+ valid = ArrayPrototypeIncludes(ips, canonicalizeIP(hostnameASCIIWithoutFQDN));
+ if (!valid) {
+ reason =
+ `IP: ${hostname} is not in the cert's list: ` + ips.join(', ');
+ }
} else if (dnsNames.length > 0 || subject?.CN) {
- const hostParts = splitHost(hostname);
+ const hostParts = splitHost(hostnameASCIIWithoutFQDN);
const wildcard = (pattern) => check(hostParts, pattern, true);
if (dnsNames.length > 0) {