> Due to compability with older versions, only IDNA domains should be
> checked
> Patch attached.

I'm not particularly happy about the u'\xdf' special case. Isn't there a
better way to do this check?
I cant find better way. u'\xdf' is mapped to ss, and ss is not IDN

Or just remove this validation.

(BTW I really think this should be a warning, not an error, but that
would require larger amount of work, so I guess it's OK for now.)
(More pain than gain)
Main thing in this patch is that the check should not be done against
non-IDN strings. I want this version of the patch to go in for that
reason as currently you cannot even complete ipa-adtrust-install run due
to IDN normalisation check being applied to non-IDN domains.

On non-IDN domains, the only effect of IDN normalization is that it lower-cases the names (right?), so the check should compare lower-cased original name with the normalized name, instead of special-casing certain characters etc.

