5 ms·
> Technically speaking, adding a period at the end of a URL is valid in that it implicitly exists for all URLs in the context of DNS. I think your are confusin
by nanis 5y ago
> Technically speaking, adding a period at the end of a URL is valid in that it implicitly exists for all URLs in the context of DNS.
I think your are confusing the role of a trailing dot in the DNS[1] system with the role of a host element in a URI[2].
So, technically speaking, adding a period at the end of a URL is really not OK because `https://example.com/index.html https://example.com/index.html` and `https://example.com/index.html https://example.com/index.html.` are different resources. (note that HN's URL linking logic omits the trailing dot.)
I can understand if you think there should be no difference between `https://example.com/ https://example.com/` and `https://example.com./ https://example.com./` and that is legitimate per the RFC:
> The rightmost domain label of a fully qualified domain name in DNS may be followed by a single "." and should be if it is necessary to distinguish between the complete domain name and some local domain.
but there is no reason to expect that adding a period at the end of any old URI is going to work.
[1]: https://serverfault.com/a/18122 https://serverfault.com/a/18122
[2]: https://datatracker.ietf.org/doc/html/rfc3986#section-3.2.2 https://datatracker.ietf.org/doc/html/rfc3986#section-3.2.2
- tialaramex 5y agoAlthough it is valid in DNS, it is not valid in the TLS SNI. If you tell the remote server you wanted some.name.example. with that extra dot at the end that's an error and it should tell you to go away. All the names in SNI should be real names and not some locally qualified name, the alternative would be confusing because these are identities and so it doesn't mean anything to have proof you're really "testserver4" we want to know whether you're really "testserver4.mycorp.example" or not.
- DHowett 5y agoThis seems exactly backwards, though. “testserver4.mycorp.example” (no trailing dot) is not fully-qualified and as such could refer to any number of things of differing identities, e.g. “testserver4.mycorp.example.atthomenetwork.com”. On the other hand, “testserver4.mycorp.example.” (trailing dot) is fully-qualified and is not an ambiguous identity.
- tialaramex 5y agoRight, so under your approach they need to add a dot, every single time. This wastes a byte during the handshake, in order to transport the dot which you've decided must be there. Whereas the approach they actually shipped does not waste that byte. If it makes you more comfortable pretend it's an amazing "compression scheme" where they omit that extra byte with a dot in it to save space. See also IEEE 754 floating point where that first 1 in your binary floating point number is omitted entirely because it's implied and so writing it into the 32-bit value anyway would waste an entire order of magnitude.
- foxfluff 5y ago> “testserver4.mycorp.example” (no trailing dot) is not fully-qualified and as such could refer to any number of things of differing identities, e.g. “testserver4.mycorp.example.atthomenetwork.com”. Whether a domain is fully qualified depends on the application. There's no universal syntax. The trailing dot is merely an interface convention followed by some applications to allow the user to indicate that the domain name is complete. It's only useful for applications that don't always deal with fully qualified domains, and perhaps ones that deal with top level domains. RFC1123 6.1.4.3 Interface Abbreviation Facilities: User interfaces MAY provide a method for users to enter abbreviations for commonly-used names. [..] If an abbreviation method is provided, then: (a) There MUST be some convention for denoting that a name is already complete, so that the abbreviation method(s) are suppressed. A trailing dot is the usual method. If you add trailing dots where the dns root would be implied anyway, this could be regarded as an "over-qualified" name. It is considered an error. For example in SMTP. RFC1123 5.2.18 Common Address Formatting Errors: o Some systems over-qualify domain names by adding a trailing dot to some or all domain names in addresses or message-ids. This violates RFC-822 syntax. RFC822 says "The root node is common to all addresses; consequently, it is not referenced." Since SNI always uses fully qualified domain names, there is no purpose to having a trailing dot.
- acchow 5y agoParent comment meant `https://example.com./index.html https://example.com./index.html` instead of your `https://example.com/index.html https://example.com/index.html.` And naturally in your citation you could use `https://serverfault.com./a/18122 https://serverfault.com./a/18122` which works perfectly fine
- nanis 5y agoThe comment to which I was replying said "the end of the URL". Adding the period at the end of the domain name is not the same as adding it at the end of the URL. I responded to what was actually said.