6 ms·
I am trying to parse what this means, can someone ELI5?
by BeefySwain 2y ago
I am trying to parse what this means, can someone ELI5?
- inopinatus 2y agoTLDR For years a combination of gaps in policy, disjointed standards development, hoarding behaviour, and administrative laxity, led to substantial wastage of IPv4 address space that persists to this day, in part because multiple independent website tenants sharing an IP address was (and often still is) difficult. Glossary DNS: Domain Name System, how computers discover (or resolve) each other's numeric IP addresses from symbolic hierarchical names. HTTP WG: HTTP Working Group, the standards committee(s) responsible for defining the application-layer protocols by which a web browser talks to a web server. Under the auspices of the IETF. IETF: Internet Engineering Task Force, the standards organization for the Internet. Most famous for being the entity that publishes TCP/IP and the cherries on top. LIR: Local Internet Registry, an entity that applies to be the holder of block-allocated IP address space. Typically ISPs and hosting companies that assign it for their use or onward customer use. RIPE: The European peak body, a Regional Internet Registry (RIR), responsible for (amongst many other things) allocating IP space to the LIRs, ultimately under license from the global steward IANA. Sibling of ARIN, LACNIC, AFRINIC, APNIC (North & South America, Africa, Asia-Pacific respectively). SNI: Server Name Identification. Before SNI was introduced to SSL/TLS, the only way to tell which HTTPS origin was being requested, was by server IP address. SRV: A specific type of record in the DNS that allows lookup of a service (e.g. IMAP mail, XMPP messaging, LDAP directories) for a given domain name, to return a set of hostname(s) that actually provide that service, and the ports on which it is available. This enables multi-tenant services on shared IP addresses and thereby conserves IP space. /19 network prefix: A large chunk of IPv4 address space, corresponding to 8192 unique IPv4 addresses. Refers to the first 19 bits of the block of (32 bit) IPv4 addresses being allocated. Back in the 90s a /19 was a common granularity of allocation from RIR to LIR and could be granted with a low bar to justification. Mathematically, 2^(32-19) = 8192. Address record: A specific type of record in the DNS that maps a hostname to an IP address. Technically referred to as an "A record" for IPv4 addresses, or an "AAAA" record for IPv6 addresses which are literally 4x the binary length. Allocation, Assignment, and Announcement: IP address space is allocated in blocks by RIRs to LIRs, who then assign smaller parcels of it to specific purposes such as retail hosting and internet access, and announce it at internet exchanges and to their peers for actual traffic exchange. Very often, the quantity of assignment failed to justify a large allocation, leaving space unassigned i.e. unused, and in some cases unannounced, but still hoarded, with incentives for hoarding becoming perversely stronger as the addresses ran out and the policy screws started to tighten ca.2005-2011. Apex: in "example.com" it is the "example.com" rather than "www.example.com". For marketing purposes, almost every entity wants their zone apex to be directly reachable as a website, which means placing an address record at the apex. This excludes using the apex address record for any other service but HTTP, which I have always regarded as downright antisocial. Since alias records (a.k.a CNAME records) aren't permitted at the apex, it also makes DNS management harder when you have frequent changes to make, as in the highly dynamic world of cloud-based services, or even just want to point your website at a third party hosting service without having to edit your zones whenever their IP addresses change. Normative: A formal declaration in one technical standard (e.g. SMTP) that it depends in whole or in part on another standard (e.g. DNS) for full specification. It is unusual for a TCP/IP-based IETF protocol standard to omit DNS as normative or otherwise specify how they use the DNS for discovery, but HTTP has always been super vague about it. Origin: Fancy word for your actual website. Or in the presence of complications like reverse proxies/load balancers/CDNs etc, the front of your service stack from the point of view of a web browser.
- metadat 2y agoThanks for this. It seems the parent comment put maximum acronyms with zero information for people who are on the same wavelength / plane of existence.
- inopinatus 2y agoguilty as charged
- pests 2y agoHa, seeing the list of jargon being defined was eye opening - I understood everything without a second glance but, like you I assume, I've been exposed to this world for 25+ years as this point and its second nature. I remember the first time I used "characters" in front of a non-technical friend instead of just the more common "letters" or literally anything else.
- inopinatus 2y ago"octets" is a good one, especially if you have musical friends
- JoshTriplett 2y agoI think "octets" is at this point historical jargon with little present value. It dates back to the day when some vendors were fighting for non-8-bit bytes. Those systems are long dead, and "byte" means "8 bits". Given that, I don't know of any context in which "octet" is an important distinction rather than an obfuscation.
- pests 2y agoStill makes a little sense as IPv4 addresses are 32 bytes and we break them down into 4 parts of 8 bits each. No one ever uses the 32 byte number, which will resolve.
- matt-p 2y agoThat it was historically "more difficult" to have more than one website per IP address particularly if it was using SSL because doing that needed amendments/extensions to DNS and other specs. We now have it, but still need to use a hack to cname an apex e.g set Google.com to bah-bahs-tenant100.s3.amazon.com. Adhering to the spec we need to set google.com to an ip address e.g 8.8.4.4
- bonzini 2y agoRight now if you want to retrieve http://www.example.com http://www.example.com, you have to ask DNS for the IP address of www.example.com. HTTP can multiplex multiple sites on a single IP address so you can make DNS answer with a "CNAME", i.e. let it give another hostname which could be from Cloudflare and will actually do the serving. However http://example.com http://example.com cannot use CNAME because it is an apex record (historical limitation that's hard to lift and is worked around in many different ways by providers). And this caused many websites to occupy an IP address unnecessarily. Likewise for HTTPS, though in that case multiplexing arrived only maybe 10-15 years ago instead of 25. A proposed Internet "standard" suggested that instead you would do a different kind of query, not a query for the IP address but one for a "server". It's a kind of query that is very underused on the Internet but it's related to how you find printers on a local network for example. In that case you would do this kind of query (called SRV) for http.tcp. example.com and that would always be able to return another hostname, thus getting rid of the issue with apex domains.
- teddyh 2y ago> In that case you would do this kind of query (called SRV) for http.tcp. example.com You’re forgetting the underscores: It’s actually “_http._tcp.example.com”. The underscores are there to avoid any possibility of collisions with host names, since host names are not allowed to contain underscores, but are generally allowed in the DNS.
- PinguTS 2y ago> However http://example.com http://example.com cannot use CNAME because it is an apex record [snip]. And this caused many websites to occupy an IP address unnecessarily. That's not true. I have an server with a single IP and a number of Domains that are served from that single IP like http(s)://example.com http(s)://example.org http(s)://example.de All of those delivery completely different websites from that single domain. You are mixing up two tings: DNS with HTTP(s). In DNS its right but for HTTP(s) it doesn't matter.
- billyjobob 2y agoOf course you can have multiple apex A records that point to the same IP address. We are talking about CNAME records here. Are your sites using CNAME records or A records? Even if you are using CNAMEs, that's only been possible recently due to hacks/workarounds, as bonzini said.
- hackernudes 2y agoDns A/AAAA record = IP address Dns SRV record = IP:port Not sure why SRV never really caught on for most internet stuff. (Edit: SRV records are hostnames, not IPs, so I guess it takes two lookups?)
- inopinatus 2y agoTo be precise, SRV records don't immediately return an IP address; they return canonical name(s) (i.e. FQDN of hosts) whose IP addresses can either be included in the additional part of the DNS reply or resolved separately. In addition to canonical name & port number they also include priority & weighting values, although the usefulness of these depends on the service. SRV might not be super visible in the application developer's lane, but swim outside and there's a lot of it about. It's foundational for SIP, for example (IP telephony). Email remains a tremendously significant internet utility and SRV is used, albeit not universally, for discovery of client endpoints (SMTP submission, IMAP, CalDAV etc). However, SRV hasn't replaced MX for SMTP between MTAs, perhaps because MX already does basically the same and was established years prior. And, well, Jabber is dead, but XMPP was another fully worked demonstration of SRV's capability. In more local environments SRV is used for resolution/discovery in Active Directory (Microsoft) and Bonjour (Apple) - if you listen to the wire on any local network you'll often see a ton of SRV over mDNS or DNS-SD. Perhaps ironically, one of the objections that sometimes arose to using SRV for HTTP was from Active Directory sites with zone cuts at _tcp.example.com and facing additional complexity in any transition.
- riobard 2y agoI never understand the reasoning behind the design decision that SRV cannot just return IP address and forcing clients to query again for A/AAAA again. That decision forces an extra RTT before connection can be established, which makes people want to avoid SRV records. Totally self-inflicted wounds.