8 ms·
I am the author, I wanted to publish it myself, I didn't expect you had already published it. Thank you very much. Encountered quite a few problems during the
by ccbikai 2y ago
I am the author, I wanted to publish it myself, I didn't expect you had already published it. Thank you very much.
Encountered quite a few problems during the deployment, mainly related to HTTPS certificates.
The longest segment of a domain name is 63 characters. The maximum length of an HTTPS certificate commonName is 64 characters.
This caused Cloudflare, Vercel, and Netlify to be unable to use Let's Encrypt to sign HTTPS certificates (because they used the domain name as the commonName), but Zeabur can use Let's Encrypt to sign HTTPS certificates.
Finally, the Cloudflare certificate was switched to Google Trust Services LLC to successfully sign.
Related certificates can be viewed at https://crt.sh/?q=loooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo.ong https://crt.sh/?q=looooooooooooooooooooooooooooooooooooooooo...
- csande17 2y agoDon't you have to be a Non-Government Organization, outside China[1], to be eligible for a .ong domain name? [1] According to https://www.godaddy.com/help/about-ong-domains-41384 https://www.godaddy.com/help/about-ong-domains-41384
- toast0 2y agoAre you accusing them of being a government organzation, or accusing them of being in China?
- ehPReth 2y agoNGO is a specific type of organization (such as a 501(c)(3) in the US), which would exclude 'a random person registering a domain': https://en.wikipedia.org/wiki/Non-governmental_organization https://en.wikipedia.org/wiki/Non-governmental_organization
- bux93 2y agoThat wikipedia article literally says there is "no fixed or formal definition for what NGOs are". The .ong domain has a policy that has criteria. https://thenew.org/org-people/about-pir/policies/ngo-and-ong-registration-policy/ https://thenew.org/org-people/about-pir/policies/ngo-and-ong... These are not hard to meet, nor should they be.
- SamBam 2y ago> These are not hard to meet, nor should they be. But hard for a random url-elongator site to meet. > Registrants are required to certify that they meet the following eligibility requirements when registering a .NGO or .ONG domain name: > 1. Focused on acting in the public interest. [...] work for the good of humankind and/or the preservation of the planet > 5. Active Organizations. Members of the .NGO and .ONG community are actively pursuing their missions on a regular basis. > 6. Structured. Members of the .NGO and .ONG community, whether large or small, operate in a structured manner (e.g., under bylaws, codes of conduct, organizational standards, or other governance structures.) Clearly this site doesn't qualify.
- toast0 2y ago> 1. Focused on acting in the public interest. [...] work for the good of humankind and/or the preservation of the planet Operating a publicly available lengthening service is in the public interest and is working for the good of all humans. I used to use hugeurl, but it's no longer in service. > 5. Active Organizations. Members of the .NGO and .ONG community are actively pursuing their missions on a regular basis. This is an active organization, pursing a mission of longer urls for the good of all. Maybe this sounds frivolous, but there's a lot of frivolous but chartered 501(c)(3)s, and the requirements doesn't specifically require a registrant to be registered as a non-profit or charity or similar (although such a registration is likely to satisfy an audit, tax records showing a lack of profits/retained earnings may be sufficient) > 6. Structured. Members of the .NGO and .ONG community, whether large or small, operate in a structured manner (e.g., under bylaws, codes of conduct, organizational standards, or other governance structures.) We don't have evidence of how it's operated. Many organizations operate websites without publishing their bylaws. Although, I'll grant that circumstantial evidence seems to be that it's operated by an individual.
- bux93 2y agoYou can't see from the site who the owner is. Could be a library. Could be a music club. Could be the Gates foundation. An art collective. Running the website (in this case, an url elongator) is not required to be an objective in the articles of incorporation. Nevertheless, an URL elongator strikes me as funny, and providing fun for free is surely for the good of humankind.
- Dalewyn 2y agoThe author's X account[1] and associated posts are decidedly Chinese, so it's a valid inquiry. [1]: https://x.com/ccbikai https://x.com/ccbikai
- logrot 2y agohttps://loooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo.ong/loooooooooOOoOooooooooooooOOOoOoooooooooooOOOoOoooooooooooOOOoooooooooooooOOOooOOooooooooooOOOoOoooooooooooOoOOOOooooooooooOoOOOOoooooooooOOooOoOoooooooooOOoOOOoooooooooooOoOOOooooooooooOOoOOoOooooooooooOoOOOooooooooooOOOoOOOoooooooooOOoOooOoooooooooOOoOoOOoooooooooOOoOooOoooooooooOOOoooooooooooooOOooOoOoooooooooOOooOoooooooooooOOoOooOoooooooooOOooooOooooooooooOoOOOooooooooooOOoOOOOoooooooooOOOooOooooooooooOOooOOOooooooooooOoOOOOoooooooooOOOoOOOoooooooooOOoOooOoooooooooOOoOoOOoooooooooOOoOooOooooooooooOoOOOOooooooooooOOoooOooooooooooOOOooOooooooooooOOOoooooooooooooOOOooOoooooooooOoOOOOOoooooooooOoOoOoooooooooooOOoOooOoooooooooOOooooOoooooooooOOoOOOooooooooooOOooooOoooooooooOOoOOOooooooooooOOoOOoOoooooooooOOooOoOoooooooooOOoOOOooooooooooOoOOOOOoooooooooOoOooOOoooooooooOOOoooOoooooooooOOOoOoOoooooooooOOooooOoooooooooOOOooOooooooooooOOooOoOoooooooooOoOOOOOoooooooooOOOoooooooooooooOOOooOooooooooooOOoOOOOoooooooooOOOoOoooooooooooOOooOoOoooooooooOOOooOOoooooooooOOOoOoooooooooooOOOooOOoooooooooOoOOOOOoooooooooOOooooOoooooooooOOoOOOooooooooooOOooOoooooooooooOoOOOOOoooooooooOOoOOoOoooooooooOOooooOoooooooooOOOooOOoooooooooOOOooOOoooooooooOOooooOoooooooooOOoooOOoooooooooOOOooOooooooooooOOooOoOng https://looooooooooooooooooooooooooooooooooooooooooooooooooo...
- csande17 2y agoThe GitHub repo linked from the page is owned by an individual (not any kind of structured NGO that would be eligible for this), and they set the location field on their GitHub profile to "NanJing,China" (suggesting that they are located in China).
- maxhax 2y agoSo happy your reply made me realize that you can purchase longd.ong as a website. https://www.godaddy.com/domainsearch/find?checkAvail=1&tmskey=&key=dpp_leaf_ong&domainToCheck=longd&tld=.ong https://www.godaddy.com/domainsearch/find?checkAvail=1&tmske...
- shawabawa3 2y agoJust to expand on this, commonName is not at all required in certificates and is basically deprecated/legacy Letsencrypt does not require you to set it, just subject alternate names, which can be up to 255 characters, but some providers require it for no reason
- semi 2y agosurprisingly it's been deprecated since RFC 2818 was published 24 years ago. It's only more recently that browsers and other common software stopped validating it though
- throw0101c 2y agoIf a subjectAltName extension of type dNSName is present, that MUST be used as the identity. Otherwise, the (most specific) Common Name field in the Subject field of the certificate MUST be used. Although the use of the Common Name is existing practice, it is deprecated and Certification Authorities are encouraged to use the dNSName instead. * https://datatracker.ietf.org/doc/html/rfc2818#section-3.1 https://datatracker.ietf.org/doc/html/rfc2818#section-3.1 Therefore, if and only if the presented identifiers do not include a DNS-ID, SRV-ID, URI-ID, or any application-specific identifier types supported by the client, then the client MAY as a last resort check for a string whose form matches that of a fully qualified DNS domain name in a Common Name field of the subject field (i.e., a CN-ID). If the client chooses to compare a reference identifier of type CN-ID against that string, it MUST follow the comparison rules for the DNS domain name portion of an identifier of type DNS-ID, SRV-ID, or URI-ID, as described under Section 6.4.1, Section 6.4.2, and Section 6.4.3. * https://www.rfc-editor.org/rfc/rfc6125#section-6.4.4 https://www.rfc-editor.org/rfc/rfc6125#section-6.4.4 Also from 2015: 9.2.2 Subject Distinguished Name Fields a. Subject Common Name Field Certificate Field: subject:commonName (OID 2.5.4.3) Required/Optional: Deprecated (Discouraged, but not prohibited) Contents: If present, this field MUST contain a single IP address or Fully-Qualified Domain Name that is one of the values contained in the Certificate’s subjectAltName extension (see Section 9.2.1). * https://cabforum.org/wp-content/uploads/BRv1.2.5.pdf#page=17 https://cabforum.org/wp-content/uploads/BRv1.2.5.pdf#page=17 * https://stackoverflow.com/questions/5935369/how-do-common-names-cn-and-subject-alternative-names-san-work-together https://stackoverflow.com/questions/5935369/how-do-common-na...
- mcpherrinm 2y agoLet’s Encrypt now (as of 2023) supports having certificates with no CN now, so long domains are fully supported: https://community.letsencrypt.org/t/simplifying-issuance-for-very-long-domain-names/207924 https://community.letsencrypt.org/t/simplifying-issuance-for... The previous workaround available was to include a second, shorter domain on the certificate but that wasn’t always easy or possible.
- Dr_Birdbrain 2y agoCan you help me understand what is the point of this project? :)
- micw 2y agoAmazing. Will you provide email services? ^^
- pragma_x 2y agoI love this. My first impression was: "What in the QA is this? I wonder what this breaks?" > because they used the domain name as the commonName Understandable, but that's old-school, right? I'm pretty sure the x.509 extensions for SAN cover this now, and I'm kind of surprised that CA's are sticking to the old way of doing this.