12 ms·
Special-use domain 'home.arpa.' (2018)
- Y_Y 2y agohttps://home.arpa https://home.arpa
- qwertox 2y agoDNS_PROBE_FINISHED_NXDOMAIN. Is it different at your end or why are you posting this?
- egberts1 2y agoBecause, it is the INTERNET! (cough cough) Seriously, I run ARPA-NET in my home.internet, as well as IPX (Bayans VINES) and Frame Relay/X.25. Yeah, it's what I do. Also encrypted MAC-layers too. Now the real kicker is maintaining DNSSEC for my home.internet. A real exercise in extremity (but not futility yet it is doable)
- thot_experiment 2y agoI just use home.com for all my home automation stuff, it's a lot easier to explain to houseguests than home.home.arpa would be.
- qwertox 2y agoThe issue with this is that you can't create certificates this way. Assume you own example.com, then you can issue a free certificate for *.example.com and use that certificate for all your home services. Using HTTPS in the intranet does have its benefits and eases coding when services require SSL. If you host vaultwarden.example.com in your intranet, then you don't have to publish the subdomain on a public nameserver; it's enough that your intranet DNS resolver can respond with the local A or AAA record for vaultwarden.example.com and it's covered by the wildcard certificate.
- codetrotter 2y ago> you can't create certificates this way Sure I can. It's my network, so I decide what root CAs are trusted. Be your own CA, and tell your computers to trust your own CA cert. For example: https://smallstep.com/blog/build-a-tiny-ca-with-raspberry-pi-yubikey/ https://smallstep.com/blog/build-a-tiny-ca-with-raspberry-pi... or https://github.com/jsha/minica https://github.com/jsha/minica
- lytedev 2y agoPer GP, this will be VERY difficult to explain to houseguests.
- codetrotter 2y agoWhy? Specifically, what I mean is, if you have house guests that care enough about your LAN that they actually want to access any of the services you have running on it – it shouldn't be difficult to explain to them why and how to trust your CA. The main difficulty IME is getting any of your guests to care about your LAN services in the first place.
- 0x457 2y agoI'm sorry, but if you ask me to install your private CA on any of my devices... I would politely tell you to stop. As for house guests, I really like what OnHub did - you could allow anyone to network to control certain IoT devices. When someone was house sitting for me, they could have control thermostat, lights, etc from their phone without any apps or "add household member" shenanigans.
- thot_experiment 2y agoThat's what I do, I just hijack home.com to do it and don't care about SSL on my intranet.
- codetrotter 2y ago
- paulddraper 2y agoBut you have to explain the insecure connections?
- thot_experiment 2y agoWhy would they care? There's no reason to serve my home automation stuff over https.
- paulddraper 2y agoNor is there a reason to use a commercial domain. But here we are.
- thot_experiment 2y agoHuh? home.com is a really simple easy to remember domain, that's a good reason isn't it?
- pwg 2y agoAnd "home.com" is owned by someone, and registered through GoDaddy: Domain Name: HOME.COM Registry Domain ID: 1668509_DOMAIN_COM-VRSN Registrar WHOIS Server: whois.brandsight.com Registrar URL: http://gcd.com Updated Date: 2022-04-09T03:55:51Z Creation Date: 1993-12-16T05:00:00Z Registry Expiry Date: 2031-12-15T05:00:00Z Registrar: GoDaddy Corporate Domains, LLC Registrar IANA ID: 3786 Registrar Abuse Contact Email: abuse@gcd.com Registrar Abuse Contact Phone: +1.5189669187 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited Name Server: NS2-02.AZURE-DNS.NET Name Server: NS3-02.AZURE-DNS.ORG Name Server: NS4-02.AZURE-DNS.INFO DNSSEC: unsigned
- thot_experiment 2y agoNot on my LAN it isn't! Why would I care who owns the domain?
- nick0garvey 2y agoI use this for everything at my house. I haven't add any issues.
- monotux 2y agoI've used it at home for several years as well, works great. Due to reasons I've used another level to separate services, management, clients and iot (iot.home.arpa, services.home.arpa...) which I kinda regret today.
- bhaney 2y agoThat's cool, but it's ugly so I'm going to keep using a technically-incorrect-but-works-fine alternative
- DaSHacka 2y agoExactly this; I don't care how much more "correct" home.arpa is, I'll keep using my .lan thank you very much. They really need to just go ahead and officially reserve a nice shorthand TLD for local networks. .lan is already frequently used in internal networks and wouldn't have much appeal as a general-purpose TLD anyway.
- alyandon 2y agoI thought about going that route but ultimately decided to hijack .home internally for my home network.
- greggsy 2y ago.home is fine, but .local is used by mDNS like Bonjour. In practice, it doesn’t seem to cause much problems for printers and AirPlay.
- OJFord 2y agoSurely you'd only ever have an issue if your name collided? If you never have a router.local using mDNS the existence of a DHCP-registered hostname in that form won't matter? And if it did collide you just might not get what you expected?
- greggsy 2y agoI’m holding out for a draft RFC to deprecate .local for mDNS, and allow it to be used for local domains. It’s practically infeasible, but one can wish.
- dark-star 2y agoSame here. We set up our company's intranet using a `.local` address long before mDNS was a thing. Needless to say it causes a lot of pain on a daily basis. On almost every linux installation we have to tweak `/etc/nsswitch.com` for it to work. I doubt it'll ever happen but hey, one can wish :)
- anderskaseorg 2y agoThat will never happen, but RFC 6762 suggests some other options for private networks: .intranet, .internal, .private, .corp, .lan. https://datatracker.ietf.org/doc/html/rfc6762#appendix-G https://datatracker.ietf.org/doc/html/rfc6762#appendix-G ICANN seems to be in the process of finalizing a proposal to officially reserve .internal for this purpose. https://www.icann.org/en/announcements/details/icann-seeks-feedback-on-proposed-top-level-domain-string-for-private-use-24-01-2024-en https://www.icann.org/en/announcements/details/icann-seeks-f...
- vbezhenar 2y agoGiven the fact that Kubernetes uses cluster.local. by default (and probably in the 99% of clusters), you can be sure that any useful software will be OK with that.
- rootbear 2y agoMy Verizon FIOS router came with the ridiculous default domain "mynetworksettings.com". I haven't changed it yet, because I wasn't sure about .local vs .home and whether changing it would break something. As an OG ARPANET user, I rather like the idea of having a home "arpanet" so I think I'll give home.arpa a try!
- NewJazz 2y agoHey, at least Verizon bothered to register the domain.
- arcanemachiner 2y agoReminds me of this story from last year: https://www.caranddriver.com/news/a44083580/maryland-license-plates-filipino-gambling-accident/ https://www.caranddriver.com/news/a44083580/maryland-license...
- urda 2y agoI use lan.urda.com for mine. Looooove having a public and private DNS record set.
- quincepie 2y agoThere was a also proposal for ICANN to reserve ".internal" (earlier this year) which is what I currently use. I suppose home.arpa has the advantage of being strictly resolved in the local zone while ".internal" would be more for anything in a private network (or a large multi zone network)? [1] https://www.icann.org/en/public-comment/proceeding/proposed-top-level-domain-string-for-private-use-24-01-2024 https://www.icann.org/en/public-comment/proceeding/proposed-...
- AndyMcConachie 2y agoThis proposal is still wending its way through ICANN's processes. It should finalize with an ICANN Board resolution sometime this year.
- titanomachy 2y agoI'd need to self-sign my certificates, right? So any guests in my house (assuming a modern browser) would be presented with a big ugly security warning after navigating to a local home.arpa site? I pay $10/year for a custom domain on my country's TLD and host any local stuff on that, so I can use proper CA-signed certificates which are trusted by default. But I could see this being useful if I was only using my own clients.
- hackcasual 2y agoThere's a ton of gTLDs too, I just grabbed a cheap one and ACME-fied all my lan services
- titanomachy 2y agoAre there any that actually stay cheap, though? Any time I've bought one they've cranked the price after a year.
- deathanatos 2y ago… .net? (<$15/y for the registration.)
- throawayonthe 2y ago[dead]
- piperswe 2y agoThe following TLDs are $3.98/yr (not an initial discount, that's just the price) with Cloudflare Registrar according to https://old.reddit.com/r/webdev/comments/17lpxa6/cloudflare_domain_registrar_pricing_table/ https://old.reddit.com/r/webdev/comments/17lpxa6/cloudflare_...: - .bid - .download - .date - .loan - .men - .party - .stream - .trade - .win You could probably get away with using a few of these for a home network, though some would be kinda strange (.men? .loan?)
- 2y ago
- riffic 2y ago[RFC 8375]
- kstrauser 2y agoICANN has proposed using .internal; see https://news.ycombinator.com/item?id=39152306 https://news.ycombinator.com/item?id=39152306.
- mrbluecoat 2y agoAnd how is .home.arpa better than RFC-2606 .test, .example, .invalid, or .localhost ?
- yjftsjthsd-h 2y agoBecause devices on my home network aren't examples, aren't invalid, aren't (all) localhost, and aren't (necessarily) for testing.
- lukevp 2y agoWhat about devices on my work network? Is work.arpa a thing? Or are the labels arbitrary?
- icedchai 2y agoI use int.example.com for my home network, where example.com is a domain I've had for 30 years. Domains didn't cost anything back then!
- NewJazz 2y agoThis RFC is recommending a default, non-unique domain for residential routers to ship with. If you have a domain of your own, by all means use it. Most residential network operators don't.
- betaby 2y agoWhat exactly does that mean? 'example.com' is registered to IANA since 1992.
- gl-prod 2y agoOC replaced the real domain with example.com. Could have used int.google.com.
- throwanem 2y agoIt means grandparent commenter ain't sayin': > where example.com is a domain I've had for 30 years (That domain has that reservation specifically for use in arbitrary examples, as here.)
- icedchai 2y agoIt was a placeholder... an example. (You know, the documented purpose of example.com!) I am not posting my actual domain here.
- trallnag 2y agoSo public DNS contains records pointing to private IPs?
- icedchai 2y agoYes. I could implement split DNS, but I don't.
- eddyg 2y ago`.home`, `.corp` and `.mail` are on ICANN’s “high risk” list so won’t ever be gTLDs. So I use those gTLDs when setting up internal networks. Ref: https://www.icann.org/en/board-activities-and-meetings/materials/approved-board-resolutions-regular-meeting-of-the-icann-board-04-02-2018-en#2.c https://www.icann.org/en/board-activities-and-meetings/mater...
- rvnx 2y agoThey still let ".dev" go through
- reddalo 2y agoI'm still angry at them (and Google) for that
- jefftk 2y agoIt' looks to me like ".home", ".corp", and ".mail" were reserved as "high-risk", and then they refused to approve any of them as gTLDs. I see an argument that ".dev" should have been considered "high-risk", but it doesn't seem to have been on the list. So this isn't a reason to distrust ICANN when they say they won't be approving ".home", ".corp", and ".mail".
- FireBeyond 2y agoThe one I use is .lan.
- 2y ago
- spiritplumber 2y agojust let us have .lan for lans please
- blackdogie 2y agoA good way to avoid the Fritz.box issue from a few weeks ago https://news.ycombinator.com/item?id=40106336 https://news.ycombinator.com/item?id=40106336 / https://domainnamewire.com/2024/05/02/internet-gateway-company-faces-name-collision-with-box/ https://domainnamewire.com/2024/05/02/internet-gateway-compa...
- FinnKuhn 2y agoFor anyone else wanting to now how this turned out: https://www.heise.de/en/news/Schiedsverfahren-gewonnen-Domain-fritz-box-gehoert-nun-AVM-9717910.html https://www.heise.de/en/news/Schiedsverfahren-gewonnen-Domai...
- kps 2y agoFor anyone else wanting to know how this turned out without clicking through popups in German: Fritz.box won against the new anonymous registrant.
- 8organicbits 2y agoThe inability to get a TLS cert is an issue. I've been working on getlocalcert [1] as a free subdomain service for local networks. You get a valid domain, you can get a Let's Encrypt (or other ACME DNS-01 provider) cert. But you need to provide your own split DNS locally to resolve addresses. It's intended to fill the gap between paying for a domain or using a free domain service full of abuse. Because you need to provide DNS locally, it's useless for the common abuse scenario (spam, phishing, illegal content). Unlike other free domain providers, I have never received an abuse notification. I got on the public suffix list in the last few months. Lots more features I'd like to add, but my attention has been elsewhere. [1] https://www.getlocalcert.net/ https://www.getlocalcert.net/
- someguydave 2y agoSign your own? It’s your home!
- accrual 2y agoI've thought about running a local CA, but wouldn't one need to have all of their devices configured to trust the local CA in addition to issuing certs to your services? I've been getting by just clicking through the TLS warnings for my LAN services, most browsers remember the choice for a couple days at least.
- gclawes 2y agoI've been doing this for a while with SmallStep CA: https://github.com/smallstep/certificates https://github.com/smallstep/certificates It's a bit of a pain to load a cert onto every device (easier with stuff like Ansible if you have a bunch of linux devices), but manageable. And it lets me do proper trusted TLS for a lot of stuff that would otherwise be self-signed. edit: It's also just a fun homelab project to see what it's like to run a full production-ish PKI setup. One thing I recommend is to add X509v3 Name Constraints extensions to your root CA if you go down this path. It prevents the CA from being abused to MITM you for other domains (at least for browsers/clients that respect names constraints) X509v3 Name Constraints: critical Permitted: DNS:home.arpa DNS:.home.arpa IP:10.0.0.0/255.0.0.0 IP:172.16.0.0/255.240.0.0 IP:192.168.0.0/255.255.0.0
- deleted 2y ago[deleted]
- mixmastamyk 2y agoHmm, my local dns servers, adguard and dnsmasq don't seem to recognize it. Do I have to configure something? I prefer the .lan that I'm currently using.