18 ms·
.INTERNAL is now reserved for private-use applications
- joncfoo 2y ago[...] the Board reserves .INTERNAL from delegation in the DNS root zone permanently to provide for its use in private-use applications. The Board recommends that efforts be undertaken to raise awareness of its reservation for this purpose through the organization's technical outreach.
- deleted 2y ago[deleted]
- csdreamer7 2y agoCan we get .local or .l added for private-use applications too?
- kxrm 2y agoIs it not already? https://en.wikipedia.org/wiki/.local https://en.wikipedia.org/wiki/.local
- csdreamer7 2y agoNot by ICANN? https://www.iana.org/domains/root/db https://www.iana.org/domains/root/db
- duskwuff 2y agoThe ICANN root zone only contains gTLDs and ccTLDs which are delegated. Other TLDs which are explicitly reserved for non-public use, like .localhost, .test, or .invalid, don't appear on that list either.
- csdreamer7 2y agoTy for the information.
- quectophoton 2y agoI think a more correct place to look at would be the gTLD Applicant Guidebook[1][2], section "2.2.1.2.1 Reserved Names", which I guess should be updated to now include "INTERNAL". Though that list apparently includes all reserved names, not only those reserved for non-public use. [1]: https://newgtlds.icann.org/en/applicants/agb https://newgtlds.icann.org/en/applicants/agb [2]: https://newgtlds.icann.org/sites/default/files/guidebook-full-04jun12-en.pdf https://newgtlds.icann.org/sites/default/files/guidebook-ful...
- duskwuff 2y ago.local is already reserved for mDNS.
- jeroenhd 2y ago.local is in this weird state where it's _technically_ not reserved, but most PCs in the world already resolve it with special non-DNS software because of the Bonjour/mDNS protocol. So you end up with the IETF standardising .local, because Apple was already using it, but ICANN never did much with that standardisation. I doubt ICANN will actually touch .local, but they could. One could imagine a scheme where .local is globally registered to prevent Windows clients (who don't always support mDNS) from resolving .local domains wrong.
- eddyg 2y ago.home, .corp and .mail are on ICANN’s “high risk” list so won’t ever be gTLDs, so they are also good (short) options. Ref: https://www.icann.org/en/board-activities-and-meetings/materials/approved-board-resolutions-regular-meeting-of-the-icann-board-04-02-2018-en#2.c https://www.icann.org/en/board-activities-and-meetings/mater...
- NewJazz 2y agoThey could be gTLDs in the far future, but ICANN is likely to hold off for a good long while. Better to use something that is actually reserved, though. You never know.
- LeoPanthera 2y agoUsing .local causes big problems with mDNS/Bonjour/Rendezvous, which also uses that TLD.
- mjevans 2y agoPlease also reserve .lan which is what I now prefer to use since .local got stolen from private networks.
- NewJazz 2y agoYou can use .home.arpa. https://datatracker.ietf.org/doc/html/rfc8375 https://datatracker.ietf.org/doc/html/rfc8375
- neop1x 2y agoYou can use a public subdomain like box.uuid.california.usa.mydns.org but we need something short like .l or .lan :) .home.arpa is terrible. I have been using .l personally for a couple of years and it works fine except Chrome won't recognize it as a tld and would start a google search. Once it is visited a couple of times, it autocompletes it as a webpage so it's quite usable afterall.
- deleted 2y ago[deleted]
- tetris11 2y agoI need a dumbed down version of this.
- kijeda 2y agohttps://www.ietf.org/archive/id/draft-davies-internal-tld-00.html https://www.ietf.org/archive/id/draft-davies-internal-tld-00... There are certain circumstances where private network operators may wish to use their own domain naming scheme that is not intended to be used or accessible by the global domain name system (DNS), such as within closed corporate or home networks. The "internal" top-level domain is reserved to provide this purpose in the DNS. Such domains will not resolve in the global DNS, but can be configured within closed networks as the network operator sees fit. This reservation is intended for a similar purpose that private-use IP address ranges that are set aside (e.g. [RFC1918]).
- pixl97 2y agoWhen setting up local networks people commonly use a top level domain like 'my.lan', 'my.network', 'my.local'. Instead of using one of these non-reserved domains that may one day end up as a TLD, it is recommended to use 'my.internal'. If the 'private' TLD you're using suddenly becomes real, then you can ship off data, every possibly unencrypted data and connection requests to computers you do not control.
- GuB-42 2y agoThe dumbed down version is that no one will be allowed to register a .internal domain on the internet, ever. So you are free to use it for your internal network in any way you like and it will not come into conflict with registered domains and internet standard.
- jeroenhd 2y agoRemember how tons of developers got surprised when Google got the .dev TLD, because they were using domains they didn't own to develop software? Well, now .internal has been reserved so developers and companies can safely use .internal domains without that happening to them.
- 2y ago
- huijzer 2y ago1. Buy .intern TLD 2. Sell to scammers. 3. Profit. (I want to appreciate how hard it probably is for ICANN to figure out proper TLDs.)
- gjsman-1000 2y agoUm... no? .intern is not a valid TLD; you can't get any domains with it, nobody has proposed that TLD, and if someone did that issue would be discovered then.
- jeroenhd 2y agoIf you've got a couple hundred grant laying about, you could probably set up a shell company and acquire .intern through a several-year ccTLD acquisition process. I'd like to think people learned from .dev and such. I doubt any scammer will be able to use it.
- LordKeren 2y agoSorry, what happened with .dev? EDIT: just saw your comment about Google here https://news.ycombinator.com/item?id=41205394 https://news.ycombinator.com/item?id=41205394
- n_plus_1_acc 2y agoPeople were using .dev for internal things and acted surprised when Google decided to use it on the internet.
- jeroenhd 2y agoTo expand on my comment: Google bought .dev and started selling domains. In truth, developers probably only noticed because Google pre-loaded their .dev TLD into HSTS, which meant that any domain ending in .dev, even if it's a local one or one you own, must communicate over HTTPS if you want a browser to interact with it. As a result, even if you bought steves-laptop.dev for yourself, you still wouldn't be able to run an HTTP dev environment on it, you'd need to set up HTTPS. I think that was probably a good move by Google, because otherwise it could've taken weeks for most devs to notice.
- ChrisArchitect 2y agoBunch more discussion on the proposal earlier in the year: Proposed top-level domain string for private use: ".internal" https://news.ycombinator.com/item?id=39152306 https://news.ycombinator.com/item?id=39152306
- shrimp_emoji 2y ago[dead]
- jcrites 2y agoAre there any good reasons to use a TLD like .internal for private-use applications, rather than just a regular gTLD like .com? It's nice that this is available, but if I was building a new system today that was internal, I'd use a regular domain name as the root. There are a number of reasons, and one of them is that it's incredibly nice to have the flexibility to make a name visible on the Internet, even if it is completely private and internal. You might want private names to be reachable that way if you're following a zero-trust security model, for example; and even if you aren't, it's helpful to have that flexibility in the future. It's undesirable for changes like these to require re-naming a system. Using names that can't be resolved from the Internet feels like all downside. I think I'd be skeptical even if I was pretty sure that a given system would not ever need to be resolved from the Internet. [Edit:] Instead, you can use a domain name that you own publicly, like `example.com`, but only ever publish records for the domain on your private network, while retaining the option to publish them publicly later. When I was leading Amazon's strategy for cloud-native AWS usage internally, we decided on an approach for DNS that used a .com domain as the root of everything for this reason, even for services that are only reachable from private networks. These services also employed regular public TLS certificates too (by default), for simplicity's sake. If a service needs to be reachable from a new network, or from the Internet, then it doesn't require any changes to naming or certificates, nor any messing about with CA certs on the client side. The security team was forward-thinking and was comfortable with this, though it does have tradeoffs, namely that the presence of names in CT logs can reveal information.
- slashdave 2y ago> it's helpful to have that flexibility in the future On the contrary, it is helpful to make this is impossible. Otherwise you invite leaking private info by configuration mistake.
- colejohnson66 2y agoWhy? Remember the .dev debacle?
- leeter 2y agoI can't speak for others but HSTS is a major reason. Not everybody wants to deal with setting up certs for every single application on a network but they want HSTS preload externally. I get why for AWS the solution of having everything from a .com works. But for a lot of small businesses it's just more than they want to deal with. Another reason is information leakage. Having DNS records leak could actually provide potential information on things you'd rather not have public. Devs can be remarkably insensitive to the fact they are leaking information through things like domains.
- zzo38computer 2y agoI think it is good to have a .internal TLD for internal use. (I also think that a .pseudo TLD should be made up which also cannot be assigned on the internet, but is also not for assigning on local networks either. Uusually, in the cases where it is necessary to be used, either the operating system or an application program will handle them, although the system administrator can assign them manually on a local system if necessary.)
- Denvercoder9 2y ago> I also think that a .pseudo TLD should be made up which also cannot be assigned on the internet, but is also not for assigning on local networks either. There's already .example, .invalid, .test and .localhost; which are reserved. What usecase do you have that's not covered by one of them?
- zzo38computer 2y ago.example is used for examples in documentation and stuff like that. .invalid means that a domain name is required but a valid name should not be used; for example, a false email address in a "From:" header in Usenet, to indicate that you cannot send email to the author in this way. .test is for a internal testing use, of DNS and other stuff. .localhost is for identifying the local computer. .internal is (presumably) for internal use in your own computer and local network, when you want to assign domain names that are for internal use only. .pseudo is for other cases that do not fit any of the above, when a pseudo-TLD which is not used as a usual domain name, is required for a specialized use by a application, operating system, etc. You can then assign subdomains of .pseudo for specific kind of specialized uses (these assignments will be specific to the application or otherwise). Some programs might treat .pseudo (or some of its subdomains) as a special case, or might be able to be configured to do so. (One example of .pseudo might be if you want to require a program to use only version 4 internet or only version 6 internet, and where this must be specified in the domain name for some reason; the system or a proxy server can then handle it as a special case. Other examples might be in some cases, error simulations, non-TCP/IP networks, specialized types of logging or access restrictions, etc. Some of these things do not always need to be specified as a domain name; but, in some cases they do, and in such cases then it is helpful to do so.)
- 2snakes 2y agoThere used to be issues with the public part of a .com getting sent weird private windows traffic iirc. This was discovered with honeypot analysis and the potential for information exposure if you could register a .com and another company was using it as their AD domain.
- quectophoton 2y agoOn this topic, whoever owns "test.com" must be getting a lot of sensitive information.
- xvilo 2y agoAny ideas on how you would run SSL/TLS on these set-ups?
- the8472 2y agoEither pin the appropriate server cert in each application or run your internal CA (scoped to that domain via name constriants) and deploy the root cert to all client machines.
- rileymat2 2y agoI think you can still run self signed, with a private CA/root cert?
- jeroenhd 2y agoAn internal certificate authority would probably be the easiest option. Combined with MDM/group policy, you could tell most devices in your network to set up a trust chain of your own. From then on you can automate access by running your own ACME server internally to automatically hand out certificates to local devices. The automated setup probably isn't very secure, though. Anyone can register any .local name on the network, so spoofing hostnames becomes very easy once you get access to any device on the network. Send a fax with a bad JPEG and suddenly your office printer becomes xvilo.local, and the ACME server has no way to determine that it's not. That means you probably need to deal with manual certificate generation, manually renewing your certificates every two years (and, if you're like me, forgetting to before they expire).
- Hamuko 2y agoI just got myself a proper domain name. You can get a domain for pretty cheap if you're not picky about what you get. You could for example register cottagecheese.download on Cloudflare for about $5/year right now. I have my domain's DNS on Cloudflare, so I can use DNS verification with Let's Encrypt to get myself a proper certificate that works on all of my devices. Then I just have Cloudflare DNS set up with a bunch of CNAME records to .internal addresses. For example, if I needed to set up a local mail server, I'd set mail.cottagecheese.download to have a CNAME record pointing to localserver.internal and then have my router resolve localserver.internal to my actual home server's IP address. So if I punch in https://mail.cottagecheese.download https://mail.cottagecheese.download in my browser, the browser resolves that to localserver.internal and then my router resolves that to 10.x.x.x/32, sending me to my internal home server that greets me with a proper Let's Encrypt certificate without any need to expose my internal IP addresses. Windows doesn't seem to like my CNAME-based setup though. Every time I try to use them, it's a diceroll if it actually works.
- deleted 2y ago[deleted]
- 8organicbits 2y agoMy biggest frustration with .internal is that it requires a private certificate authority. Lots of organizations struggle to fully set up trust for the private CA on all internal systems. When you add BYOD or contractor systems, it's a mess. Using a publicly valid domain offers a number of benefits, like being able to use a free public CA like Lets Encrypt. Every machine will trust your internal certificates out of the box, so there is minimal toil. Last year I built getlocalcert [1] as a free way to automate this approach. It allows you to register a subdomain, publish TXT records for ACME DNS certificate validation, and use your own internal DNS server for all private use. [1] https://www.getlocalcert.net/ https://www.getlocalcert.net/
- xer0x 2y agoOh neat, thanks for sharing this idea
- TheRealPomax 2y agoI'm pretty sure that if letsencrypt localhost certs work, they'll work fine with .internal too?
- merb 2y agolet’s encrypt does not support certain for localhost.
- mschuster91 2y ago> Lots of organizations struggle to fully set up trust for the private CA on all internal systems. Made worse by the fact phone OSes have made it very difficult to install CAs.
- booi 2y agoAnd in on some platforms and configurations, impossible. Same with the .dev domain
- 2y ago
- wolpoli 2y agoAnyone know when I should use .internal and when I should use .local?
- mmooss 2y ago[dead]
- Macha 2y agoDon't assign names using .local, it's for mDNS: https://en.wikipedia.org/wiki/.local https://en.wikipedia.org/wiki/.local
- SoftTalker 2y agoAnd what about .localdomain?
- radicality 2y agoI’ve been using .home.arpa for a while at home now.
- mmooss 2y ago[dead]
- dawnerd 2y agoI'm still peeved they let google take over .dev when they knew tons of us used that in the older days for dev environments.
- TheRealPomax 2y agoto be fair, ".dev" is not a full word, unlike INTERNAL or EXAMPLE. You're free to petition them to reserve .DEVELOPMENT, though, of course.
- nine_k 2y agoA convenient TLD is short, not excruciatingly loquacious. In ease of typing .dev certainly wins over .development.
- Jerrrrrrry 2y agoIt's not convenient if 99% of users (internet users) can't (effectively) use it. .dev is great; even if Google's motives were evil-truistic; and, *.development should be among the Reserved, Internet Use only. The abbreviated vs verbose TLD name is consistence. There aren't any folks more appreciable than consistency then the RFC goons.
- slaymaker1907 2y agoLuckily, we have *.test. I’ve used that one quite a bit.
- TheRealPomax 2y agoYes, but a convenient reserved TLD, formally declared never to be used by anyone and guaranteed to never resolve to anything by global DNS, is not accepted based on convenience alone. The ".dev" TLD is plenty useful as real domain. Plus, and this one's hard to believe, calling programming related work "dev" work is a surprisingly recent thing.
- cowsup 2y ago.com is not a full word either (company), or .org (organization), .net (internet), .gov (government), ...
- VoodooJuJu 2y agoWhy did something so useful and simple like this take so long to make official?
- poikroequ 2y agoThings like this are rarely simple or obvious. I don't know what potential gotchas there could have been, but I'm sure there were strange and unusual things they had to carefully consider before making this an official standard.
- Hamuko 2y agoICANN didn't understand why you weren't simply just using the recommend .home.arpa TLD.
- Filligree 2y agoI’m going to go right on using .lan.
- throwaway290 2y ago.la and .land are already valid domains so don't make a typo. And I guess .lan can be sold eventually if it turns out it's a word somewhere.
- flemhans 2y agoThey already got .cat, so why not the ending as well.
- ryukoposting 2y agoI'll probably just keep using .lan, but it's nice to know that ICANN is thinking about this use case.
- ahoka 2y agoNow we just wait until browsers stop doing a search if you type anything ending with .internal, which is the biggest issue with using non standard private domains.
- amelius 2y agoOf course, scammers will register variations of .internal Like .lnternal Or .ιnternal
- endorphine 2y agoHow? Do these gTLDs even exist?
- cloudyporpoise 2y agothey don't. This person must believe anyone can create and register any TLD lol https://data.iana.org/TLD/tlds-alpha-by-domain.txt https://data.iana.org/TLD/tlds-alpha-by-domain.txt
- amelius 2y agoThen why does .americanexpress exist? Sounds like someone simply pulled their wallet. Or maybe you forgot "/s"
- NietTim 2y agoEver since this kind of stuff was introduced I've been annoyed that there is no way to disable it for yourself. And it's allowed for straight up evil stuff like google buying the .dev TLD
- NewJazz 2y agoYour mention of .dev seems like a complete non-sequiter to me. What happened to .internal here is the exact opposite of what happened to .dev. And how would you even propose to "disable" reservation of a TLD. Sorry your comment just makes no sense from my POV.
- Arch-TK 2y agoI've just used i.slow.network. for my internal domain.
- myshkin5 2y agoDoes this mean .svc.cluster.local for Kubernetes should migrate to .svc.cluster.internal?
- zigzag312 2y agoToo many letters.
- gxt 2y agoIs there an appliance or offline service to setup a private CA, do secure remote attestation, and issue certificates only to authenticated peers? Also preferably with fido2 support for administrative purposes.
- vedangvatsa 2y ago[flagged]
- PufPufPuf 2y agoThat's an LLM-automated spam comment if I ever saw one.