ICANN proposes creating .INTERNAL domain to do the same job as 192.168.x.x
- Reference: 1706513472
- News link: https://www.theregister.co.uk/2024/01/29/icann_internal_tld/
- Source link:
The proposed TLD is .INTERNAL and, as the name implies, it's intended for internal use only. The idea is that .INTERNAL could take on the same role as the 192.168.x.x IPv4 bloc – available for internal use but never plumbed into DNS or other infrastructure that would enable it to be accessed from the open internet.
ICANN's Security and Stability Advisory Committee (SSAC) [1]advised the development of such a TLD in 2020. It noted at the time that "many enterprises and device vendors make ad hoc use of TLDs that are not present in the root zone when they intend the name for private use only. This usage is uncoordinated and can cause harm to Internet users" – in part by forcing DNS servers to handle, and reject, queries for domains only used internally.
[2]
DNS, however, can't prevent internal use of ad hoc TLDs. So the SSAC recommended creation of a TLD that would be explicitly reserved for internal use.
[3]
[4]
A consultation process produced 35 candidate strings, each of which was checked to ensure it wasn't already a TLD, and for "potential for confusing similarity, for length, and for its capacity to be memorable and meaningful." Assessments were conducted for all six United Nations languages: Arabic, Chinese, English, French, Russian and Spanish. That process saw many candidates "deemed unsuitable due to their lack of meaningfulness."
For example, .DOMAIN was binned because it was felt not to "convey that its purpose is specifically for private-use applications."
[5]
After years of debate, ICANN and other internet governance orgs were left with two viable candidates: .PRIVATE and .INTERNAL.
[6]Don't panic. Google offering scary .zip and .mov domains is not the end of the world
[7]DotAsia registry tries to put poll problems behind it and set new strategy
[8]Combination of cheap .cloud domains and fake Shark Tank news fuel unhealthy wellness scams
[9]ICANN warns UN may sideline tech community from future internet governance
Last Thursday, ICANN [10]announced [PDF] that .INTERNAL was its choice.
.PRIVATE lost out because assessors felt it "may carry the unintended imputation of privacy to a higher degree, and more potential was seen for conflicting meanings across the gamut of assessed languages."
ICANN's board still has to sign off the creation of .INTERNAL. But if you want to get ahead of the pack, there's nothing stopping you. Indeed, some outfits already use ad hoc TLDs. Open source Wi-Fi firmware project WRT has used .LAN, and networking vendor D-Link has employed .dlink.
There's nothing stopping you doing likewise.
[11]
But as ICANN's [12]proposal for the idea noted: "Operators who choose to use private namespaces of the kind proposed in this document should understand the potential for that decision to have corresponding costs, and that those costs might well be avoided by choosing instead to use a sub-domain of their own publicly registered domain name."
Which is why The Register loves the standards process. ®
Get our [13]Tech Resources
[1] https://itp.cdn.icann.org/en/files/security-and-stability-advisory-committee-ssac-reports/sac-113-en.pdf
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZbeFXlv6RYB9IAK2HkaOBAAAANM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbeFXlv6RYB9IAK2HkaOBAAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZbeFXlv6RYB9IAK2HkaOBAAAANM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbeFXlv6RYB9IAK2HkaOBAAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2023/05/17/google_zip_mov_domains/
[7] https://www.theregister.com/2023/12/28/dotasia_by_election_reform_challenge/
[8] https://www.theregister.com/2024/01/17/netcraft_health_scams_analysis/
[9] https://www.theregister.com/2023/08/22/icann_un_digital_compact_warning/
[10] https://itp.cdn.icann.org/en/files/root-system/identification-tld-private-use-24-01-2024-en.pdf
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZbeFXlv6RYB9IAK2HkaOBAAAANM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://itp.cdn.icann.org/en/files/security-and-stability-advisory-committee-ssac-reports/sac-113-en.pdf
[13] https://whitepapers.theregister.com/
I use....
.hadschihalefomarbenhadschiabulabbasibnhadschidavudhalgossarah
(sorry to all who now have that shitty song stuck in their head! have one of these and numb your pain ---->)
Re: I use....
The 64 character limit for TLDs is really weird. In most cases, a low limit in things is bad because it doesn't take into account future expansion, but seriously, do they think the world will ever be albe to use TLDs of more than like, 12 characters, at the very most? The whole point of DNS is to make addresses human-readable. Is every device on Earth supposed to get its own TLD, which will have to contain random alphanumeric strings? Is every personal TLD going to look like AOL email addresses, with random numbers added to your name? Will the current concept of domain names and TLDs even apply if your personal TLD is equivalent to your email address and assigned at birth?
Re: I use....
It seems like a fine limit to me. We may not use anything that long, but having a lower limit wouldn't offer any advantages as far as I know. The 64-character limit also makes it possible to use some strange things, like the encoding of Unicode domains to ASCII. The longest domain name in use is .ファッション, which is in your expected range for length, but since it's in unicode, it's actually implemented as .xn--bck1b9a5dre4c. It's convenient that the limit makes that feasible, as a shorter limit would have required it to be truncated.
Re: I use....
You'll be kicking yourself for this comment when Llanfairpwllgwyngyllgogerychwyrndrobwllllantysiliogogogoch becomes its own country.
Mind you, at 58 letters long, when using the English alphabet, it's already too long to be coded in the Welsh alphabet via punycode, so I propose the limit is raised to 128 characters!
I've used .internal as a TLD before
When setting up isolated networks at a few long ago consulting gigs.
What's wrong with .local or a subdomain thereof if you must segregate?
Leave .internal for the world of gynaecology.
The .local domain is reserved for .local people.
I didn't know that. Years ago I chose a 2 letter domain root that wasn't used for an existing country and so far the various wars and disputes haven't spawned a new country that wants to use it. I'm not going to re-jig my DNS server to a new standard though. Sometimes being different is useful.
wasn't used for an existing country
Somehow I don’t think ones like .cs or .yu will ever be allocated again.
Or .gb, for that matter.
[1]Wooosh?
[1] https://www.bbc.co.uk/programmes/p006vm6j
> The .local domain is reserved for .local people.
Hello, hello. What's going on? What's all this shouting? We'll have no trouble here.
In fact, .local is already reserved by the IETF and IANA for essentially this purpose (apparently not specifically for use with internal DNS servers, but rather mDNS, but it's what has been done for decades and has always been the default in Windows). Does ICANN just feel like they need to be seen to be doing something, and it can't be just agreeing with some other organization, so they are willing to fragment the ecosystem and make it more confusing? Or are they deciding they're going to "fix" what they see as being used incorrectly by everyone?
Re: Does ICANN just feel like they need to be seen to be doing something
Yes.
Message ends.
No. Using .local in as a DNS TLD can cause problems because of precisely the reason you cite - it's officially used by mDNS and as mDNS configurations "own" that TLD, using it in the local DNS will cause issues if you're network also runs mDNS.
For this reason, it's already prohibited from being used in the DNS.
[1]https://community.veeam.com/blogs-and-podcasts-57/why-using-local-as-your-domain-name-extension-is-a-bad-idea-4828
[1] https://community.veeam.com/blogs-and-podcasts-57/why-using-local-as-your-domain-name-extension-is-a-bad-idea-4828#:~:text=The%20special%2Dpurpose%20.,for%20a%20dedicated%20DNS%20server.
"Local" also implies "nearby", but "internal" doesn't have the same connotations.
This really has nothing to do with "taking over" for the RFC1918 IP ranges. It's not "doing the job" of 192.16.x.x. You still need IP addresses and you still should be using RFC1918 IPs on your internal network, when using IPv4.
> After years of debate
Lol, what?
Maybe the debate was one or two people repeatedly insisting this NEEDED to be done, and dozens of other people saying "you're morons" and the other two submitting it for discussion again at the next meeting, slowly wearing people down to where they just said "whatever".
One could say it was a mass debate.
Where the speakers have a sneaky grasp of foreign languages?
Those cunning-linguists...
"DNS, however, can't prevent internal use of ad hoc TLDs"
So basically, ICANN wants to make a standard out of something everyone can already do and some are doing it, but ICANN wants to put a specific name on it which will make everyone already doing it wonder if they should go through the hassle of changing and decide not to. But future network admins may buy into the "standard", except if that contradicts some business requirement, in which case they'll just go with whatever they need and it'll work anyway.
Did I get that right ?
Re: "DNS, however, can't prevent internal use of ad hoc TLDs"
Not even that. ICANN has, over years of discussion, decided to take a name and do nothing with it. A name they already were doing nothing with, that nobody had asked to use, and in a set of other names they've already decided to do nothing with. When this idea is fully implemented, nothing whatsoever will change anywhere in the world.
Re: "DNS, however, can't prevent internal use of ad hoc TLDs"
Huh? By that argument, RFC1918 is pointless too.
A rare piece of sanity
This has been resisted for so long, and was so obviously needed.
I have .lan at home mainly as OpenWRT uses this and it's quicker to type than .internal.
To be honest I'd reserve common ones used (identified in the report) and not just one, then just move on.
i.e. .home, .internal, .lan, .corp, .localdomain
I can see it actually being more sensible for an AD domain to be companyname.{corp|lan|internal} than a real (as recommended by MS).
Companies often forget to renew real domains (then your are stuck).
Call it molehilling.
It's like bike-shedding how many angels can fit on the head of a pin.
It Isn’t Just 192.168
Note that [1]RFC1918 specifies three different IPv4 address ranges for private use: 192.168.0.0/16, 10.0.0.0/8, and 172.16.0.0/12.
And don’t forget the range for ad-hoc allocation in the absence of a DHCP server: 169.254.0.0/16.
And then there’s IPv6.
[1] https://datatracker.ietf.org/doc/html/rfc1918