Can you link to a site where these two are different?
Can you link to a site where these two are different?
For example, with Active Directory, the DNS A record for your foo.com domain must resolve to your domain controllers. Your www.foo.com will resolve to a separate non-domain controller web server.
I think a lot of the commenters here are thinking solely in terms of commercial web services such as twitter.com and such, but there's so much more to the wider landscape.
My $dayjob has our AD root domain the same as our public root domain. Because we implemented AD in the year 2000, and this was Microsoft’s recommendation for domain naming way back then.
And if you use Exchange, you can’t rename your AD domain, you have to rebuild your forest and migrate piecemeal. So we’re stuck with it.
The practice of using Corp.example.com did not evolve until many years after Windows 2000 and Exchange 2000 were in the wild.
So we run http redirectors on each of our domain controllers to send traffic to www.
I trained on Active Directory (AD) with a group of veteran sysadmins in 1999. I don't have access to the "Microsoft Official Curriculum" book from my class in '99 (long-since thrown away), but I have a distinct memory of a lively conversation in class re: the pitfalls of using a public domain name as an AD domain name (or, worse yet, a Forest Root domain name) during the class. It was very evident to our group of veteran sysadmins that using a public domain name in AD would create silly make-work scenarios (like installing IIS on every DC just to run redirect visitors to "www.example.com"-- just as you describe, albeit IIS didn't natively support sending redirects at the time).
I'd go further and suggest that anybody with a modicum of familiarity with DNS knows having multiple roots-of-authority for a single domain name is a bad idea. Microsoft not supporting split-horizon in their DNS server (like BIND does with 'views') compounded the difficulties with such a scenario in an all-Windows environment.
I certainly wouldn't argue that Microsoft has given exclusively good recommendations for AD domain names in the past (evidence ".local" in Windows Small Business Server), but I am reasonably certain that their documentation always suggested that using a subdomain of a public domain name was a supported and workable option.
I started deploying AD in 2000. I've deployed roughly 50 forests in different enterprises, and I've never used a public domain name as an AD domain name. I've domain-renamed all my subsequently-acquired Customers for whom it was an option (which it was, so long as they had not yet installed Exchange 2007), and have been rebuilding the Forests of Customers who made the wrong decision in the past, where it makes economical sense.
* http://jdebp.info./FGA/dns-split-horizon.html#SeparateConten...
As an aside: I really enjoy your writing about using SRV lookups. It makes me sad that SRV records aren't being as much as they could / should be.
* http://jdebp.eu./FGA/dns-split-horizon-common-server-names.h...
* http://jdebp.eu./FGA/dns-ms-dcs-overwrite-domain-name.html
* http://jdebp.eu./FGA/dns-use-domain-names-that-you-own.html
And the other comment mentioned that this was a known issue 20 years ago because the old versions of IIS did not support redirecting.
Having a disjoint DNS namespace (and the needless make-work that it creates) is the issue, more than running HTTP servers on all your DCs to do redirects. There is absolutely no practical advantage to running an Active Directory domain with a public DNS name. It's all downside. It has always been all downside, and anybody who had any experience with DNS could see that all the way back in the beta and RC releases of the product in 1999 and 2000.
http://www.pool.ntp.org vs http://pool.ntp.org
One takes you to the website about the project, the other goes to a random ntp server.
http://www.pool.ntp.org/ redirects me to https://www.ntppool.org/en/.
http://pool.ntp.org/ takes me to an "It works!" default Apache 2 page for an Ubuntu installation. As the comment in the issue describes, http://pool.ntp.org/ takes you to a random ntp server.
If you want another example, try google.com using Google's own DNS:
PS U:\> nslookup - 8.8.8.8
Default Server: google-public-dns-a.google.com
Address: 8.8.8.8
> google.com
Server: google-public-dns-a.google.com
Address: 8.8.8.8
Non-authoritative answer:
Name: google.com
Addresses: 2607:f8b0:4009:810::200e
172.217.8.206
> www.google.com
Server: google-public-dns-a.google.com
Address: 8.8.8.8
Non-authoritative answer:
Name: forcesafesearch.google.com
Addresses: 216.239.38.120
216.239.38.120
Aliases: www.google.com
Even if you ultimately end up at the same site through redirects, you're clearly not going to the same site initially.Either way, the ask was for a difference in www.example.com vs example.com. Not a difference in www.pool.example.com vs pool.example.com. In the latter case, the different subdomains will still be shown (AFAIK).
>Even if you ultimately end up at the same site through redirects, you're clearly not going to the same site initially.
Which is nothing that an end user is going to care about and doesn't provide an example to the asked question.
http://www.pool.example.com displays as http://pool.example.com
Here's a gif: https://vgy.me/61I0DA.gif
For fun I'm going to set up a www.www.www.www.www.www.www.www.www record.
http://www.www.www.www.www.www.www.www.www.www.example.com shows as example.com
E: I'll add it to my certs later but I did it: https://www.www.www.www.www.www.www.www.www.www.www.www.aish...
E2: http://www.example.www.example.org shows up as example.example.org - this is fun.
I just found the same thing. How exactly is this a feature? What an insane decision.
How would I differentiate between loadbalancer1.www.intranet and loadbalancer1.intranet? THOSE ARE NOT THE SAME.
http://www.pool.ntp.org/ http://pool.ntp.org/
https://www.citibank.com.sg/ https://citibank.com.sg/
Plus, this actually removes any www part of the domain.
So subdomain.www.example.com shows as subdomain.example.com
Why even open that can of worms?
B) Consider subdomains for test-purpose like "www.test.www.example.com" (now displayed as "test.example.com", which is actually not even the root of the specific subdomain).
C) Users unsure, if they are on the full-featured or a reduced mobile site, when "m" is hidden.
D) I may actually want to have a service agnostic default host at the root and subdomains for dedicated servers (like "www", "ftp", "mail", "stun", "voip", etc). Maybe this one just returns a short text message by design, if accessed on port 80. Not every domain is just about the WWW. (Edit: While we may assume that such a server would forward in practice, this may be assuming too much.)
> Can you link to a site where these two are different?
There are 3rd level domains where everyone can register "www.{TLD}". E.g., .com.kg, .net.kg, .org.kg. Look at the www.com.kg. It's also available as www.www.com.kg. Or www.org.kg that's in fact www.www.org.kg. If you display just the last part (com.kg, org.kg), does that mean that you're viewing the root website? Nope, that doesn't. That means that chrome is fucked up.
One of my school's websites: I can't remember what it was and this was before I understood what the difference is, but www worked much better than without iirc.
This also applies to m.*, so literally any web-app with a mobile version.
I haven’t tested it but it will most likely show up as domain.com in the address bar and will result in an error show to the customer.
If chrome wants to strip www as it’s essentially the same domain.com they can submit an RFC and not just decide for everyone. Honestly I hope they start making more stupid decisions like this so ppl move to Firefox so we have more competition.
Yup, that's on the developers. Hopefully this fix will make it so that it will be easier to setup DNS with just one domain instead of 2. Props to Chrome.