My computer has an underscore in its name, and I have trouble with the network
kb.iu.edu
kb.iu.edu
I was building a realtime video player in this new cool thing called HTML5 at the time. HTML5 video support was (/still is, to some extent) a huge PITA due to the uneven codec support, minor implementation differences etc... So naturally I spent days troubleshooting that... Turns out `_` in domain names were not handled properly by some versions of IE running on intranet.
The only more annoying bug like this I can remember now is fighting a suspected DOS attack on our servers when I worked in publishing. The culprit: our Android dev contractor decided to save some time by not implementing push notifications used to read the content but instead used the alarm service, thus making sure that almost every Android user fired a bunch of expensive requests at the same effin' time. Happy times.
Your choice of words implies there was a bug in IE, but there likely was not. People quickly forget before Google dumbed down the landscape with its Unibrowser and forced its ways and whims upon the world (and continue to do so)... IE had user-accessible settings for EVERYTHING.
IE also had the concept of security zones with different settings for each zone including Intranet, a feature ahead of its time - quirkily enough and nearly undocumented, Chrome on Windows quietly uses IE's security zones for a few purposes of its own.
Indeed, there are separate settings in IE for "Send IDN host names for [non] Intranet URLs" with different default values depending on Intranet or not, and the _ was likely interpreted as an international domain name and triggering this setting. Why does this setting exist? Knowing Microsoft almost surely for some backwards compatibility edge case.
I first ran into this problem 20 years ago, and have constantly over the next 20 years. Usually *nix Bind DNS servers warn you against self-inflicted gunshot wounds, but Windows DNS lets you do so gladly. I've managed to figure out over the years this was largely due to silly Windows NT4 admins that built domains, hostnames, and other things with underscore, that when evolving to Active Directory with Windows 2000 that used real DNS, and if Microsoft didn't let them use an underscore, they'd have forced (and should have) admins all over to have to rebuild their domains from scratch to conform to DNS RFC's.
The easy (Microsoft) answer: "Extend" the standard to allow underscores for AD DNS... And allow bad habits to extend perpetually and indefinitely, world and standards bed damned. As usual, thanks for all the fish Microsoft.
I've run into several organizations over the years that use Windows domains that have underscores, and every time I laugh, usually explaining to them about how that's technically illegal and breaks compatibility with, oh everyone but them. It's usually shrugged off that because it's "internal only" they don't have to. At least until they setup external partner and extranet networks outside of their own.
Any unix/linux folks that have ever setup a bind server themselves has probably run into this fact, but windows admins tend to remain still blissfully ignorant about the evils they do.
=================================
yes, non-punycode domains may not start or end with dashes and must not have consecutive dashes
the consecutive dashes in punycode were done on purpose so that the new internationalizing punycode domains couldn't conflict with any existing domain.
But you might smile and feel a little nostalgic seeing an old timer plowing data in the modern era, just be careful not to spook him with any of your new runes.
Somebody had been working on the box logged in as root and accidentally changed the hostname to "-", which royally messed things up.
I think there are multiple RFCs trying to define hostnames and one of them lifted restrictions on digits-only labels because TLDs contain at least one letter so there’d be no confusion with IP addresses. However I was not able to find out who guarantees that there is at least one letter on the TLD level.
- fully qualified hostnames can have a trailing dot; mail domains must never have a trailing dot
- hostnames can be unqualified (dotless), but RFC 2821 accidentally forbade dotless mail domains so they are even more of an interop minefield than you might expect
- NETBIOS hostname conventions (- forbidden, _ allowed) tend to leak into internet hostnames more than mail domains
Both are subsets of domain names. I have found it useful to be pedantic about the differences, but I have worked as a postmaster and hostmaster …
Now if it was mandatory to use, say, brackets (like we do for email) or something...
Country-code TLDs are defined as ISO 3166-1 alpha-2 [1] (with the grandfathered exceptions .ac and .uk). Generic TLDs are subjected to a DNS stability check before approval [2] which, amongst other things, requires that they be either made up of characters a-z only or be valid IDNs.
[1] https://www.iana.org/help/eligible-tlds
[2] https://newgtlds.icann.org/sites/default/files/guidebook-ful..., section 2.2.1.3.
The seminal definition (must start with a letter) was from RFC 952. Then it was lifted in RFC 1123: “One aspect of host name syntax is hereby changed: the restriction on the first character is relaxed to allow either a letter or a digit. […] If a dotted-decimal number can be entered without such identifying delimiters, then a full syntactic check must be made, because a segment of a host domain name is now allowed to begin with a digit and could legally be entirely numeric (see Section 6.1.2.4 [sic]). However, a valid host name can never have the dotted-decimal form #.#.#.#, since at least the highest-level component label will be alphabetic.”
Note that section 6.1.2.4 is completely irrelevant, it looks like a referencing mistake. The later RFC 3696 then calls the rule the LDH rule and says: “There is an additional rule that essentially requires that top-level domain names not be all-numeric.”
But it never says where such a rule comes from.
RFC 2181 references section 6.1.3.5 of RFC 1123 (maybe that’s an old 6.1.2.4) but it doesn’t state that rule either.
This relaxation was for 3com because you couldn’t very well exclude Bob Metcalf of all people in your networking protocol! I remember there was a bit of chatter at the time about a domain beginning with a digit.
I think they were inspired by Johnny Cash’s “A Boy Named Sue” but felt that the whole giving a boy a girls name trope hasn’t aged well (and besides its trendy now anyway.)
https://docs.docker.com/compose/migrate/#service-container-n...
(generated container names went from using underscores to using hyphens)
Why is it that every single input in AWS has some arbitrary character limitations?
Can't do uppercase letters here. No dashes there. Underscores forbidden there.
Even some AWS passwords have forbidden characters in them.
Makes you wonder what is stored as a file on some old NFS volume :).
Because AWS is not one thing.
It's a federation of products built by fabled “two pizza teams” relatively independently for uncoupled velocity, without a heavy dose of "enterprise architecture" imposed on it.
AWS is a group of largely-independent teams.
It's also very much a "thing". Pretty sure all the AWS teams have the same logo on their t-shirts, get yelled at by the same HR department, and get paid by the same company.