Skip to main content
Resources

向IT人士发布的域名冲突识别和缓和措施指南

立即下载

《供 IT 专业人士使用的域名冲突识别与缓解指南》(1.1版) [PDF, 476 KB]

摘要

域名冲突有可能会给使用私营域名空间的企业和组织带来无法预料的后果。本文档列出了一些潜在后果,并给出了改变在企业和组织内部使用私营域名空间方式的最佳实践。

在域名空间下,如果一个私营顶级域名正在成为(或已经成为)一个全球域名系统下的顶级域名,则最佳缓解措施是将该域名空间迁移至全球域名系统下的一个根域。对于使用搜索清单下的简写域名的域名空间来说,其缓解措施是不再使用搜索清单。推行这些缓解措施还需要长期监控私营网络,确保停止使用所有可能导致域名冲突的情况。

解决域名冲突的一个全面缓解措施是,在任何使用域名的情况下都采用完全合格的域名 (FQDN)。对于已经使用全球域名系统的网络来说,这意味着不再使用搜索清单。对于使用私营域名空间的网络来说,这意味着该私营域名空间应属于全球域名系统的一个根域,且不得使用搜索清单。

Domain Name System
Internationalized Domain Name ,IDN,"IDNs are domain names that include characters used in the local representation of languages that are not written with the twenty-six letters of the basic Latin alphabet ""a-z"". An IDN can contain Latin letters with diacritical marks, as required by many European languages, or may consist of characters from non-Latin scripts such as Arabic or Chinese. Many languages also use other types of digits than the European ""0-9"". The basic Latin alphabet together with the European-Arabic digits are, for the purpose of domain names, termed ""ASCII characters"" (ASCII = American Standard Code for Information Interchange). These are also included in the broader range of ""Unicode characters"" that provides the basis for IDNs. The ""hostname rule"" requires that all domain names of the type under consideration here are stored in the DNS using only the ASCII characters listed above, with the one further addition of the hyphen ""-"". The Unicode form of an IDN therefore requires special encoding before it is entered into the DNS. The following terminology is used when distinguishing between these forms: A domain name consists of a series of ""labels"" (separated by ""dots""). The ASCII form of an IDN label is termed an ""A-label"". All operations defined in the DNS protocol use A-labels exclusively. The Unicode form, which a user expects to be displayed, is termed a ""U-label"". The difference may be illustrated with the Hindi word for ""test"" — परीका — appearing here as a U-label would (in the Devanagari script). A special form of ""ASCII compatible encoding"" (abbreviated ACE) is applied to this to produce the corresponding A-label: xn--11b5bs1di. A domain name that only includes ASCII letters, digits, and hyphens is termed an ""LDH label"". Although the definitions of A-labels and LDH-labels overlap, a name consisting exclusively of LDH labels, such as""icann.org"" is not an IDN."