> This is not a service; avoid relying on it for testing and monitoring purposes.
I caught it in review but thousands of others won't.
That ship has sailed I would say.
It's a shame that we don't have any standards for the concerns of canonically testing Internet reachability and for authoritatively redirecting network users to a captive payment portal (without having to resort to ugly hacks that often break with TLS).
But even just having an RFC to yell about is great, thank you :)
So yeah I would pick something simpler for a network access test probably?
It's a static page that every Apple device relies on saying only:
<HTML><HEAD><TITLE>Success</TITLE></HEAD><BODY>Success</BODY></HTML> ~$ ping -c1 1.1
PING 1.1 (1.0.0.1) 56(84) bytes of data.
64 bytes from 1.0.0.1: icmp_seq=1 ttl=56 time=7.89 ms
--- 1.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 7.888/7.888/7.888/0.000 msAs an example, depending on "man -w" not outputting anything to stderr: https://unix.stackexchange.com/questions/405783/why-does-man...
We removed the version and a few customers complained we broke their stuff.
Our back clapping was interrupted by an angry customer phone call. One of our customers had gotten access to our internal schema and had a massive reporting setup in Access solving most of his needs.
I ended up converting his reports using some internal tools we had. Customers will grab anything to give them.
[The caliber and depth of his reports were such I wish we would have bought them instead of making me spend months building out our own reports.]
Learning from customers is some of the best learning you can do. :)
This is probably an even more important principle in the age of LLMs.
Also as a _long_ list of other specialist TLS endpoint configurations if you're interested, which can be arbitrarily combined, see https://testserver.host/#tls-endpoints.
That gives neat tricks like https://tls-v1-2--expired--incomplete-chain--http2.testserve...: only accepts TLS 1.2, then sends an expired certificate but fails to send the intermediate cert for the chain (so the client must infer it) and then negotiates HTTP/2 for the connection on top. Fun!
The web page at example.com is maintained as a courtesy by IANA in order to explain the purpose of the example.com domain to wayward humans.
In the nomenclature of RFC 2119, one MUST NOT design computer systems that rely on the correct operation of an HTTP server at that domain. [0] Plus, it's _really_ rude to pound on a small-scale service being provided as a courtesy... go hit the home page of a tech megacorp (such as Microsoft or Google) or the status page for a major CDN (such as Cloudflare or Akamai) instead!
[0] I expect that someone here will want to pop up with a "gotcha" where they say something like "Oh, but IANA's email says that automated use is strongly recommended against, rather than prohibited and besides, they can't actually stop me from doing it!". To that, I reply "Sure, and standards-writers can't actually stop implementers that do the profoundly antisocial thing and do the things they MUST NOT. As any adult who's been paying attention to the world around them throughout their lives knows, there's only so much you can do to stop people who are very determined to be enormous assholes.".
Would you settle for any old static page served by Cloudflare? For instance, example.com? https://bgp.tools/dns/example.com
Maybe Cloudflare gives them a good rate, or is donating service, but it's also possible or even likely that IANA is just using Cloudflare as a vendor, and therefore is paying for all the traffic, which is why they don't want people relying on it or hammering it all the time
In the nomenclature of RFC 2119, one MUST NOT design computer systems that rely on the correct operation of an HTTP server at [example.com.] Plus, it's *_really_* rude to pound on a small-scale service being provided as a courtesy.Much too big for metered data, full of ads, and importantly they all mandate HTTPS these days, which breaks my use case of forcing a captive portal on paid/login-gated Wi-Fi to render.
example.com is (unfortunately for the IATA) the almost perfect "can I reach the Internet" service: It's unlikely to go away, supports HTTP, is fairly small, easy to remember, and I don't care if a captive portal poisons my DNS cache with a fake response temporarily.
/s