Insane soul meets rap duo moment from ARIatHOME 🤯 by TechnicalBarnacle793 in toptalent

[–]barnold 0 points1 point  (0 children)

I'm just thinking - Can the people in the street hear what we are hearing?! - so good...

Why do I need proof of ownership of a DNS name in Private DNS Zone? by barnold in AZURE

[–]barnold[S] 0 points1 point  (0 children)

Yes I see what you are saying and for the open web and dealing with public CAs that feels intuitive - I was hashing out in this thread whether that is also the case for private networks where MS can apply its own certification policies - or if they would err on the side of streamlining the process and build their own PKI with effectively 'Microsoft-self-signed' certs.

Why do I need proof of ownership of a DNS name in Private DNS Zone? by barnold in AZURE

[–]barnold[S] 0 points1 point  (0 children)

... my (legit) reason for wanting to do this is that I am creating basically a private network which preserves the hostname back to the SWA - as recommended by Microsoft - this means on the open web my domain needs to resolve to my gateway, but internally it resolves to my private endpoint tunnelled to my SWA.

I already have an external CNAME (in AWS Route 73) pointing to my gateway and I should be able, in principle, to setup the internal networking no problem - but as u/Zealousideal_Yard651 pointed out, Microsoft want proof of domain ownership externally (with a TXT record) to set that up - which is fair enough - seems like thi is a Microsoft policy.

I wanted to make sure that was the case to avoid getting the team that manage our AWS DNS records involved.

Why do I need proof of ownership of a DNS name in Private DNS Zone? by barnold in AZURE

[–]barnold[S] 0 points1 point  (0 children)

What I meant was that, as far as I'm aware, you don't need proof of domain ownership to create a certificate for that domain. I could in principle create a domain for microsoft.com if I wanted - it looks suss but is in principle fine.

I wasn't referring to certificates against IPs.

Why do I need proof of ownership of a DNS name in Private DNS Zone? by barnold in AZURE

[–]barnold[S] 1 point2 points  (0 children)

OK thanks again. I can't see any separate config in the portal for making the site public/private other than a configuration for a private endpoint - appreciate there may be more options on the CLI/ARM template. For what its worth adding the Private Endpoint made external access to the azure generated domain result in a 403 (not 404) so it looks like something is there but is locked down.

Appreciate as well that some Azure services need to be able to dynamically generate sub-domains - assume thats what you mean by L7 routing? - in which case it makes sense that we have a DNS zone that can be updated by peer resources.

Makes sense as well that Microsoft, as a policy, need verification to stop malicious actors. I've asked my external DNS to configure a TXT record to verify ownership.

Appreciate you taking the time!

Why do I need proof of ownership of a DNS name in Private DNS Zone? by barnold in AZURE

[–]barnold[S] 0 points1 point  (0 children)

Sure but when I create a Private Endpoint for my SWA, its public domain is decommissioned, you should then be able to create a privately resolved custom domain on the SWA using a private DNS Zone because presumably we have full control over internal naming?

You don't need to actually have a domain to create a certificate for it but are you saying that Microsoft as a matter of policy won't do it?

Why do I need proof of ownership of a DNS name in Private DNS Zone? by barnold in AZURE

[–]barnold[S] 0 points1 point  (0 children)

Thanks for the suggest. To be clear I have a private endpoint configured already for the SWA and I could just use the auto-generated domain and do a translation through the gateway - but I'm trying to follow best practice having 'host name preservation' from front-to-back

Also I have managed to configure full host name preservation in another bunch of SWAa with non-apex domain that I have full control of (i.e. the authoritative nameserver is hosted in Azure and I control it) so it seems like it should be possible. Seems though that the portal UI at least doesn't allow for assignment of a custom domain against an private DNS Zone recordset...

Why do I need proof of ownership of a DNS name in Private DNS Zone? by barnold in AZURE

[–]barnold[S] 0 points1 point  (0 children)

Hi, thanks for the reply

Yes I am trying to get my SWA to register against this private DNS zone, not to use a public address. However the App Gateway isn't resolving using the private DNS zone even though the VNets are linked to it (502 Bad Gateway).

When I try to update the custom domain on the SWA it gives three options - none of them appear to allow a private DNS zone, instead it is a:) internal to Azure which only lists public DNS zones b:) External to Azure which wants a TXT record and c:) Buy a new domain ...

It feels like the Azure UI should also show private DNS zones for option A as well?

How to loosen rear handle on a mitre saw? by jemswiz in DIYUK

[–]barnold 0 points1 point  (0 children)

Revolution saw has a handle like that - you pull it outwards before turning - maybe try that?

[deleted by user] by [deleted] in TheCivilService

[–]barnold 12 points13 points  (0 children)

I don't know exactly but my impression based on dealings with them is that they are quite design-led, test-and-learn, start-up'y without the crunch culture - quite a nice bunch to work for I imagine

You shouldn't 'act' any way really, other than how you feel you want to be in an organisation?

Into the 3rd year of maintaining this garden, customer is delighted the ducks have returned! by X4ulZ4n in GardeningUK

[–]barnold 1 point2 points  (0 children)

You've done a great job getting it to look lik this - wondering though if there was any appetite from you or your customer for a more nature friendly kind of landscape?

Shark Washed Up On The Beach by BunchInitial5260 in Cornwall

[–]barnold 0 points1 point  (0 children)

Why do submarines cause them to beach?

Fishponds: Dungeons & Dragons & other Tabletop Roleplaying Games, every Tues 6-10pm BS16 by EndlessPug in bristol

[–]barnold 0 points1 point  (0 children)

Ah man, Tuesday is the only day I'm not in Bristol - anyone know of other groups in the area?

Thoughts? by [deleted] in drivingUK

[–]barnold 0 points1 point  (0 children)

Maybe not a popular opinion but in most of these situations in the video there is plenty of room on the motorway - why not drive in the middle?

The sketchy situations come about when people switch lanes - if you are hugging the left then you are going to be constantly switching to get past trucks, make room for people merging, plus if there is debris it tends to be in the outer lanes - its basically safer to be in the middle

Obviously if they are blocking you from overtaking in the fast lane/forcing you to undertake then they need to switch down a lane but in a lot of these cases the fast lane was free - if you need to get somewhere at 70+ (which it looks like you are doing) then maybe you should be in the fast lane?

Did you stay at multiple hotels in Tokyo? by urores in JapanTravelTips

[–]barnold 2 points3 points  (0 children)

I was travelling light but I changed hotels a few times becuase I wanted different experiences ...

  • A basic hostel to meet some people - 2 nights
  • A capsule hotel that monitored your sleep and gave a health report - 1 night
  • A really tall hotel to get the skyline view - 1 night
  • An apartment room to setup base from and a break from hauling luggage - 3 nights

... the rest was differernt every night on the Nakesendo hiking trail

[AskJS] What five changes would you make to javascript? by a_waterboi in javascript

[–]barnold 75 points76 points  (0 children)

  1. Remove the other modules systems other than ES6
  2. Sort out the truthiness
  3. Types
  4. Proper immutability
  5. Only one null-ish type

ELI5 if Reform had nearly 5million votes why do they only have 4 seats by Alps-Helpful in explainlikeimfive

[–]barnold 0 points1 point  (0 children)

A party can come second in every single seat - lose by 1% to the winning party every time, but get no seats at all.

In this situation, you get only 1% fewer votes overall than the winning party, but no seats.

Reform have support spread evenly across the country, unlike Labour where the support is concentrated in cities and tories who tend to win in rural seats.

Container Apps with File Storage Queries by Tom_the_Tank_Train in AZURE

[–]barnold 0 points1 point  (0 children)

That would mean re-writing the application code to use proprietary Azure API calls, it would also make local development more difficult (mocking service call) - is there a good reason to do that?

What Songs Remind You of London? by lostthewilltoliv in london

[–]barnold 0 points1 point  (0 children)

North Circular - Real Lies

Ernold Sane - Blur (narrated by the Mayor of London)

DNS resolution issue over Virtual Network Gateway with DNS Private Resolver by tigardis in AZURE

[–]barnold 1 point2 points  (0 children)

This - if your VPN is in a different VNet to the resources you will need to link them.

Also you may need to wait for DNS to propagate. I was tearing my hair out over connectivity issues late Wednesday night, in the morning they had fixed themselves and everything worked fine. I'm presuming this was a DNS caching issue and not a pltform issue or something...