Jump to content

Recommended Posts

Posted
When setting up a new server, it even recommends you to use .local, yet everywhere I go people are saying this is a big no no. What do others use for a server that will only be used locally... .school, .server? Thanks
Posted
No, don't use .local. You can't buy certs for it, it still interferes with Apple defaults (but less so than it used to) and it's just a bodge. General advice is to use a legitimate domain now, so that you can get certs and ensure compatibility.
Posted

It's when creating a new windows domain by installing the domain controller services, rather than just a stand alone server that you need to be careful.

 

I would suggest a subdomain of your web domain name. So, for example, a windows domain of lan.schoolnamehere.county.sch.uk, since if you ever want to get a certificate for that domain, it will be a lot easier.

Posted
Thanks for the recommendations. The current server we have running now that has been here for years is on .local and there is no end of problems - slow logins, applications taking a long time to open and just generally slow. We are planning to update the whole system in the summer and will definitely change the domain.
Posted
If starting from scratch then yeah avoid .local but to be honest we have a .local and it hasn't caused us any issues, the Apple stuff isn't an issue these days.
Posted
When setting up a new server, it even recommends you to use .local, yet everywhere I go people are saying this is a big no no. What do others use for a server that will only be used locally... .school, .server? Thanks

 

Yes, see users experience in thread above...

Posted

We used to use .local but changed when I scrapped everything and built a new domain in about 2005. Whilst everything will still work if you use .local you might discover that (like .school) they decide .local will be the latest gTLD meaning anyone can register school.local. You'll also not be able to get "real" SSL certificates for your schoolname.local AD domain but again not really a problem if you use AD's CA for all your local certs.

 

Basically if you already have a network running with .local you can probably leave it as it is and just hope .local doesn't become a TLD, if you are setting something up new then use a domain you have actually registered (even if it doesn't resolve to anything from outside school).

  • Thanks 1
Posted

We've used .local from the day one. No issues whatsoever.

No need for .internal SSL certificates.

use exchange and just change all the URLS to be the external domain and use this on the certificate

Posted
Always used .local here. Never had any issues

 

It doesn't necessarily cause issues per se, it can just make it difficult moving forward to hybrid or full cloud solutions as well as web SSO. So when possible to change it's absolutely the best choice to avoid it.

Posted

10,000+ PCs all on .Local

 

In the past you only needed to not use local if you were going to have your AD externally facing in some manner, but nowadays there's so much control over DNS and Domains that either way will still work fine!

Posted
Basically, there's so many alternatives that there's absolutely no reason to choose .local at all. You can make up a TLD if you want (we did) but choose something else. The subdomain of your actual domain just seems like the best option by a mile.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...