Latest News

Showing posts with label Custom Domains Ownership Verification. Show all posts
Showing posts with label Custom Domains Ownership Verification. Show all posts

Adding Ownership Verification For Your Custom Domain? Examine The Error Display

Sometimes, you have to step outside the box, to complete a Blogger blog task.

The task of adding domain ownership verification, to a custom domain purchased using "Buy a domain", is one example of stepping outside the box. I advise people that tweaking DNS settings, in general, is a task best undertaken by someone with "Advanced" experience with Blogger custom domain publishing.

Unfortunately, domains purchased using "Buy a domain" are occasionally subject to incomplete setup - and correction of an incomplete setup involves republishing the domain. And republishing the domain requires verification of domain ownership.

To a first time domain owner, the task of verifying domain ownership is surely a bit scary.
We have not been able to verify your authority to this domain.

This initial accusation is followed by the instructions
On your domain registrar's website, locate your Domain Name System (DNS) settings and enter the following two CNAMEs:

The challenge, for many, is getting to the Domain Name System (DNS) settings, aka the Zone Editor.
  1. Login to Google Apps.
  2. Find the instructions for logging in to the registrar's website.
  3. Login to the registrar's website.
  4. Find the registrar's Zone Editor wizard.

Having completed Steps #1 - #4, adding the "CNAME" is almost an anticlimax. See the instructions?


On your domain registrar's website, locate your Domain Name System (DNS) settings and enter the following two CNAMEs:

Name, Label, or Host field Destination, Target, or Points To field

www ghs.google.com

i7vgls457wxc gv-fbz2zptam3ucji.dv.googlehosted.com

Once you have access to the Zone Editor, look for "www", added by "Buy a domain". See how it's formatted, in the display?
  • Add the second "CNAME", mirroring the format and syntax of the first.
  • Note the example of the second, shown here as "i7vgls457wxc" - though when you setup your domain, you will surely see different values for both "i7vgls457wxc" and "gv-fbz2zptam3ucji.dv.googlehosted.com")
  • Refresh the Zone Editor list, and compare the "www" and "i7vgls457wxc" entries.
  • If you added the new entry properly, the format and syntax, of the two entries, will be identical.

Having successfully added your new "CNAME", go back to the Blogger Publishing wizard, and publish the blog to the domain. Finally, wait a few days for Transition to expire - and while you wait, plan what to do, next.

>> Top

Confusion About Advice "If you bought your domain name from Blogger, you won't need to create a CNAME record."

To Blogger blog owners who want their new non BlogSpot URLs to display their blogs, this conflicting bit of advice provides only confusion and doubt.
If you bought your domain name from Blogger, you won't need to create a CNAME record.

That advice was written to advise the use of the Blogger "Buy a domain" wizard, which provides non BlogSpot URLs for Blogger blogs, through a simple 15 minute purchase process. In September 2012, that simple process changed, slightly.

If you are trying to re publish your blog to a non BlogSpot URL - and you are seeing an "Error 12" / "Error 32", or similar message in the Publishing wizard display - you need to add a second "CNAME" address to your domain.

The new "CNAME", added in September 2012, allows you to verify ownership of the domain to the Publishing wizard. Any time you re publish your blog to a non BlogSpot URL, you have to verify ownership. This prevents people who are not you from deviously publishing their Blogger blog to your domain.

If you are reading this, and you are the owner of any website which provides advice on how easy it is to purchase a non BlogSpot URL for a Blogger blog - and part of your advice mentions
If you bought your domain name from Blogger, you won't need to create a CNAME record.
Please, edit your instructions to reflect the reality of domain ownership verification.

If you are reading this, and you know of a blog or website which provides the confusing advice
If you bought your domain name from Blogger, you won't need to create a CNAME record.
let us know, below.

Try and reduce the confusion, when people have to re publish their blog, after using the Blogger Publishing wizard - or possibly after buying directly from a registrar. Help us, to help you.

>> Top

Adding The Domain Ownership Verification "CNAME", For A Non Root Virtual Host

Now that the new required custom domain publishing ownership verification feature has been out for several months, we are seeing it used in domains with multiple virtual hosts.

A few blog owners are even publishing their blogs to non root virtual hosts - and here we are seeing a new reason for a persistent Error 12 / 32, which just can't be solved.
I have followed all of the instructions, and I am still seeing Error 12. Help!

The "Advanced settings" Error 12 instructions - now provided on screen instead of requiring the blog owner to open an external "Settings instructions" document - require careful examination.

We have to look very closely at this variation on the publishing instructions, when publishing to a non root virtual host.
Advanced settings

http://www.blog.mydomain.com

We have not been able to verify your authority to this domain. Error 12.
On your domain registrar's website, locate your Domain Name System (DNS) settings and enter the following CNAMEs:

  Name, Label, or Host field    Destination, Target, or Points To field

  www                           ghs.google.com

  xxxxxxxxxxxx               gv-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.domainverify.googlehosted.com.

See our detailed instructions on providing CNAMEs for various registrars or see the full settings instructions for more details.
Taking these instructions at face value, and adding a "CNAME" record of relative Name value "xxxxxxxxxxxx" to verify the publishing address of "www", the blog owner is going to continue to see an "Error 12" or "Error 32" for a long time.

We have to look, very carefully, at the "Advanced settings" publishing address - in this case
www.blog.mydomain.com
In the registrar's Zone Editor (aka "Domain Manager" wizard), we see the Name value entered as an address relative to the domain root.
  • With "www" entered for the Name, this provides a published address of "www.mydomain.com".
  • With "www.blog" entered, this provides a published address of "www.blog.mydomain.com".

The Name value, for both "CNAME"s, as specified in the "Advanced settings" instructions, is relative to the domain root.
  • A Name of "www", to provide a published address of "www.blog.mydomain.com", should be entered as "www.blog" in the Zone Editor.
  • Similarly, a Name of "xxxxxxxxxxxx", to provide a published address of "www.blog.mydomain.com", should be entered as "xxxxxxxxxxxx.blog" in the Zone Editor.

Entering the domain ownership verification "CNAME" relative to the published URL allows non root virtual hosts to be used, in the domain, without chance of conflict.
  • To publish to "blog.mydomain.com", we add a domain ownership verification "CNAME" of "xxxxxxxxxxxx.mydomain.com" (with the proper value of "xxxxxxxxxxxx").
  • To publish to "www.mydomain.com", we add a domain ownership verification "CNAME" of "xxxxxxxxxxxx.mydomain.com" (with the proper value of "xxxxxxxxxxxx").
  • To publish to "www.blog.mydomain.com", we add a domain ownership verification "CNAME" of "xxxxxxxxxxxx.blog.mydomain.com" (with the proper value of "xxxxxxxxxxxx").
We simply have to read the "Advanced settings" instructions, and enter the Name values in the Zone Editor, considering the context of the instructions.

>> Top

To Republish A Custom Domain, You Do Have To Add A Second "CNAME"

One of the challenges of using Blogger involves following the instructions.

Blogger / Google personnel provide Help instructions which are not always updated - sometimes they simply write a new Help instructions document, leaving the old Help instructions in place.

The policy of leaving old Help instructions in place - and sometimes conflicting with new displays and procedures - occasionally causes confusion. One scenario where this causes a problem is in publishing or re publishing a blog to a custom domain.
I've seen instructions that when you buy a domain from Blogger / Google, using "Buy a domain", you won't need to create a CNAME record.

One of the advantages of using "Buy a domain" is the ease of setup. If you use "Buy a domain", you don't have to bother with any of the details. This is generally - but not always - true.

(Update 2013/09): The second "CNAME" won't be required, in all cases. If you don't see instructions for adding a second "CNAME", focus your efforts on getting the domain working, with righteous base DNS addresses,

Sometimes, even using the "Buy a domain" wizard can later present a problem.

One of the known problems with "Buy a domain" results in a partially setup domain - and with a partially setup domain, you may have to re publish the blog to the domain, to get the new domain to work completely.

To re publish the blog, you have to verify your ownership of the domain - even if you previously used "Buy a domain". And the additional step of adding a second "CNAME" overrides the old Blogger Help instruction
If you bought your domain name from Blogger, you won't need to create a CNAME record.
When you are instructed to re publish the blog using "Advanced settings", that 's what you must do. And, when "Advanced settings" contains instruction to add a second "CNAME", then please - add a second "CNAME".

>> Top

Blog Owners Seeing "Error 14" Or Similar Symptom, When Attempting To Publish To A Custom Domain URL

We're seeing a small but steady flood of reports, in Blogger Help Forum: Something Is Broken, from blog owners attempting to publish their blogs using a custom domain URL.
I am not able to redirect my blog from blogspot to my own domain! Blogger is giving me the error
We have not been able to verify your authority to this domain. Error 14.

This specific problem has been observed numerous times in the past, ever since Blogger added the domain ownership verification process to the custom domain publishing feature. Problem reports require careful diagnosis, involving examination of the basic DNS addresses setup with the registrar, to verify the "Error 14" as the primary problem.

Because careful diagnosis is required, for each case reported, we're not adding a Rollup Discussion in the forum. Instead, we request that each blog owner, observing this problem, post her / his problem report in a topic started for that purpose, by himself / herself only. This will allow us to inventory this problem properly, and assist Blogger Engineering in isolating and fixing this problem promptly, so the blog owners can get on with the after publishing process.

Reports of this problem appear to have started in volume late Saturday, 11/17, Pacific time - though some reports, examined in detail, mention the problem initially observed several days ago. The initial volume of the problem appeared to come from SouthEast Asia - but as additional reports were posted, we see Europe and the Americas apparently represented.

Blogger Engineering is now aware of the problem, and will investigate. We'll continue to monitor the forum topics, and to post an initial advisory FAQ, as a response to the reports observed - when reports contain clear evidence of the "Error 14" being a primary symptom. Please monitor that FAQ, and this post, for any ongoing updates.

>> Top

Observe DNS Address Entry Conventions

One of the more frustrating steps involved in setting up a custom domain comes with entry of the DNS addresses, into the domain host or registrar's DNS dashboard aka zone editor.

Whether you are setting up a new domain, just purchased directly from a registrar - or re publishing an existing domain, purchased using "Buy a domain" - the addition of the proper DNS addresses is essential to successful custom domain publishing.

Sometimes, you just can't get the zone editor to accept what you are provided by "settings instructions". Other times, you enter the proper values, your update is accepted by the zone editor - and the Blogger Publishing wizard rejects your attempts.

Even after repeated attempts to publish your blog to the domain, you can get another "Another blog ..." error - maybe an "Error 12" or variant.

You may see "Another blog ...", in spite of your efforts.

This may be in spite of the fact that you are retrieving a new "Name" / "Destination" periodically from "settings instructions", and dutifully adding or updating the domain ownership verification "CNAME" Alternately, you may just be adding the base DNS "A" or "CNAME" addresses.

There are syntax conventions, for both "Name" and "Destination".

Every blog owner needs to realise that the zone editors have conventions for entry of both the "Name" ("Label" / "Host"), and the "Destination" ("Target" / "Points To") values in the DNS address records ("Zone Entry"). The conventions used will vary, from zone editor to zone editor - and the differing conventions will affect the success of your domain publishing attempts.

You may see the results of an error immediately, or later.

In some cases, the zone editor will immediately reject your entry, if you mis enter the value. In other cases, the entry will be accepted - but Blogger will reject your attempts to publish. Either scenario can be caused by mis entry of either the "Name" or "Destination" value, and your overlooking the differences between "absolute" vs "relative" addresses.


GoDaddy adds the trailing ".", automatically!


This problem is observed by some as the mysterious "period" / "full stop".

  • If you omit the period, and it is required, the Zone Update may take place - but the Blogger Publishing wizard will overlook or reject the resulting DNS address.
  • If you add the period, and it is not allowed, the zone editor will reject your attempt.

This can happen for either the "Name" or "Destination" value.

The problem cannot be resolved by Blogger / Google.

Here, I will note that this problem is one which neither Blogger nor Google can resolve. Whether you purchased the domain using "Buy a domain" - or directly from the registrar - if you use the DNS dashboard / zone editor wizard provided by the DNS Host / Registrar, your understanding of the conventions observed by the zone editor are your responsibility.

You, the domain owner, must determine the syntax requirements.

There are requirements for entering the "Name" and for entering the "Destination" values - and you have to find out, and adjust to, each requirement.

For some zone editors, with a domain of "mydomain.com", you will probably enter the published address - "www.mydomain.com" - as "www". This says that the "Name" value is "relative" to the domain URL.

You can't enter the domain root, "mydomain.com", as "mydomain.com" - as this would give you a DNS address of "mydomain.com.mydomain.com" - and yet another "Another blog ..." error. You will probably need to enter the domain root as "@" or a similar special character. This, too, is your responsibility to verify.

With other registrars, "mydomain.com" is entered as "mydomain.com". Nobody but the registrar can tell you which case affects your domain.

If you require assistance, be prepared to provide details.

If you are asking for help in Blogger Help Forum: Something Is Broken, and I am advising you, I'll be asking you for three essential values.

  1. The BlogSpot URL.
  2. The domain URL.
  3. The "Name" / "Destination" values provided by the "settings instructions" document, or "Error 12" et al display.

None of these values are optional - and strict attention to accuracy and detail, in your reply, is essential.

If you redact any portion of what you provide, I'll only ask you again, to not redact details. And I'll repeatedly advise you to always copy and paste - never type by eyeballing - both the long and short tokens ("Name" / "Destination") in the "Error 12" et al displays.

Use Third Party DNS Servers, For 1And1 Domains

Not all registrars are able to support the new Blogger domain ownership verification requirement.

Some registrars won't allow a second "CNAME" in the same subdomain - and others can't handle the excessively long target address. Ever since Blogger added domain ownership verification, we've been seeing complaints from some blog owners, who have purchased domains directly from registrars who can't provide the required DNS addresses on their servers.

Even though not all registrars have DNS servers that will provide the right DNS address entries, most registrars will allow us to use third party DNS servers. The use of publicly available DNS servers, which can provide the required DNS addresses, will eliminate the need to transfer domain registration - when the registrar is unable to provide the right DNS addresses, using their own servers.

If you're trying to setup your domain, purchased from 1And1 or a similar registrar, you need only to setup a suitable third party DNS server.

If your registrar limits their services, use a third party DNS host.

Use of a third party DNS host will also help victims of the eNom DNS Infrastructure problem - and those who purchased Name Registration, directly from the registrar.

An explanation of the solution is provided, by Blogger Engineers.

Marc Ridey, of Blogger Engineering, provides How to setup your Blogger blog with a custom domain from 1and1.com, and adds three simple steps to the normal third party registrar domain setup process.

  1. Setup a (free) ClouDNS account.
  2. Setup your normal DNS addresses (plus the domain ownership verification "CNAME", if required) in ClouDNS, using the ClouDNS Domain Manager wizard.
  3. Setup your domain, using your registrar's domain manager wizard, pointing to the ClouDNS DNS servers.

Do each step, one at a time - and check your work.

When you update DNS addresses, such as adding additional hosts, and ownership verification, you use the ClouDNS Domain Manager wizard.

Note the caveat, for advanced domain owners.

If you are using your third party registrar because you have non Blogger services (a web site, email, files, or other service) hosted by the registrar, please note the warning by Marc!
Warning: If you are using 1and1 hosting services to display a website as well as a Blogger blog, these instructions will disable the website. Please post a comment with your website address and I'll check how these instructions must be updated. If you're using eMail, remember to complete the optional eMail step.

Note that ClouDNS, when setup, may offer the option to redirect the domain root (aka "naked domain") to the "www" alias (or whatever DNS address you may setup). For best results, ignore that option, and use the Blogger or Google Apps redirect.

There are still only three acceptable DNS models - use of ClouDNS, or any similar third party DNS host, will not change that.

This may not be a perfect solution - but it will produce a stable domain.

This may not be an ideal solution for the problem - it introduces a bit of complexity into the domain setup process. This will allow owners of newly purchased domains from 1And1, Network Solutions, and others to get their domains verified, and get their blogs online again.

Since this starts with blog owners who elected to purchase their domain directly from a registrar - and setup the domain themselves - maybe it's not too much, technically.

http://blogging.nitecruzr.net/2012/11/use-third-party-dns-servers-for-domains.html Use Third Party DNS Servers, For Domains Registered By 1And1, And Similar Registrars

No Immediate Solution For 1And1 Customers With Unverifiable Custom Domains

Since Blogger restored Custom Domain Publishing last month, with the new domain ownership verification requirement, there have been a few complaints from customers of some registrars who just can't provide the required DNS address record for ownership verification.
My registrar says that I can't have two "CNAME" records in the same subdomain.
and
My registrar's domain manager wizard displays an error saying "Address too long.", when I try to add the "CNAME".
Blog owners contacting the registrar, and asking for help, are generally told
That's Blogger's problem!

(Update 2012/11): Blogger Engineering has provided a workaround for this problem, with any uncooperative registrar, such as 1And1 - use of a (free) third party DNS host.

What not all blog owners realise is that the new "CNAME" must be just that - there is no substitute here.

Some of the more patient blog owners have made various suggestions, to get us moving towards a solution.
  1. Blogger Support needs to work with the problem registrars, and convince them to improve their service.
  2. Blogger Support needs to provide an alternate ownership verification procedure - maybe equivalent to the Google Webmaster Tools meta tag verification procedure.
  3. Blogger Support needs to clean up their "CNAME" setup instructions, and remove mention of the problem registrars - so future blog owners won't choose these registrars to host their domains.


About 3/4 of the problem reports have come from customers of 1And1. Using that registrar as a starting point, I contacted Blogger Support and suggested the 3 alternatives, outlined above. The Blogger Engineer responding seemed to think that only suggestion #3 - cleanup of the per registrar "CNAME" addition instructions was immediately possible.

It's possible, then, that we will eventually see less problem reports from 1And1 customers - and hopefully others - as Blogger Engineering cleans up their domain setup instructions. The current customers of uncooperative registrars, unfortunately, are unlikely to see relief, for the near future.

This is an unfortunate situation for these 1And1 customers. The best solution for them is to move domain registration to another, more helpful, registrar. Unfortunately, most registrars don't allow domain registration transfers immediately after initial purchase - waiting periods of 30, or even 60 - days are normal. And domain registration fees are not refunded.

This leaves new 1And1 customers, and similar victims, with several options - none of them good. First, publish the blog back to BlogSpot, so the blog can be accessed by existing readers.
  • Wait 30 - 60 days, with the domain dead, then transfer domain registration to a more helpful registrar and activate.
  • Purchase a second domain, from a more helpful registrar.
  • Forget about custom domain publishing.
The latter alternative has motivated several victims to choose a fourth alternative.
  • Move their blog hosting to a different service.
None of this can be good for Blogger's reputation.

>> Top

Ownership Verification Is Not A Standard Process

With the recently restored custom domain publishing feature, and the new domain ownership verification requirement, comes various queries from blog owners unable to verify domain ownership, and to publish their blog to their custom domain.
Can I use a "TXT" file, instead of a "CNAME"? My registrar suggests this as an alternative.
and
Why do I need this? My domain was working, just fine, before I had to re publish the blog!
Not all blog owners understand the historical need for verifying domain ownership.

(Update 2013/09): The second "CNAME" won't be required, in all cases. If you don't see instructions for adding a second "CNAME", focus your efforts on getting the domain working, with righteous base DNS addresses,

Ownership verification, allowing one to setup a given relationship between various Internet resources, varies according to the need of the application which uses the Internet resources in question.

Domain ownership verification, to provide urgently needed custom domain security, is simply one example of ownership verification, in general.

  • If you have file / folder control of a web site, you may be able to add a specific named file, to the website. The application in question can check for the presence of the required file (possibly one with a complex name).
  • Some applications such as Webmaster Tools can, alternatively, use a meta tag in the blog header, to verify blog ownership. Again, the tag will have a complex name / value.
  • To verify domain ownership, Blogger requires you to install a unique "CNAME" as a DNS address into your domain. The "CNAME" will contain two complex values, provided only to the blog / domain owner.

In either case, the complex values provide an encrypted certificate, which is specific to the application and to the blog / website, which is provided only to the owner of the blog / domain / website.

The named file is a simple solution - both to setup and to verify - but using it requires that the blog / website owner have the ability to setup a specific named file, in a specific folder, containing the certificate. Blogger does not provide file / folder control, so that solution is out - for any application which is to be used with Blogger blogs.

Applications (such as Webmaster Tools) which work with Blogger blogs, and similar websites, can use meta tag verification. This requires that the blog owner add a meta tag in the blog header, with a complex tag name / value. The tag name / value contains the certificate in question.

Blogger blogs can use neither a named file, nor meta tags, for domain ownership verification. There is no domain header, where meta tags could be installed - and again, Blogger does not provide file / folder control.

To verify domain ownership, Blogger requires the domain ownership certificate to be installed as a unique "CNAME" DNS address. The complex values in the "Name" and "Destination" values of the "CNAME" contain the encrypted ownership certificate. Since the specific certificate values, for each different domain, are provided to the blog owner (in the "settings instructions" document) - and the "CNAME" can only be installed by the domain owner - when the proper "CNAME" exists, the blog owner and domain owner are certified to be one person.

The unfortunate problem with "CNAME" based domain ownership verification is that not all registrars can provide the required "CNAME"s, and can provide "CNAME"s with long "Name" or "Destination" values. This does not mean that the Blogger solution, for domain ownership verification, is faulty.

It's possible that Blogger Engineering has considered a second option for domain ownership verification, which will be added when - or after - the "Buy a domain" wizard is updated to support automatic domain ownership verification. It's also possible that blog owners, who use specific registrars which are unable to provide the required "CNAME", will be forced to abandon their current registrar.

Whatever the case, it's likely that the "CNAME" based domain ownership certificate was the best possible solution, to solve the urgent security problem, and allow custom domain publishing to be restored last week.

You Do Have To Add A Second "CNAME"

We're seeing evidence of confusion, in Blogger Help Forums, from blog owners who read the out of date instructions, about using "Buy a domain".

We see considerable confusion, where people using that feature insist that they don't have to add a "CNAME". In other cases, people using the Blogger / GoDaddy DNS Configuration wizard will think that the second "CNAME" is being added for them.

(Update 2013/09): The second "CNAME" won't be required, in all cases. If you don't see instructions for adding a second "CNAME", focus your efforts on getting the domain working, with righteous base DNS addresses,

Right now, everybody has to add their own domain ownership verification token - aka the second "CNAME".

We're hoping that the (currently offline) "Buy a domain" wizard will automatically add the domain ownership verification - just as it adds the other DNS addresses - but we'll see that, when we see it. The Blogger / GoDaddy wizard should, likewise, take care of this, on your behalf - but right now, it doesn't. The bottom line? If you go to the Publishing wizard, and see
Error 12
or a variant, after typing the domain URL into "Advanced settings", better get busy.

What not all blog owners realise is that the new "CNAME" must be just that. Blogger is not being arbitrary, or pedantic, in requiring precision.
  • It must be a "CNAME". A "TXT" will not work.
  • The "Name" value must be specified precisely as supplied (Plus or minus the trailing period!).
  • The "Destination" value must be specified precisely as supplied (Plus or minus the trailing period!).
You cannot fly by the seat of your pants, and try what seems like it might work, as a "substitute". Webmaster Tools provides a blog ownership verification process - which may, or may not help.

If the registrar for your domain does not allow the addition of this "CNAME", you will need to setup a third party DNS host for your domain. You do have to add this second "CNAME" - even if this may conflict with older Blogger Help instructions.

>> Top

The New "CNAME" Needs To Be Added, And Used, Promptly

One oddity, observed by a few blog owners, is that even after adding the "CNAME" to verify domain ownership, not every blog owner is able to see theirs successfully verified.
I added both "CNAME"s - and I'm still getting "Error 12" when I try to publish.
There are several "common sense" rules, that not everybody observes.
  1. The new "CNAME" can't use the example values.
  2. The new "CNAME" has to be a "CNAME". Don't let your registrar add a "TXT" instead.
  3. The new "CNAME" has to be specific to the URL in question. Enter your published URL precisely, into "Advanced settings".
  4. The new "CNAME" has to be added with attention to domain manager address entry convention.
Even with these rules observed, there are still a small handful of unsuccessful blog owners, seeing "Error 12" - or "Error 32".

One of the possible reasons for these last few hold outs, I believe, relates to timing.

Let's consider the "CNAME" setup process.
  1. Get the "Name" / "Label" / "Host" and "Destination" / "Target" / "Points To" values, for your unique blog / domain.
  2. Add the new "CNAME" to your domain.
  3. Publish the blog to the domain URL.


In the "settings instructions" document, How do I use a custom domain name for my blog?, we are instructed to
wait about an hour for your DNS settings to activate
In various other instructions, you will typically see
Wait for up to a day, for settings to be updated
or similar miscellaneous waiting instructions.

Besides the waiting factor, there's a "negative waiting" factor. Several blog owners have observed that the "Name" / "Label" / "Host" and "Destination" / "Target" / "Points To" values, for their unique blog / domain, seems to change, from day to day. This tells me that the ownership verification "certificate" (which is what the "Name" / "Label" / "Host" and "Destination" / "Target" / "Points To" values provide), like most security certificates, has a limited use period.

If you get the certificate in Step #1 above, you have to use the certificate in Step #3 reasonably promptly after doing so. If the certificate for your domain expires within a 24 hour period, then you have, at most, 24 hours between Steps #1 and #3. In other words, you get 24 hours to re publish your domain - after you add the new "CNAME" - and that's including the period that you
wait about an hour for your DNS settings to activate
It's alternatively possible that the expiry is based on an arbitrary time of day - not 24 hours after being issued.

Whatever the nature of the expiry (absolute and arbitrary - or relative to time of issuance) the existence of an expiry time is normal, for a well designed security certificate. By giving the certificate a temporary lifetime, it becomes less useful to would be hijackers and similar miscreants.

So, you may not really benefit from waiting a day to re publish your domain - unless you like seeing "Error 12" (possibly "Error 32"), repeatedly, when you try to publish. Personally, I would wait an hour at the most, after Step #2, before trying Step #3. I would then retry Step #3 hourly, until successful. If you have more patience than I, fine.

>> Top

What Is This New "CNAME", Anyway?

Ever since Blogger finally restored the custom domain publishing feature, blog owners have been asking about the addition to the domain setup process - the new "CNAME".
Do I really need this? My old blogs don't have it, and they are fine.
and
My registrar won't let me add a second "CNAME" - they allow one "CNAME" / domain (my "www").
and
My registrar won't allow long addresses, such as what you have for "Destination" / "Target" / "Points To".
And we are learning that this requirement is going to be a problem for blog owners using some registrars, who can't provide this "CNAME" in their customers domains.

In technical terms, the new "CNAME" is an ownership certificate, provided in a one way encryption.

If you have WiFi in your home (likely) - and are using encryption (hopefully), you have a similar one way encrypted certificate - the WPA / WPA2 key / passphrase. For an allegorical (easy to read) discussion about certificate encryption, see Designing an Authentication System.

Only the blog / domain owner know the values and can install the certificate.

Only you, the blog owner (and anybody who you trust, on your behalf), are able to install the certificate for your domain, into your domain DNS addresses. Only you have access to both

  • The Blogger dashboard Publishing wizard.
  • The zone editor wizard provided by the registrar.

This helps Blogger help you keep your domain under your control - as long as you pay the yearly registration fee for your domain.

The certificate contains 3 unique values.

The domain ownership certificate has 3 keys.

  1. A private key, which Blogger appears to change regularly (some say daily) - and one which they control.
  2. The BlogSpot URL.
  3. The domain URL (entered in "Advanced settings").


It has two significant values.

  1. "Name" / "Label" / "Host". This is now known as the "short token".
  2. "Destination" / "Target" / "Points To". This is now known as the "long token".

Note the three labels used to identify each "value" - which reflect the diversity of the registrars which may provide DNS hosting for our domains (when they are able to fulfill our specific needs). When you look at the Domain Manager wizard for your domain, you may see any of the three (possibly, others) used - as there is no authoritative label for these two DNS address components.

Compare the two "CNAME"s, in structure and value.

Let's look at the two "CNAME"s, together, so you can compare the similar structure. Note the need to get the syntax, which can vary by registrar, absolutely correct.

This is the first "CNAME" - the "www" alias DNS address. This "CNAME" is identical for all Blogger blogs, using the asymmetrical DNS address convention.

  1. "Name" / "Label" / "Host". www
  2. "Destination" / "Target" / "Points To". ghs.google.com

This is the second "CNAME" - the domain ownership certificate. This "CNAME" will vary, for each different domain. Here we see the original example (which has since changed).

  1. The "short token". vptre6sub6jm
  2. The "long token". gv-g47p6dir6kfenz.dv.googlehosted.com


See the final period, at the end of the "Destination" / "Target" / "Points To" address, below? It's not in the example, above. Be very careful here, some registrar's will automatically insert the "." for you - and if you insert it also, you'll have a problem. Other registrars will need you to add it - and if omitted, you'll have a problem. Regardless, its presence, in the final product, is essential.

gv-g47p6dir6kfenz.dv.googlehosted.com.

You can verify specific certificate values.

If you know the value for the short token, you can Dig and extract the long token - when the second "CNAME" is properly setup.

Once you provide the above examples to the Domain Manager, the following two DNS addresses are generated and added to the domain server. The "3600" represents the TTL, a setting provided by the registrar. The "IN" is part of the Dig log extract syntax.

www.mydomain.com. 3600 IN CNAME ghs.google.com.
and
vptre6sub6jm.mydomain.com. 3600 IN CNAME gv-g47p6dir6kfenz.dv.googlehosted.com.
Both "CNAME"s point to specific Google servers. The second "CNAME" is only slightly obscure. Both "CNAME"s are essential (when required - but only when required).

  1. The first lets you, and your readers, view your blog.
  2. The second lets Google verify that you own the domain, and you should be allowed to publish your blog to the domain URL.

Nobody but you, the blog owner, will ever know the values of the tokens. Nobody but you, the domain owner, can install that "CNAME" into the domain DNS addresses. If DNS resolution of the short token address points back to the right Google server, then you, the owner of the blog, and the owner of the domain are verified as the same person. And the ownership certificate is "decrypted", using DNS name resolution.

  • Short token. vptre6sub6jm
  • Long token. gv-g47p6dir6kfenz.dv.googlehosted.com

Some certificate values are temporary.

Since the private Blogger key changes regularly, if anybody learns what tokens you used, in the short 3 step domain verification process, the values will have likely changed, and their time will have been wasted. Your blog and domain remain your blog and domain.

So, do the necessary. Blogger provides instructions, specific for 7 known registrars - and a general purpose instruction for others, in Google Help: Create a CNAME record for my custom domain. If their instructions conflict too much with your reality, try setting up third party DNS hosting.

  1. Get the short token and long token values, for your unique blog / domain.
  2. Add the new "CNAME" to your domain.
  3. Publish the blog to the domain URL.

That's it (subject to observed timing issues). You are now done with the domain ownership verification process, and with these encrypted values. Start planning the migration - this will happen faster than you think. And it is your responsibility, to get this done.

Custom Domain Publishing Is Back - And With A New Detail

After a very stressful week, Blogger Engineering has restored the custom domain publishing option.
Last week we encountered an issue that could affect Blogger users in the process of configuring a custom domain, during the verification of ownership of domains between the provider and Blogger. Blogs with previously configured custom domains were not affected.

With the reason for disabling custom domain publishing being security, Blogger Engineering has added a step in the publishing process, to add a random token as a "CNAME", and verify your right to publish to your domain, from Blogger. You get the random token from the "settings instructions" document, "How do I use a custom domain name for my blog?".

See the URL of this (hypothetical) settings instructions document?

http://www.blogger.com/custom-domain-instructions.g?cnameVerificationToken=VPTRE6SUB6JM+gv-G47P6DIR6KFENZUFIFYWSQJJPDYFZK4SQMUUIUFLYLCQD4OIGDFA.domainverify.googlehosted.com.&domain=www.hotspotshield.com

This is an example. If you're registering a domain other than "www.hotspotshield.com", you're going to have a different token - which should be a function of the BlogSpot and domain URLs. You'll also note another case sensitivity issue - "www.hotspotshield.com" and "www.HotSpotShield.com" will produce completely different tokens.
Now, it's an out of date example.
http://www.blogger.com/custom-domain-instructions.g?cnameVerificationToken=GKBPLXBRMT5M+gv-H5FFOYEKYNXE46EE4A3PLAK6HCDIELS27KQUR5OBKHFKXRKMCTDA.domainverify.googlehosted.com.&domain=www.hotspotshield.com
That's what you get, for "www.hotspotshield.com", today. We'll check again, tomorrow. Also, we need to know when "today" ends.

If you buy a domain using "Buy a domain" after today, Google Apps should setup the domain for you - including the second "CNAME". If you bought the domain directly from a registrar, you're going to have to click on "settings instructions", and get the token for your domain. Note that a "CNAME" is required - a "TXT" won't provide the same verification. Also note the various registrar entry conventions, which will affect your use of their domain manager forms.

We are learning a lot of details about the domain verification process, some of which were known in custom domain setup in general - and which are absolutely critical to the process. You will want to read the [FAQ] Why is my domain still in "12" / "404" State?, to get all of the details. The FAQ has been updated several times, so re read it often..

This will, hopefully, provide a solution for the Abandoned Domains problem, and allow everybody to publish to their domain, regardless of whether the domain was previously used for Blogger / Google custom domain publishing by another blog.

On the other hand, if you purchased your domain using "Buy a domain", and you ever need to recycle the publishing settings, you're probably going to have to add this new "CNAME" to your domain, before you can re publish. This will possibly include everybody who purchased their domain, before the Publishing option was disabled - if the domain is not operational right now - and possibly, blog owners who need to un delete a domain published blog.

>> Top

Contact Us

24x7 online , we happy to answer you
tamilcypc@gmail.com

Disclaimer

This Blog and its TUT's are intended for educational purposes only, no-one involved in the creation of this TuT may be held responsible for any illegal acts brought about by this Blog or TuT.



Featured Post

Custom Domains And HTTPS Redirection Code