<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: idmsa.apple.com problematic, Sign-in to Apple discussions in OpenDNS</title>
    <link>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184820#M11532</link>
    <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;It could be location-dependent, both for origin and destination. Nonetheless, the problem instantly changes when DNS is changed, and goes away permanently with Q9. So I do believe Q9 is doing something better than Open.&lt;/P&gt;
&lt;P&gt;Thanks anyways.&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Sat, 24 Mar 2018 14:38:14 GMT</pubDate>
    <dc:creator>hcsitas</dc:creator>
    <dc:date>2018-03-24T14:38:14Z</dc:date>
    <item>
      <title>idmsa.apple.com problematic, Sign-in to Apple discussions</title>
      <link>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184818#M11530</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;If I click “Sign-in” on discussions.apple.com, the idmsa.apple.com page hangs without serving the user id and password prompt. If I switch DNS to 8.8.8.8, it works but after about 30 minutes&amp;nbsp;Google DNS has the same issue. Switching back to OpenDNS will get it to work temporarily but stop after idling for about 30 minutes.&lt;/P&gt;
&lt;P&gt;However, with Quad 9, the page works perfectly even after idle periods. I’d like to stay with OpenDNS because Q9 does not provided custom filtering. However I’m concerned that this “bug” might exist for other pages. Could you resolve kindly? The usual stuff - clearing caches and rebooting router has no effect. Happens even if I remove all filtering, and problem is unchanged even after moving platforms from iOS to PC Chrome.&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 24 Mar 2018 11:25:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184818#M11530</guid>
      <dc:creator>hcsitas</dc:creator>
      <dc:date>2018-03-24T11:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: idmsa.apple.com problematic, Sign-in to Apple discussions</title>
      <link>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184819#M11531</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;This doesn't look like a DNS problem, but like a connectivity problem.&amp;nbsp; Btw, I do not face this problem when using OpenDNS, neither on iOS nor on Windows.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 24 Mar 2018 14:32:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184819#M11531</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2018-03-24T14:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: idmsa.apple.com problematic, Sign-in to Apple discussions</title>
      <link>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184820#M11532</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;It could be location-dependent, both for origin and destination. Nonetheless, the problem instantly changes when DNS is changed, and goes away permanently with Q9. So I do believe Q9 is doing something better than Open.&lt;/P&gt;
&lt;P&gt;Thanks anyways.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 24 Mar 2018 14:38:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184820#M11532</guid>
      <dc:creator>hcsitas</dc:creator>
      <dc:date>2018-03-24T14:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: idmsa.apple.com problematic, Sign-in to Apple discussions</title>
      <link>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184821#M11533</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;The fact that you have the same problem with Google Public DNS contradicts your theory.&amp;nbsp; I treat the Q9 case rather for coincidental.&lt;/P&gt;
&lt;P&gt;If it would be a DNS problem, you had to analyze the DNS query results, like:&lt;/P&gt;
&lt;PRE&gt;nslookup &lt;EM&gt;domain_name&lt;/EM&gt;.&lt;/PRE&gt;
&lt;P&gt;Btw, Apple uses nearly almost CNAMEs, and they seem to use the CDN service of Akamai.&lt;/P&gt;
&lt;PRE&gt;nslookup idmsa.apple.com.&lt;BR /&gt;Server: fritz.box&lt;BR /&gt;Address: fd00::ca0e:14ff:fee9:8373&lt;BR /&gt;&lt;BR /&gt;Nicht autorisierende Antwort:&lt;BR /&gt;Name: idmsa.apple.com.akadns.net&lt;BR /&gt;Address: 17.179.252.96&lt;BR /&gt;Aliases: idmsa.apple.com&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 24 Mar 2018 14:55:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184821#M11533</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2018-03-24T14:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: idmsa.apple.com problematic, Sign-in to Apple discussions</title>
      <link>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184822#M11534</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;I treat the case with Q9 as &lt;EM&gt;completely related&lt;/EM&gt;. And what *seems* frequently isn’t. I did check the DNS results for idms.apple.com at Open, and it returned the same address for Europe and the US, although it split them up by country. That seems to point the problem towards &lt;A href="mailto:DNS@Open" rel="nofollow noreferrer"&gt;DNS@Open&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;This must be related to higher security awareness both at Apple&amp;nbsp;also Q9 and possible upgrades on their side, so let’s hope experts at Open can figure it out and get Open up to date too. Not holding breath however, my account here is a free one.&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 24 Mar 2018 15:20:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184822#M11534</guid>
      <dc:creator>hcsitas</dc:creator>
      <dc:date>2018-03-24T15:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: idmsa.apple.com problematic, Sign-in to Apple discussions</title>
      <link>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184823#M11535</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;I have found something in the Q9 FAQ which could be related, that they do not send the EDNS Client Subnet to authoritative nameservers.&amp;nbsp; If you get better DNS results as when sending the EDNS Client Subnet, then it is likely that your IP address is associated with the wrong location, i.e. some geo-location issue, as you mentioned.&amp;nbsp; You can test this here:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://www.iplocation.net/" rel="nofollow noreferrer"&gt;https://www.iplocation.net/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;let’s hope experts at Open can figure it out&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;In this case you must raise a support ticket, "Submit a request" above.&amp;nbsp; Staff do not strictly monitor contributions in the community forum...&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 24 Mar 2018 15:25:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184823#M11535</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2018-03-24T15:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: idmsa.apple.com problematic, Sign-in to Apple discussions</title>
      <link>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184824#M11536</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;And indeed, I tested with a few domains' DNS queries, and typically Q9 returns IP addresses different from OpenDNS and Google.&amp;nbsp; Just an example:&lt;/P&gt;
&lt;PRE&gt;nslookup idmsa.apple.com. 8.8.8.8&lt;BR /&gt;Server: google-public-dns-a.google.com&lt;BR /&gt;Address: 8.8.8.8&lt;BR /&gt;&lt;BR /&gt;Nicht autorisierende Antwort:&lt;BR /&gt;Name: idmsa.apple.com.akadns.net&lt;BR /&gt;Address: 17.179.252.96&lt;BR /&gt;Aliases: idmsa.apple.com&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;nslookup idmsa.apple.com. 9.9.9.9&lt;BR /&gt;Server: dns.quad9.net&lt;BR /&gt;Address: 9.9.9.9&lt;BR /&gt;&lt;BR /&gt;Nicht autorisierende Antwort:&lt;BR /&gt;Name: idmsa.apple.com.akadns.net&lt;BR /&gt;Address: 17.32.194.38&lt;BR /&gt;Aliases: idmsa.apple.com&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;nslookup idmsa.apple.com. 208.67.220.220&lt;BR /&gt;Server: resolver2.opendns.com&lt;BR /&gt;Address: 208.67.220.220&lt;BR /&gt;&lt;BR /&gt;Nicht autorisierende Antwort:&lt;BR /&gt;Name: idmsa.apple.com.akadns.net&lt;BR /&gt;Address: 17.179.252.96&lt;BR /&gt;Aliases: idmsa.apple.com&lt;/PRE&gt;
&lt;P&gt;That explains a lot...&amp;nbsp;&lt;BR /&gt;You should be aware that not sending the EDNS Client Subnet is suboptimal in many cases especially in conjunction with CDNs.&amp;nbsp; In your individual case it is coincidental to the contrary which can happen as well, but rather seldom.&lt;/P&gt;
&lt;P&gt;And this is what "&lt;EM&gt;experts at Open can figure it out&lt;/EM&gt;" as well.&amp;nbsp; There is probably nothing what they could improve except to introduce different resolver addresses where the EDNS Client Subnet is not being used, so that you have the option to choose from the one or the other.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 24 Mar 2018 15:41:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184824#M11536</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2018-03-24T15:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: idmsa.apple.com problematic, Sign-in to Apple discussions</title>
      <link>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184825#M11537</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;My geolocation maps correctly using the link you have provided.&lt;/P&gt;
&lt;P&gt;So it is confirmed, Q9 sends different addresses than Google and Open, which in my case also happens to be better addresses. It smells really bad to me. Why does the biggest kid in the cyber-security neighborhood Q9 send different addresses for super-secure Apple than Open or Google? Especially addresses that work anytime, every time? Because they’re ahead of the cyber security curve, simple as that.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Something not right, that’s my ticket. If Open are not listening, phooey to them. I’m outta here. You should be too.&lt;/P&gt;
&lt;P&gt;Anyway, thanks for the splendid analysis! Open needs to get in touch with you pronto.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 24 Mar 2018 16:11:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184825#M11537</guid>
      <dc:creator>hcsitas</dc:creator>
      <dc:date>2018-03-24T16:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: idmsa.apple.com problematic, Sign-in to Apple discussions</title>
      <link>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184826#M11538</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;No, I will not raise a ticket because of this, because as I said, I do not face any related problem.&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;Why does the biggest kid in the cyber-security neighborhood Q9 send different addresses for super-secure Apple than Open or Google?&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;This is most likely the answer:&amp;nbsp;&lt;A href="https://support.opendns.com/hc/en-us/articles/227987647%C2%A0" rel="nofollow noreferrer"&gt;https://support.opendns.com/hc/en-us/articles/227987647&amp;nbsp;&lt;/A&gt;&lt;BR /&gt;But because you're "outta here", it is of minor relevance now.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 24 Mar 2018 16:33:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184826#M11538</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2018-03-24T16:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: idmsa.apple.com problematic, Sign-in to Apple discussions</title>
      <link>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184827#M11539</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;I didn’t ask you to raise a ticket. I said Open needs to proactively fix. Your link is 10 months old and wants an email with as much information as possible. It’ll bring good cheer to hackers worldwide. Everybody happy? Yes. Bye.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 24 Mar 2018 16:41:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184827#M11539</guid>
      <dc:creator>hcsitas</dc:creator>
      <dc:date>2018-03-24T16:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: idmsa.apple.com problematic, Sign-in to Apple discussions</title>
      <link>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184828#M11540</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;"&lt;EM&gt;Your link is 10 months old&lt;/EM&gt;"&amp;nbsp; ...and proves when they joined the project.&amp;nbsp; I do not see that this article has to expire.&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;It’ll bring good cheer to hackers worldwide.&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;What?&amp;nbsp; Sorry, I don't understand what hacking had to do in this context.&amp;nbsp; You do not need to answer.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 24 Mar 2018 16:46:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184828#M11540</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2018-03-24T16:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: idmsa.apple.com problematic, Sign-in to Apple discussions</title>
      <link>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184829#M11541</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;But I will. A page that hangs mysteriously under defined circumstances that can be easily replicated is opportunity. Especially a page used by millions worldwide. You do not need to answer because you won’t be able to come up with one. Thanks anyways, I do appreciate your analysis.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 24 Mar 2018 16:52:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184829#M11541</guid>
      <dc:creator>hcsitas</dc:creator>
      <dc:date>2018-03-24T16:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: idmsa.apple.com problematic, Sign-in to Apple discussions</title>
      <link>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184830#M11542</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;I do have an answer, or better an explanation, already posted above.&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;Especially a page used by millions worldwide.&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;Well, OpenDNS has more than 80 Millions of users, and I find only one report about the issue with the Apple discussions site's login or others here?&amp;nbsp; Weird.&amp;nbsp; Are all other users blindly accepting the issue?&amp;nbsp; Hard to believe.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 24 Mar 2018 17:01:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184830#M11542</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2018-03-24T17:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: idmsa.apple.com problematic, Sign-in to Apple discussions</title>
      <link>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184831#M11543</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Ha ha. Most happily accept the default DNS supplied by their ISP. People who use custom DNS services are by definition a super minority compared to the public at large. How many are Apple users? A minority within a minority within a minority. With no patience for glaring imperfections. And definitely not posting on Open’s sleepy “send me a mail open me a ticket” forum. Onwards to Q9! Zum Wohl!&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 24 Mar 2018 17:10:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/idmsa-apple-com-problematic-sign-in-to-apple-discussions/m-p/5184831#M11543</guid>
      <dc:creator>hcsitas</dc:creator>
      <dc:date>2018-03-24T17:10:45Z</dc:date>
    </item>
  </channel>
</rss>

