11-10-2020 05:09 PM
After upgrading my iPad from iOS 13.7 to 14.2, I find my caching forwarder logs flooded with:
Nov 10 16:28:09 janus named[1050]: REFUSED unexpected RCODE resolving 'ocsp.g.aaplimg.com/TYPE65/IN': 208.67.222.222#53
Nov 10 16:28:09 janus named[1050]: REFUSED unexpected RCODE resolving 'ocsp.g.aaplimg.com/TYPE65/IN': 208.67.220.220#53
Nov 10 16:28:09 janus named[1050]: REFUSED unexpected RCODE resolving 'ocsp.g.aaplimg.com/TYPE65/IN': 208.67.222.222#53
At a rate of about 1000/day.
Does OpenDNS have any plans to support HTTPS RR requests? Other open DNS services return zero answers but don't cause an error to be logged.
11-11-2020 01:35 AM
Staff do not respond here. You must raise a support ticket, link “Submit a request” above.
Until then, you simply ignore these errors. They don’t seem to have any impact yet. Akamai have recently introduced this RR type, and iOS 14 utilizes it.
11-12-2020 05:35 AM
This behavior is intended.
Encrypted resolvers designated by domain owners
The owner of a DNS zone will be able to designate a specific resolver to be used for resolving its zone. In iOS 14 and macOS 11, only DoH resolvers can be designated. This designation is made using a dedicated DNS record type (type 65, named “HTTPS”), and validated either by DNSSEC or well known URIs.
As such designations would result in queries bypassing OpenDNS, the OpenDNS resolvers return a REFUSED response for queries for the HTTPS DNS record type, meaning that such designations would not be discovered.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide