Starting about a day ago, some sites are signed by an OpenDNS certificate.
The root CA is "Cisco Umbrella Root CA" and one of the intermediate certificates is "Cisco Umbrella Secondary SubCA fra-SG".
This causes an untrusted certificate error in all devices which don't trust the root CA certificate, preventing sites from loading, and some IoT devices from connecting.
My understanding is that the OpenDNS Family Shield should only answer or not answer DNS requests, but it seems that the behavior has changed, and now they preform Man in the Middle for some sites as well.
Is there a way to avoid that?
Thanks in advance,
Attached is an example for the issue with wikipedia.org:
