{"id":151563,"date":"2020-08-27T10:10:48","date_gmt":"2020-08-27T02:10:48","guid":{"rendered":"http:\/\/4563.org\/?p=151563"},"modified":"2020-08-27T10:10:48","modified_gmt":"2020-08-27T02:10:48","slug":"ios-14-%e5%bc%80%e5%a7%8b%e6%9f%a5%e8%af%a2-https-%e8%ae%b0%e5%bd%95-type-65","status":"publish","type":"post","link":"http:\/\/4563.org\/?p=151563","title":{"rendered":"iOS 14 \u5f00\u59cb\u67e5\u8be2 HTTPS \u8bb0\u5f55 (type 65)"},"content":{"rendered":"<div>\n<div>\n<div>\n<h1>                  iOS 14 \u5f00\u59cb\u67e5\u8be2 HTTPS \u8bb0\u5f55 (type 65)               <\/h1>\n<p> <\/p>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : domosekai <\/span>  <span><i><\/i> 20<\/span> <\/div>\n<div> <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div isfirst=\"1\"> <\/p>\n<p>\u4eca\u5929\u53d1\u73b0\u7f51\u5173\u4e0a\u7684 dnsmasq \u51fa\u73b0\u8bb8\u591a\u6ca1\u89c1\u8fc7\u7684 type 65 \u67e5\u8be2(HTTPS BINDING)\uff0c\u67e5\u4e0b\u6765\u662f iOS14 \u7684 iPhone \u53d1\u51fa\u3002<\/p>\n<p>\u8bd5\u7740 dig \u4e86\u4e00\u4e0b\uff0c\u76ee\u524d\u529f\u80fd\u548c CNAME \u5dee\u4e0d\u591a\uff0c\u56fd\u5185 114 \u3001\u767e\u5ea6\u3001\u963f\u91cc\u90fd\u652f\u6301\uff0c\u6211\u7684\u8054\u901a\u4e5f\u652f\u6301\uff0c\u4f46\u662f dnspod \u4e0d\u652f\u6301\uff01\uff01\uff01<\/p>\n<p>\u8fd9\u4e2a\u4ee5\u540e\u6709\u4ec0\u4e48\u7528\uff1f\u8fd8\u8bf7\u77e5\u9053\u7684\u5927\u4f6c\u8bf4\u8bf4\uff1f\u9644 dig \u8bb0\u5f55<\/p>\n<p>cloudflare<\/p>\n<pre><code>; &lt;&lt;&gt;&gt; DiG 9.16.3 &lt;&lt;&gt;&gt; TYPE65 su.itunes.apple.com @1.1.1.1 +nocookie ;; global options: +cmd ;; Got answer: ;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 5808 ;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 1, ADDITIONAL: 1  ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1232 ;; QUESTION SECTION: ;su.itunes.apple.com.           IN      TYPE65  ;; ANSWER SECTION: su.itunes.apple.com.    3323    IN      CNAME   su-cdn.itunes-apple.com.akadns.net. su-cdn.itunes-apple.com.akadns.net. 3323 IN CNAME su-applak.itunes-apple.com.akadns.net. su-applak.itunes-apple.com.akadns.net. 23 IN CNAME su.itunes.apple.com.edgekey.net. su.itunes.apple.com.edgekey.net. 23 IN  CNAME   e673.dsce9.akamaiedge.net. <\/code><\/pre>\n<p>alidns<\/p>\n<pre><code>; &lt;&lt;&gt;&gt; DiG 9.16.3 &lt;&lt;&gt;&gt; TYPE65 su.itunes.apple.com @223.5.5.5 +nocookie ;; global options: +cmd ;; Got answer: ;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 48522 ;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 1, ADDITIONAL: 0  ;; QUESTION SECTION: ;su.itunes.apple.com.           IN      TYPE65  ;; ANSWER SECTION: su.itunes.apple.com.    60      IN      CNAME   su-cdn.itunes-apple.com.akadns.net. su-cdn.itunes-apple.com.akadns.net. 60 IN CNAME su-china.itunes-apple.com.akadns.net. su-china.itunes-apple.com.akadns.net. 60 IN CNAME su.itunes.apple.com.mwcname.com. <\/code><\/pre>\n<p>dnspod \u5931\u8d25<\/p>\n<pre><code>; &lt;&lt;&gt;&gt; DiG 9.16.3 &lt;&lt;&gt;&gt; TYPE65 su.itunes.apple.com @119.29.29.29 +nocookie ;; global options: +cmd ;; Got answer: ;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: NOTIMP, id: 62775 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1  ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION: ;su.itunes.apple.com.           IN      TYPE65 <\/code><\/pre>\n<\/p><\/div>\n<div> <b>\u5927\u4f6c\u6709\u8a71\u8aaa<\/b> (<span>9<\/span>)        <\/div>\n<div> <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<ul>\n<li data-pid=\"2980506\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : ysc3839 <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             https:\/\/tools.ietf.org\/html\/draft-ietf-dnsop-svcb-httpssvc-01                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"2980507\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u4e3b<\/span> <span>\u8cc7\u6df1\u5927\u4f6c : domosekai <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             \u5927\u6982\u627e\u5230\u539f\u56e0\u4e86\uff0c\u8bf7\u641c\u7d22\u4e00\u4efd apple \u9886\u8854\u7684 IETF draft\uff0cdraft-pauly-add-resolver-discovery-01<br \/>\u7b80\u8981\u800c\u8a00\uff0c\u901a\u8fc7\u67e5\u8be2\u67d0\u57df\u540d\u7684 SVCB\/HTTPS \u8bb0\u5f55\uff0c\u53ef\u4ee5\u83b7\u53d6\u8fd9\u4e2a\u57df\u540d\u7684\u4e13\u7528 DoH server\uff0c\u5982\u679c\u5b58\u5728\u7684\u8bdd\u5173\u4e8e\u6b64\u57df\u540d\u7684\u6240\u6709 DNS \u8bf7\u6c42\u5c06\u53d1\u7ed9\u5236\u5b9a\u7684 DoH \u8fdb\u884c\uff0c\u8fd9\u7ed9\u57df\u540d\u62e5\u6709\u8005\u6307\u5b9a nameserver \u63d0\u4f9b\u4e86\u53ef\u80fd<br \/>\u9644\u5f55 A \u63d0\u5230\uff0c\u652f\u6301 SVCB\/HTTPS \u67e5\u8be2\u7684\u5ba2\u6237\u7aef\u7684\u505a\u6cd5\u662f\uff0c\u540c\u65f6\u53d1\u9001 A\/AAAA\/HTTPS \u4e09\u79cd\u7c7b\u578b\u7684\u67e5\u8be2\u7ed9 DNS\uff0c\u5982\u679c\u6709 DoH \u8bb0\u5f55\u5219\u91c7\u7528\uff0c\u8fd9\u4e2a\u540c\u65f6\u53d1\u7684\u884c\u4e3a\u6211\u4e5f\u901a\u8fc7\u6293 iPhone \u7684\u5305\u786e\u8ba4\u4e86\u65e0\u8bef                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"2980508\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u4e3b<\/span> <span>\u8cc7\u6df1\u5927\u4f6c : domosekai <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @ysc3839 \u8c22\u8c22\uff0c\u6ca1\u9519\uff0c\u8fd9\u4e2a\u662f SVCB\/HTTPS \u7684\u8349\u6848\uff0c\u4f46\u91cc\u9762\u6db5\u76d6\u7684\u529f\u80fd\u5f88\u591a\uff0c\u8fd9\u6b21 apple \u8981\u505a\u7684\u6211\u731c\u53ea\u662f\u67e5\u8be2\u7279\u5b9a\u57df\u540d\u7684 DoH server \u662f\u5426\u5b58\u5728\uff0c\u8bf7\u53c2\u8003\u6211\u4e0a\u9762\u7684\u56de\u590d                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"2980509\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : shikkoku <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @domosekai #3 dnspod \u7684 doh \u8fd8\u6ca1\u5b9e\u88c5\u5230 119 \u5462\u3002                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"2980510\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u4e3b<\/span> <span>\u8cc7\u6df1\u5927\u4f6c : domosekai <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @shikkoku \u8fd9\u548c doh \u4e0d\u662f\u4e00\u56de\u4e8b\uff0c\u5c31\u662f UDP \u67e5\u8be2                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"2980511\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : johnjiang85 <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             \u5927\u6982\u770b\u4e86\u4e0b\uff0c\u540e\u9762\u8fd8\u9700\u8981\u4ed4\u7ec6\u7814\u7a76\u4e0b\uff0c\u5927\u6982\u51e0\u70b9\u5427<br \/>1. \u8be5\u8349\u6848\u548c DoH\/DoT \u672c\u8eab\u6ca1\u6709\u5fc5\u7136\u5173\u8054\uff0c\u53ea\u662f\u53ef\u4ee5\u901a\u8fc7 DoH\/DoT \u8fdb\u884c SVCB\/HTTPSSVC \u7684 DNS \u8bf7\u6c42\u6765 \u201cTo realize the greatest privacy benefits\u201d<br \/>2. \u4e3b\u8981\u8fd8\u662f\u89e3\u51b3 HTTPS \u8bbf\u95ee WEB \u670d\u52a1\u5668\u7684\u76f8\u5173\u95ee\u9898\uff0c\u6d89\u53ca\u5185\u5bb9\u6bd4\u8f83\u591a\uff0c\u5982\u4e4b\u524d HTTPS \u76f8\u5173\u7684 HSTS\/Alt-Svc, DNS \u76f8\u5173\u7684 SRV \u8bb0\u5f55\u3001\u975e\u6807\u670d\u52a1\u7aef\u53e3\u3001CNAME \u4e0e\u5176\u4ed6\u8bb0\u5f55\u51b2\u7a81\u7b49\u7b49<br \/>3. 119 \u8fd4\u56de NOTIME \u76ee\u524d\u770b\u5f71\u54cd\u4e0d\u5927\uff0c\u4f46\u662f\u540e\u7eed\u4f1a\u8bc4\u4f30\u662f\u5426\u4ee5\u53ca\u4f55\u65f6\u652f\u6301 SVCB\/HTTPSSVC \u8bb0\u5f55\uff0c\u5305\u62ec 119 \u548c DNSPod \u6743\u5a01\u3002                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"2980512\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : johnjiang85 <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @johnjiang85 NOTIME -&gt; NOTIMP                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"2980513\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u4e3b<\/span> <span>\u8cc7\u6df1\u5927\u4f6c : domosekai <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @johnjiang85 \u611f\u8c22\u5927\u4f6c\u56de\u590d\u3002\u76ee\u524d\u786e\u5b9e\u65e0\u5b9e\u9645\u5f71\u54cd\uff0c\u6211\u4e5f\u6ca1\u6709\u53d1\u73b0\u54ea\u4e2a apple \u7684\u57df\u540d\u90e8\u7f72\u4e86 65 \u8bb0\u5f55\u3002\u53e6\u5916\uff0c\u4e0d\u662f\u901a\u8fc7 DoH\/DoT \u8fdb\u884c SVCB \u8bf7\u6c42\u6765\u4fdd\u969c\u9690\u79c1\u3002\u6211\u7684\u7406\u89e3\u662f\uff0c\u8be5\u8bf7\u6c42\u5b8c\u5168\u53ef\u4ee5\u901a\u8fc7 UDP \u8fdb\u884c\uff0c\u8fd9\u4e2a\u8349\u6848\u7684\u903b\u8f91\u662f\uff0c\u65e2\u7136 TLS \u7684\u63e1\u624b\u5305\u8981\u52a0\u5bc6\uff08\u65e0\u8bba ESNI \u6216\u8005 ECH \uff09\uff0c\u90a3\u4e48 DNS \u81ea\u7136\u4e5f\u4e0d\u80fd\u901a\u8fc7\u516c\u5171\u670d\u52a1\u5668\uff0c\u6240\u4ee5\u8981\u6709\u4e2a\u529e\u6cd5\u6765\u6307\u5b9a\u57df\u540d\u4e13\u5c5e\u7684 DoH\uff0c\u4ece\u800c\u4fdd\u8bc1&#8221;clients would only resolve names with the same entity that would service TLS connections&#8221;                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"2980514\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : johnjiang85 <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @domosekai \u55ef\uff0c\u6628\u665a\u53ea\u770b\u4e86 draft-ietf-dnsop-svcb-httpssvc-03\uff0c \u6ca1\u770b draft-pauly-add-resolver-discovery-01                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li>\n","protected":false},"excerpt":{"rendered":"<p>iOS 14 \u5f00\u59cb\u67e5\u8be2 HTTPS&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[],"tags":[],"_links":{"self":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts\/151563"}],"collection":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=151563"}],"version-history":[{"count":0,"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts\/151563\/revisions"}],"wp:attachment":[{"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=151563"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=151563"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=151563"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}