Skip to content

Instantly share code, notes, and snippets.

@crestcere
Last active January 27, 2025 09:55
Show Gist options
  • Save crestcere/224e5a095f9fa62b177a00be6882cd84 to your computer and use it in GitHub Desktop.
Save crestcere/224e5a095f9fa62b177a00be6882cd84 to your computer and use it in GitHub Desktop.
Mobileconfig file for blocking DNS servers
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>ConsentText</key>
<dict>
<key>default</key>
<string>Thank you for installing the WSF Config Profile.</string>
</dict>
<key>PayloadContent</key>
<array>
<dict>
<key>DNSSettings</key>
<dict>
<key>DNSProtocol</key>
<string>HTTPS</string>
<key>ServerURL</key>
<string>https://localhost.direct</string>
<key>SupplementalMatchDomains</key>
<array>
<string>ocsp.apple.com</string>
<string>ocsp2.apple.com</string>
<string>valid.apple.com</string>
<string>crl.apple.com</string>
<string>certs.apple.com</string>
<string>appattest.apple.com</string>
<string>vpp.itunes.apple.com</string>
<string>guzzoni-apple-com.v.aaplimg.com</string>
<string>axm-app.apple.com</string>
<string>comm-cohort.ess.apple.com</string>
<string>comm-main.ess.apple.com</string>
<string>mesu.apple.com</string>
</array>
</dict>
<key>OnDemandRules</key>
<array>
<dict>
<key>Action</key>
<string>Connect</string>
</dict>
</array>
<key>PayloadDisplayName</key>
<string>WSF Config Profile</string>
<key>PayloadIdentifier</key>
<string>com.apple.dnsSettings.managed.4A9BFC82-4439-4596-940C-C923E32E7CC1</string>
<key>PayloadOrganization</key>
<string>WhySooooFurious</string>
<key>PayloadType</key>
<string>com.apple.dnsSettings.managed</string>
<key>PayloadUUID</key>
<string>4A9BFC82-4439-4596-940C-C923E32E7CC1</string>
<key>PayloadVersion</key>
<integer>1</integer>
</dict>
<dict>
<key>DNSSettings</key>
<dict>
<key>DNSProtocol</key>
<string>HTTPS</string>
<key>ServerURL</key>
<string>https://localhost.direct</string>
<key>SupplementalMatchDomains</key>
<array>
<string>ocsp.apple.com</string>
<string>ocsp2.apple.com</string>
<string>valid.apple.com</string>
<string>crl.apple.com</string>
<string>certs.apple.com</string>
<string>appattest.apple.com</string>
<string>vpp.itunes.apple.com</string>
<string>mesu.apple.com</string>
<string>guzzoni-apple-com.v.aaplimg.com</string>
<string>gdmf.apple.com</string>
<string>axm-app.apple.com</string>
<string>comm-cohort.ess.apple.com</string>
<string>comm-main.ess.apple.com</string>
<string>appleldnid.apple.com</string>
<string>gg.apple.com</string>
<string>gs.apple.com</string>
<string>gsra.apple.com</string>
<string>gdmf.apple.com</string>
<string>gsra.apple.com</string>
<string>gdmf-ados.apple.com</string>
<string>appldnld.apple.com</string>
<string>xp.apple.com</string>
<string>updates.cdn-apple.com</string>
</array>
</dict>
<key>OnDemandRules</key>
<array>
<dict>
<key>Action</key>
<string>Connect</string>
</dict>
</array>
<key>PayloadDisplayName</key>
<string>WSF Config Profile + Update Blocker</string>
<key>PayloadIdentifier</key>
<string>com.apple.dnsSettings.managed.3BC124ED-F850-4246-8CAC-977E5BB726C8</string>
<key>PayloadOrganization</key>
<string>WhySooooFurious</string>
<key>PayloadType</key>
<string>com.apple.dnsSettings.managed</string>
<key>PayloadUUID</key>
<string>3BC124ED-F850-4246-8CAC-977E5BB726C8</string>
<key>PayloadVersion</key>
<integer>1</integer>
</dict>
</array>
<key>PayloadDescription</key>
<string>Prevents revokes by redirecting Apple's Certificate Servers to an invalid DNS. Also contains optional bonus features including an OTA Update Blocker.</string>
<key>PayloadDisplayName</key>
<string>WSF Config Profile</string>
<key>PayloadIdentifier</key>
<string>com.wsf.wsfcp</string>
<key>PayloadOrganization</key>
<string>WhySooooFurious</string>
<key>PayloadScope</key>
<string>User</string>
<key>PayloadType</key>
<string>Configuration</string>
<key>PayloadUUID</key>
<string>WSF-CP</string>
<key>PayloadVersion</key>
<integer>1</integer>
</dict>
</plist>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment