This needs to be done BEFORE the certificate gets revoked.
- Go to Settings > Cellular (wait for the Cellular Data section to load) > Scroll to the bottom and turn off WiFi Assist. If you’re device is WiFi only, you can skip this step.
- Create a text file (must be in txt format) that contains ocsp.apple.com
- Save the text file in your iCloud Files or Dropbox (you'll have to connect your Dropbox account to iCloud Files with this option)
- Download the DNSCrypt app from the AppStore https://itunes.apple.com/us/app/dnscloak-secure-dns-client/id1452162351?mt=8
- Click the three dash lines in the top left and select the following settings
General Options:
Connect On Demand (ON)
Cache Responses (ON)
https://imgur.com/lwVCsTn
Resolvers usage rules:
Leave as default
https://imgur.com/XO6xjkU
Blacklists & Whitelists:
Enable Blacklist (ON)
Select the text file you created earlier
https://imgur.com/KunvVEI
Advanced Options:
Skip accessibility check (ON)
Strict mode (ON)
Network Connectivity (Set to IPv4 and IPv6)
Everything else off
https://imgur.com/uxOLUIg https://imgur.com/ZPRLD3H
To test download iNetTools https://itunes.apple.com/us/app/inettools-ping-dns-port-scan/id561659975?mt=8 and ping ocsp.apple.com. It should come back as invalid hostname.