To make the development environment identical to the production environment, configure your client to override the authoritative DNS server(s) for the commonidtrust.org domain to the development environment. You can either configure your DNS, or you can use a VPN.
Currently, the DNS server for VPC-Dev runs on a personal, free t2.micro instance in EC2 and is accessible at 220.127.116.11. You will need a secondary resolver for real addresses, such as 18.104.22.168, 22.214.171.124 (Level3), or 126.96.36.199, or 188.8.131.52(Google).
Configure /etc/named.conf and the zone file /var/named/masters/commonidtrust.org (see examples attached).
chkconfig named on
Recursion is disabled and rate limiting is set at 5 per second. Since there are a total of 3 records, this is basically impossible to use in any form of attack, ever, and it's in a personal account anyway.
named logs to /var/log/messages
This is configured to serve up the A and/or CNAME records for account.commonidtrust.org, helpdesk.commonidtrust.org, and login.commonidtrust.org for the specific VPC environment.
pretty much just stole http://www.stormacq.com/build-a-private-vpn-server-on-amazons-ec2/