Apple ATS / Perfect Forward Secrecy requirements as of Jan 1, 2017

Michael O Holstein michael.holstein at csuohio.edu
Tue Nov 8 12:56:30 EST 2016


The easiest work-around is to run SSL on the webservers and re-configure the ACE to do TCP load balancing (versus Layer-7) only. You can still configure probes as long as you support a dumb enough cipher for the ACE to understand in client-mode (or just do a tcp probe).

Regards,

Michael Holstein CISSP
Mgr. Network & Data Security
Cleveland State University
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Liam Hoekenga <liamr at umich.edu>
Sent: Tuesday, November 8, 2016 12:30:35 PM
To: Shib Users
Subject: Apple ATS / Perfect Forward Secrecy requirements as of Jan 1, 2017

I know this is slightly off topic - but is anyone else having to find solutions for the Apple App Store applications ATS / PFS requirement that goes into effect on Jan 1, 2017?

Our IdP is currently behind older Cisco ACE load balancers that don't support the required cryptographic algorithms.. we think our easiest way forward will be to stop using SSL termination on the load balancers until we get new gear in place.

Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161108/04fc7ba5/attachment.html>


More information about the users mailing list