<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body>
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Arial,Helvetica,sans-serif;" dir="ltr">
The easiest work-around is to run SSL on the webservers and re-configure the ACE to do TCP load balancing (versus Layer-7) only. You can still configure probes as long as you support a dumb enough cipher for the ACE to understand in client-mode (or just do
a tcp probe).
<div><br>
</div>
<div>Regards,</div>
<div><br>
</div>
<div>Michael Holstein CISSP</div>
<div>Mgr. Network & Data Security</div>
<div>Cleveland State University</div>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Liam Hoekenga <liamr@umich.edu><br>
<b>Sent:</b> Tuesday, November 8, 2016 12:30:35 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Apple ATS / Perfect Forward Secrecy requirements as of Jan 1, 2017</font>
<div> </div>
</div>
<div>
<div dir="ltr">I know this is slightly off topic - but is anyone else having to find solutions for the Apple App Store applications ATS / PFS requirement that goes into effect on Jan 1, 2017?
<div><br>
</div>
<div>Our IdP is currently behind older Cisco ACE load balancers that don't support the required cryptographic algorithms.. we think our easiest way forward will be to stop using SSL termination on the load balancers until we get new gear in place.</div>
<div><br>
</div>
<div>Liam</div>
</div>
</div>
</body>
</html>