App Transport Security
App Transport Security - ΠΌΠ΅Ρ Π°Π½ΠΈΠ·ΠΌ, ΠΏΡΠΈΠ΄ΡΠΌΠ°Π½Π½ΡΠΉ Apple Π΄Π»Ρ ΡΠ²ΠΎΠΈΡ ΡΡΡΡΠΎΠΉΡΡΠ² ΠΊΠ°ΠΊ Π°Π½Π°Π»ΠΎΠ³ HSTS https://forums.developer.apple.com/thread/6767
Check Server
ΠΊΠ°ΠΊ ΠΏΡΠΎΠ²Π΅ΡΠΈΡΡ, Π½Π°ΡΡΡΠΎΠ΅Π½ Π»ΠΈ ATS Π½Π° ΡΠ΅ΡΠ²Π΅ΡΠ΅:
$ nscurl --ats-diagnostics https://www.example.com
<...>
Default ATS Secure Connection
---
ATS Default Connection
Result : PASS
---
Allowing Arbitrary Loads
---
Allow All Loads
Result : PASS
---
<...>
Configuring PFS exceptions for www.example.com
---
Disabling Perfect Forward Secrecy
Result : PASS
---
<...>ΠΡΠ»ΠΈ Π½Π° ΡΡΠΎΡΠΎΠ½Π΅ ΡΠ΅ΡΠ²Π΅ΡΠ° Π΅ΡΡΡ ΠΎΡΠΈΠ±ΠΊΠΈ, Π»ΡΡΡΠ΅ ΠΈΡΠΏΡΠ°Π²ΠΈΡΡ ΠΈΡ ΠΈΠ·ΠΌΠ΅Π½ΠΈΠ² ΠΊΠΎΠ½ΡΠΈΠ³ΡΡΠ°ΡΠΈΡ, ΡΠ΅ΠΌ ΠΏΠΎΠ½ΠΈΠΆΠ°ΡΡ ΡΡΠΎΠ²Π΅Π½Ρ Π·Π°ΡΠΈΡΠ΅Π½Π½ΠΎΡΡΠΈ ATS ΠΊΠ»ΠΈΠ΅Π½ΡΠ°.
ATS Disabled
Check Client
ΠΡΠΎΠ²Π΅ΡΡΡΡ ΠΊΠ°ΠΊ Π½Π°ΡΡΡΠΎΠ΅Π½ ATS - Π² Info.plist ΠΠΎΡ ΠΏΡΠΈΠΌΠ΅Ρ ΠΎΡΠΊΠ»ΡΡΠ΅Π½ΠΈΡ ATS Π΄Π»Ρ ΠΏΡΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΡ (Π·Π° ΠΈΡΠΊΠ»ΡΡΠ΅Π½ΠΈΠ΅ΠΌ Π΄ΠΎΠΌΠ΅Π½ΠΎΠ², ΠΎΠ±ΡΡΠ²Π»Π΅Π½Π½ΡΡ Π² NSExceptionDomains). ΠΠ»Ρ ΡΡΠΈΡ Π΄ΠΎΠΌΠ΅Π½ΠΎΠ² ΠΌΠΎΠΆΠ½ΠΎ ΠΎΠΏΡΠ΅Π΄Π΅Π»ΡΡΡ ΡΠ²ΠΎΠΈ Π½Π°ΡΡΡΠΎΠΉΠΊΠΈ.
<key>NSAppTransportSecurity</key>
<dict>
<key>NSAllowsArbitraryLoads</key>
<true/>
<key>NSExceptionDomains</key>
<dict>
<key>example.com</key>
<dict>
<key>NSIncludesSubdomains</key>
<true/>
</dict>
</dict>
</dict>The application may have ATS exceptions defined to allow itβs normal functionality. For an example, the Firefox iOS application has ATS disabled globally. This exception is acceptable because otherwise the application would not be able to connect to any HTTP website that does not have all the ATS requirements.
ΠΠ±ΡΠΈΠ΅ ΡΠ΅ΠΊΠΎΠΌΠ΅Π½Π΄Π°ΡΠΈΠΈ
- ATS Π΄ΠΎΠ»ΠΆΠ΅Π½ Π±ΡΡΡ Π½Π°ΡΡΡΠΎΠ΅Π½ Π² ΡΠΎΠΎΡΠ²Π΅ΡΡΡΠ²ΠΈΠΈ Ρ Π»ΡΡΡΠΈΠΌΠΈ ΠΏΡΠ°ΠΊΡΠΈΠΊΠ°ΠΌΠΈ Apple ΠΈ Π΄Π΅Π°ΠΊΡΠΈΠ²ΠΈΡΠΎΠ²Π°Π½ ΡΠΎΠ»ΡΠΊΠΎ ΠΏΡΠΈ ΠΎΠΏΡΠ΅Π΄Π΅Π»Π΅Π½Π½ΡΡ ΠΎΠ±ΡΡΠΎΡΡΠ΅Π»ΡΡΡΠ²Π°Ρ (Π½Π°ΠΏΡΠΈΠΌΠ΅Ρ, 3th party not support ATS) - If the application opens third party web sites in web views, then from iOS 10 onwards NSAllowsArbitraryLoadsInWebContent can be used to disable ATS restrictions for the content loaded in web views
ΠΡΡΡ Π΅ΡΠ΅ ΠΌΠ΅Ρ
Π°Π½ΠΈΠ·ΠΌ PFS
PFS β Perfect Forward Secrecy
ΠΠΎΠ΄ΡΠΎΠ±Π½Π°Ρ ΡΡΠ°ΡΡΡ Ρ NowSecure
ΠΠΎΠΊΡΠΌΠ΅Π½ΡΠ°ΡΠΈΡ ΠΏΠΎ Π½Π°ΡΡΡΠΎΠΉΠΊΠ΅: https://developer.apple.com/library/archive/documentation/General/Reference/InfoPlistKeyReference/Articles/CocoaKeys.html#//apple_ref/doc/uid/TP40009251-SW33
Last updated
Was this helpful?
