With ATS enabled in iOS 9, many of my clients cannot fulfill the privacy requirement. However, they can satisfy the requirements of https and TLS 1.2. In this regard, I would like to relax in front of the requirements of secrecy, keeping https and TLS 1.2 in place.
I was wondering if anyone had figured out a way to use NSExceptionRequiresForwardSecrecy or NSThirdPartyExceptionRequiresForwardSecrecy to disable direct secrecy for all domains.
I tried using * for NSExceptionDomains or * .com, but when I used the link to the problem, it did not help. When I use it domain.com, then the problem will be loaded. I looked at Apple Docs on it, but did not see any way to achieve my goal.
Is it possible to simply disable forward secrecy for all domains, for example, you can completely disable ATS by setting NSAppTransportSecurity / NSAllowsArbitraryLoads to true?
Thanks!
source share