Hi folks,
looking for some guidance on what needs to be done to the XG so that the XG CA meets Apple CA pinning requirements. The CA works fine for SMPTS and decrypt scanning in the web proxy, but not for iMAPS.
When you first enable iMAPS scanning the certificate asks for for permission to continue which if granted works for about 30 minutes before failing again.
Ian
Hi everyone, thank you for your feedback and your patience in this matter. As you know Apple have made some changes to the CA and cert requirements for iOS and MacOS. Briefly below these are summarised, and our response.
Current Apple requirements for iOS 13 and MacOS 10.15:
All TLS server certificates must comply with these new security requirements in iOS 13 and macOS 10.15:
Additionally, all TLS server certificates issued after July 1, 2019 (as indicated in the NotBefore field of the certificate) must follow these guidelines:
Connections to TLS servers violating these new requirements will fail and may cause network failures, apps to fail, and websites to not load in Safari in iOS 13 and macOS 10.15.
We are tracking and fixing this issue in NC-55223 and the fix is currently timed for v18.0.1 (MR1) release.
Stuart,
I really hope you can fix in GA.
Thanks for your info.