{"id":189,"date":"2021-01-13T13:18:06","date_gmt":"2021-01-13T05:18:06","guid":{"rendered":"https:\/\/www.ssle.cn\/help\/?p=189"},"modified":"2022-01-13T13:18:57","modified_gmt":"2022-01-13T05:18:57","slug":"apple-ios-ats-wei-xin-xiao-cheng-xu-ssl-she-zhi-jiao-cheng","status":"publish","type":"post","link":"https:\/\/ssle.cn\/help\/apple-ios-ats-wei-xin-xiao-cheng-xu-ssl-she-zhi-jiao-cheng\/","title":{"rendered":"Apple iOS ATS &#038; \u5fae\u4fe1\u5c0f\u7a0b\u5e8f SSL\u8bbe\u7f6e\u6559\u7a0b"},"content":{"rendered":"<p><strong>\u652f\u6301ATS\u548c\u5fae\u4fe1\u5c0f\u7a0b\u5e8f\u7684\u524d\u63d0\u6761\u4ef6 (\u5bf9SSL\u54c1\u724c\u65e0\u8981\u6c42\uff0c\u4ec5\u4ec5\u662f\u670d\u52a1\u5668web\u7248\u672c\u548c\u914d\u7f6e\u9700\u8981\u8bbe\u7f6e):<\/strong><\/p>\n<ul>\n<li>\u670d\u52a1\u5668\u652f\u6301 TLSv 1.2 \u534f\u8bae<\/li>\n<li>PFS\uff08\u5b8c\u5168\u6b63\u5411\u4fdd\u5bc6\uff09ECDHE<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>\u8981\u652f\u6301TLS1.2 \u548c PFS \u9700\u8981\u670d\u52a1\u5668\u64cd\u4f5c\u7cfb\u7edf\u652f\u6301<\/strong><\/p>\n<p>WIN 2008 R2 IIS 7 \u4ee5\u4e0a\u7248\u672c<br \/>\nCentOS 6+ \u00a0OpenSSL 1.0.1c+<br \/>\nApache 2.4 +<br \/>\nNginx 1.0.6+<br \/>\nJDK1.7<br \/>\ntomcat7.0.56+<\/p>\n<p>&nbsp;<\/p>\n<p><strong>\u8fde\u63a5\u5fc5\u987b\u4f7f\u7528\u00a0AES-128 \u6216\u8005 AES-256 \u52a0\u5bc6\uff0c\u5e76\u4e14\u652f\u6301PFS\uff08\u5b8c\u5168\u6b63\u5411\u4fdd\u5bc6\uff09ECDHE , Apple \u63a8\u8350\u4ee5\u4e0b\u52a0\u5bc6\u5957\u4ef6:<\/strong><\/p>\n<pre>TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384\r\nTLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256\r\nTLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384\r\nTLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA\r\nTLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256\r\nTLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA\r\nTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384\r\nTLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256\r\nTLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384\r\nTLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256\r\nTLS_ECDHE_RSA_WITH_AES_128_CBC_SHA<\/pre>\n<p><strong>Apache \u8bbe\u7f6e\u65b9\u6cd5\uff08\u5fc5\u987b\u6ee1\u8db3\u4e0a\u9762\u670d\u52a1\u5668\u7248\u672c\u8981\u6c42\uff09:<\/strong><\/p>\n<pre>SSLCipherSuite EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH\r\nSSLProtocol All -SSLv2 -SSLv3\r\nSSLHonorCipherOrder On\r\nSSLCompression off \r\nSSLSessionTickets Off<\/pre>\n<p><strong>Nginx \u8bbe\u7f6e\u65b9\u6cd5\uff08\u5fc5\u987b\u6ee1\u8db3\u4e0a\u9762\u670d\u52a1\u5668\u7248\u672c\u8981\u6c42\uff09:<\/strong><\/p>\n<pre>ssl_protocols TLSv1.2 TLSv1.1 TLSv1;\r\nssl_prefer_server_ciphers on;\r\nssl_ciphers \"EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH\";\r\nssl_session_cache shared:SSL:10m;\r\nssl_session_tickets off;<\/pre>\n<p><strong>Lighttpd\u8bbe\u7f6e\u65b9\u6cd5\uff08openssl \u5fc5\u987b\u7b26\u5408\u8981\u6c42\uff09<\/strong><\/p>\n<pre>ssl.honor-cipher-order = \"enable\"\r\nssl.cipher-list = \"EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH\"\r\nssl.use-compression = \"disable\"\r\nssl.use-sslv2 = \"disable\"\r\nssl.use-sslv3 = \"disable\"<\/pre>\n<blockquote><p>Apple \u5b98\u65b9\u6587\u6863<\/p>\n<p>https:\/\/developer.apple.com\/library\/content\/documentation\/General\/Reference\/InfoPlistKeyReference\/Articles\/CocoaKeys.html<\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>\u652f\u6301ATS\u548c\u5fae\u4fe1\u5c0f\u7a0b\u5e8f\u7684\u524d\u63d0\u6761\u4ef6 (\u5bf9SSL\u54c1\u724c\u65e0\u8981\u6c42\uff0c\u4ec5\u4ec5\u662f\u670d\u52a1\u5668web\u7248\u672c\u548c\u914d\u7f6e\u9700\u8981\u8bbe\u7f6e): \u670d\u52a1\u5668\u652f\u6301 TLSv 1.2 \u534f\u8bae PFS\uff08\u5b8c\u5168\u6b63\u5411\u4fdd\u5bc6\uff09ECDHE &nbsp; \u8981\u652f\u6301TLS1.2 \u548c PFS \u9700\u8981\u670d\u52a1\u5668\u64cd\u4f5c\u7cfb\u7edf\u652f\u6301 WIN 200 &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[3],"tags":[],"class_list":["post-189","post","type-post","status-publish","format-standard","hentry","category-faq"],"_links":{"self":[{"href":"https:\/\/ssle.cn\/help\/wp-json\/wp\/v2\/posts\/189","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ssle.cn\/help\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ssle.cn\/help\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ssle.cn\/help\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ssle.cn\/help\/wp-json\/wp\/v2\/comments?post=189"}],"version-history":[{"count":0,"href":"https:\/\/ssle.cn\/help\/wp-json\/wp\/v2\/posts\/189\/revisions"}],"wp:attachment":[{"href":"https:\/\/ssle.cn\/help\/wp-json\/wp\/v2\/media?parent=189"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ssle.cn\/help\/wp-json\/wp\/v2\/categories?post=189"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ssle.cn\/help\/wp-json\/wp\/v2\/tags?post=189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}