The Movie Database 지원

I'm working on an app that will launch on iOS 9, and in order to talk to the TMDb API, I need to disable App Transport Security (a new security feature). It looks (from the headers CURL returns) that your servers support TLSv1.2, correct? That's the main requirement that's catching people. I'm connecting over https, and this is the error I get back:

Error Domain=NSURLErrorDomain Code=-1200 "An SSL error has occurred and a secure connection to the server cannot be made." UserInfo={NSURLErrorFailingURLPeerTrustErrorKey=<SecTrustRef: 0x7fe438442330>, NSLocalizedRecoverySuggestion=Would you like to connect to the server anyway?, _kCFStreamErrorDomainKey=3, _kCFStreamErrorCodeKey=-9802, NSErrorPeerCertificateChainKey=<CFArray 0x7fe43a406250 [0x10c1447b0]>{type = immutable, count = 3, values = (
    0 : <cert(0x7fe438436890) s: *.themoviedb.org i: RapidSSL CA>
    1 : <cert(0x7fe4384364b0) s: RapidSSL CA i: GeoTrust Global CA>
    2 : <cert(0x7fe438441870) s: GeoTrust Global CA i: Equifax Secure Certificate Authority>
)}, NSUnderlyingError=0x7fe43a2026b0 {Error Domain=kCFErrorDomainCFNetwork Code=-1200 "(null)" UserInfo={_kCFStreamPropertySSLClientCertificateState=0, kCFStreamPropertySSLPeerTrust=<SecTrustRef: 0x7fe438442330>, _kCFNetworkCFStreamSSLErrorOriginalValue=-9802, _kCFStreamErrorDomainKey=3, _kCFStreamErrorCodeKey=-9802, kCFStreamPropertySSLPeerCertificates=<CFArray 0x7fe43a406250 [0x10c1447b0]>{type = immutable, count = 3, values = (
    0 : <cert(0x7fe438436890) s: *.themoviedb.org i: RapidSSL CA>
    1 : <cert(0x7fe4384364b0) s: RapidSSL CA i: GeoTrust Global CA>
    2 : <cert(0x7fe438441870) s: GeoTrust Global CA i: Equifax Secure Certificate Authority>
)}}}, NSLocalizedDescription=An SSL error has occurred and a secure connection to the server cannot be made., NSErrorFailingURLKey=https://api.themoviedb.org/3/person/287?api_key=9e***********************9faa, NSErrorFailingURLStringKey=https://api.themoviedb.org/3/person/287?api_key=9e*************************9faa, NSErrorClientCertificateStateKey=0}

Any ideas what is wrong? Has a certificate expired or something?

11 댓글 (1 / 1)

Jump to last post

Hi dovfrankel,

I've heard about this, it was discussed a here. I don't think it's TLS 1.2 (we do support this) but rather the signing of the certificate. Ours was signed using SHA-1 where I believe Chrome and now the new transport in iOS wants it to be SHA-2.

We do have plans to re-sign/renew our certificates but haven't yet. I am not sure on an exact timeline.

Oh okay, thanks for the prompt reply. It would be awesome if you could re-sign before iOS 9 goes public, as it may break any apps that haven't been updated. As for myself, I'll temporarily be exempting your domain from App Transport Security. If anyone else is looking into how to do this, add this to your app's plist:

<key>NSAppTransportSecurity</key>
<dict>
    <key>NSExceptionDomains</key>
    <dict>
        <key>themoviedb.org</key>
        <dict>
            <key>NSIncludesSubdomains</key>
            <true/>
            <key>NSTemporaryExceptionAllowsInsecureHTTPLoads</key>
            <true/>
        </dict>
    </dict>
</dict>

Yes, that was going to be my next suggestion. Exempting our domain should work too 😉

We will get to it.

Thanks.

Any update on this issue as iOS 9 goes public today?

Hi Alex,

No updates right now, re-signing our SSL certificates hasn't been something that is very high on our priority list. As per Apple's own technote, adding the domain as an exemption is the only way to get around it in iOS 9 for now.

Cheers.

Yeah, i know how to whitelist and have already done it... but as long as you sign the cert using SHA-2 before Apple one day decides to turn off the whitelist option then Im happy! Thanks for the quick answer.

Hi all, I'm working on a iOS app and it's the first time I try to connect to API via HTTPS. This is the error I get back:

NSURLSession/NSURLConnection HTTP load failed (kCFStreamErrorDomainSSL, -9802) Error Domain=NSURLErrorDomain Code=-1200 "An SSL error has occurred and a secure connection to the server cannot be made." UserInfo={NSLocalizedDescription=An SSL error has occurred and a secure connection to the server cannot be made., NSLocalizedRecoverySuggestion=Would you like to connect to the server anyway?, _kCFStreamErrorDomainKey=3, NSUnderlyingError=0x7bb6ad20 {Error Domain=kCFErrorDomainCFNetwork Code=-1200 "(null)" UserInfo={_kCFStreamPropertySSLClientCertificateState=0, _kCFNetworkCFStreamSSLErrorOriginalValue=-9802, _kCFStreamErrorCodeKey=-9802, _kCFStreamErrorDomainKey=3, kCFStreamPropertySSLPeerTrust=, …

I've resolved with the domain exception, as suggested by the useful Dov's post.

I'm just asking if someone know others solution. I'm working with Swift 2 and Xcode 7.3.

Tks, Alessio.

Alessio, there is no other way until he has time to re-sign their SSL certificates. Whitelisting (domain exception) is the only way.

Hi Alex, ok, it's clear.

Thank you for your rapid answer.

Alessio.

P.S. We rolled out SHA2 SSL last night, the domain exception shouldn't be necessary anymore.

I've just tried with Xcode Simulator (no real iPhone) and it seems to be working.

Thank you, Alessio.

찾으시는 영화나 TV 프로그램이 없나요? 로그인 하셔서 직접 만들어주세요.

전체

s 검색 바 띄우기
p 프로필 메뉴 열기
esc 열린 창 닫기
? 키보드 단축키 창 열기

미디어 페이지

b 돌아가기
e 편집 페이지로 이동

TV 시즌 페이지

(우 화살표) 다음 시즌으로 가기
(좌 화살표) 이전 시즌으로 가기

TV 에피소드 페이지

(우 화살표) 다음 에피소드로 가기
(좌 화살표) 이전 에피소드로 가기

모든 이미지 페이지

a 이미지 추가 창 열기

모든 편집 페이지

t 번역 선택 열기
ctrl+ s 항목 저장

토론 페이지

n 새 토론 만들기
w 보기 상태
p 공개/비공개 전환
c 열기/닫기 전환
a 활동 열기
r 댓글에 글쓰기
l 마지막 댓글로 가기
ctrl+ enter 회원님의 메세지 제출
(우 화살표) 다음 페이지
(좌 화살표) 이전 페이지

설정

이 항목을 평가하거나 목록에 추가할까요?

로그인