### App Transport Security (ATS) Overview

App Transport Security (ATS) could be bypassed with `NSAllowsArbitraryLoads` in the `Info.plist` for development, internal use, and testing – however, since iOS 11.x this is no longer the case. Suddenly, your API and microservices stop working and the Xcode log is littered with `tcp_timers tcp retransmit SYN` errors, signaling that the iOS kernel (XNU) is marking the connection potentially insecure and preventing it from being established.

### The LAN Before Time – A Network Without Domain Name Resolution

Those of us using interfaces through a properly certified SSL-enabled site remain unaffected by the above changes. However, anyone communicating within a private network without domain name resolution suffers. Consider the following scenario:

The main idea is to create certificates for our services and sign them via our master root SSL certificate authority. This way, we only need to install the root certificate on our test devices to access all services signed by our root certificate authority.

### Creating the Root Certificate Authority

We’ll be using **Apache 2** as the HTTP server, along with the **openssl** package. These commands should be issued within a terminal session:

1. **Create the Root CA Key**:
   
   `openssl genrsa -out rootCA.key 2048`

2. **Create the Actual Root Certificate**:
   
   `openssl req -x509 -sha256 -new -key rootCA.key -out rootCA.cer -days 3650 -sub /CN="Root CA for iOS"`

### Installing the Root CA on Your iOS Device

The **rootCA.cer** file can be used on your iDevices: email them or host them on a local web server for easy access. Open them within Mail or Safari, accept the dialogs, and enter the device password when necessary.

After installation, you must **enable the root certificate** on the iOS device ([Apple Support article](https://support.apple.com/en-us/HT204477)) under:

`Settings > General > About > Certificate Trust Settings`

Without this step, Wi-Fi communication will fail as though nothing was done – be sure to enable your cert.

### Creating and Signing the Certificates for Your Server

Now, let's create the certificate that will be installed on the server (repeat for each server needed):

1. **Create a Private Key for the Server**:
   
   `openssl genrsa -out server1.key 2048`

2. **Create the CSR Signing Request for the Server**:
   
   `openssl req -new -out server1.req -key server1.key -sub /CN=192.168.0.1`

3. **Sign the Request with the Root CA**:
   
   `openssl x509 -req -sha256 -in server1.req -out server1.cer -CAkey rootCA.key -CA rootCA.cer -days 3650 -CAcreateserial -CAserial serial`

4. **Install `server1.cer` and `server1.key` on Your Server** and enable the SSL module.

After this, all your iOS devices with the **rootCA** installed will be able to communicate with the servers via HTTPS, provided their certificates are issued and signed in this manner.
