Apple To Stop SSL 3.0 Support For Push Notifications
Following the recently discovered security issue with SSL version 3.0, the the Apple Push Notification server will remove support for the specific encryption protocol on Wednesday. October 29. Google researchers revealed last week they found a flaw in SSL (Secure Sockets Layer) version 3.0, which was released many years ago. SSL has been replaced by TLS (Transport Layer Security), but the old versions are still used by some servers across the Internet and are supported by web browsers.
The researchers found it was possible using a man-in-the-middle attack to downgrade the SSL/TLS connection to the less-secure 3.0 version, where the flaw could allow an attacker to steal a person's authentication cookies.
The updated Apple Push Notification service means that changes to your servers may be required to remain compatible. Providers that support both TLS and SSL 3.0 will not be affected and require no changes.
To check for compatibility, Apple has already disabled SSL 3.0 on the Provider Communication interface in the development environment only. Developers can test in this development environment to make sure push notifications can be sent to applications.