Apple began deprecating TLS 1.0 and TLS 1.1 in iOS 15, iPadOS 15, macOS 12, watchOS 8, and tvOS 15, but that did not mean every Apple device stopped supporting those protocols on one date. Apple’s 2021 notice urged developers to move to TLS 1.2 or later and said support would be removed in future releases. Apple’s current security guide still lists TLS 1.0 through TLS 1.3 as supported; separately, newer guidance says some system-process connections may be refused from operating-system version 27.0 if their TLS configuration is noncompliant.
What Apple’s TLS deprecation means
TLS (Transport Layer Security) encrypts data exchanged between a client and a server. Apps such as Safari, Calendar, and Mail use TLS to establish encrypted communication. Developers can use higher-level APIs such as CFNetwork or lower-level APIs such as Network.framework to make network connections. Apple’s September 21, 2021 developer notice said the IETF had deprecated TLS 1.0 and 1.1 on March 25, 2021, and that Apple’s deprecation began with iOS 15, iPadOS 15, macOS 12, watchOS 8, and tvOS 15.
Deprecation is not the same as universal removal. Apple said support would be removed in future releases, while its TLS security guide, published January 28, 2026, currently lists TLS 1.0, 1.1, 1.2, and 1.3 as supported by iOS, iPadOS, and macOS. Keep four questions distinct: whether a protocol is supported by a platform, whether Apple has deprecated it, whether an API is deprecated, and whether a particular connection is refused for failing requirements.
What changed in 2021 for app developers
Apple advised developers whose apps still used TLS 1.0 or 1.1 to transition to TLS 1.2 or later, and recommended TLS 1.3, describing it as “faster and more secure.” Apple said apps with App Transport Security (ATS) enabled on all connections needed no changes for that 2021 notice. That assurance is specific to the notice; it should not be generalized to custom networking stacks or to newer rules for system-process connections.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Apple also identified deprecated Security.framework symbols for developers to remove. Review the 2021 notice for the affected symbols and check the networking code and configuration used by your app rather than assuming all connections follow ATS.
Newer requirements for certain system-process connections
Apple’s network preparation guidance says that starting with operating-system version 27.0, Apple operating systems may refuse connections to servers with outdated or noncompliant TLS configurations for specified system-process activities. This is a connection- and activity-specific requirement, not a statement that all TLS 1.0 or 1.1 traffic across all Apple devices is universally blocked. Administrators should consult Apple’s guidance to identify which activities and connection paths are in scope.
For affected system-process connections, Apple specifies TLS 1.2 or later, ATS-compliant cipher suites, and valid certificates meeting ATS standards. Its TLS guide also describes certificate and connection requirements, including forward secrecy. A server may therefore need more than a protocol-version change to meet the applicable requirements.
Will this break an app or website?
It depends on the connection path and the server’s configuration. A service that still relies on TLS 1.0 or 1.1 is a compatibility risk as platforms and services apply newer requirements, but the cited Apple guidance does not establish that every old-protocol connection already fails everywhere.
Rank #3
- App connection governed by ATS: Apple said no change was needed for the 2021 deprecation notice if ATS was enabled on every connection.
- Custom app networking: Verify the protocols and APIs the app actually uses and test each connection path against the servers it contacts.
- System-process connection: Check whether the activity is among those covered by Apple’s version 27.0 guidance, then validate protocol, cipher suite, and certificate compliance.
- Website or service: Check the server’s negotiated TLS version and certificate configuration; requirements for a particular Apple connection do not by themselves prove that every visitor or browser will behave identically.
What app developers should check
- Inventory connection paths. Identify app endpoints, networking frameworks, protocol overrides, and any Security.framework symbols Apple marked deprecated.
- Confirm server negotiation. Verify that every relevant endpoint can negotiate TLS 1.2 or later. Prefer TLS 1.3 where the client and server support it, consistent with Apple’s recommendation.
- Check ATS coverage. Determine whether ATS applies to every connection or whether custom configurations or networking implementations create exceptions.
- Test real workflows. Exercise the app against its production-equivalent endpoints, including services maintained by vendors, and diagnose certificate or cipher-suite problems separately from protocol-version problems.
What IT administrators should check
- Map affected services. Inventory device-management and other services used by Apple devices, then use Apple’s preparation page to identify which system-process activities and endpoints are covered.
- Find the server owner. Mark endpoints managed by outside vendors and ask them to confirm planned TLS, cipher-suite, and certificate compliance.
- Validate the complete configuration. Check TLS 1.2 or later, ATS-compliant cipher suites, and valid certificates for affected connections; account for forward secrecy where Apple’s TLS guidance applies.
- Allow remediation time. Apple warns that updating network configurations can take significant time, particularly when vendors maintain the servers. Organizations that lack internal TLS expertise may need a configuration audit or managed network-security support.
Certificate requirements are a separate, dated issue
Apple’s trusted-certificate requirements for iOS 13 and macOS 10.15 specify that RSA keys must be at least 2,048 bits, signatures must use SHA-2, and the server DNS name must appear in the Subject Alternative Name extension. For certificates issued after July 1, 2019, that guidance specifies server-auth EKU and a validity period of 825 days or fewer. These are certificate rules in guidance for those platform releases, not thresholds introduced by the 2021 TLS 1.0/1.1 deprecation. Check current Apple requirements for the platform and connection in question.
Quick Recap
Best Value
Rank #4
- Tamper Resistant Star Key Set Crafted with premium chrome vanadium steel, and each star tool folds neatly into the handle for quick, easy access.
- Details - The handle is engraved with size for quick identification with drilled tips to allow use.
- Portable - Keys fold compact for easy storage, Drilled tips allow use on tamper resistant security screws.
- Size:Full Size T-6, T-7, T-8, T-9, T-10, T-15 T-20, T-25, T-27 and T-30.
- And with 10 total star sizes able to match nearly all standard tamper resistant security screws on the market.
Keep the different changes straight
| Issue | What Apple says | Practical implication |
|---|---|---|
| TLS 1.0 and 1.1 deprecation | Apple announced the deprecation on September 21, 2021, beginning with iOS 15, iPadOS 15, macOS 12, watchOS 8, and tvOS 15; it said support would be removed in future releases. | Developers should migrate away from these protocols, but the announcement was not a claim of universal same-day blocking. |
| Protocol support in the current guide | Apple’s TLS guide published January 28, 2026 lists TLS 1.0 through TLS 1.3 as supported by iOS, iPadOS, and macOS. | Listed support does not cancel deprecation, deprecated API status, or connection-specific refusal rules. |
| Specified system-process connections | Starting with operating-system version 27.0, Apple systems may refuse connections with outdated or noncompliant TLS configurations for specified activities. | Check Apple’s affected-activity scope and validate each relevant connection’s protocol, cipher suite, and certificate. |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

