Account – Hilfe
Account Zertifikate Replacing Developer ID certificates issued from the previous Sub-CA
Replacing Developer ID certificates issued from the previous Sub-CA
The original Developer ID Certification Authority expires on February 1, 2027. After that date, certificates issued from the original authority can no longer be used for signing and must be replaced with certificates from the current Developer ID Certification Authority (G2). Certificates issued from G2 are valid for one year and must be renewed annually.
Required role: Account Holder
Find out if your certificates are affected
In Certificates, Identifiers & Profiles, click Certificates in the sidebar and review your Developer ID Application and Developer ID Installer certificates. Any certificates expiring on or before February 1, 2027, are likely affected. However, the expiration date alone doesn’t prove which authority issued a certificate. To be certain, check the issuer.
A team can hold a certificate from each authority with identical names, such as the same Developer ID Installer entry twice, differing only in expiration date. To tell them apart, select a certificate in Keychain Access, expand the Issuer Name field, and review the Organizational Unit field:
-
If you see Apple Certification Authority: The certificate was issued from the previous Sub-CA. Replace this certificate.
-
If you see G2: The certificate was issued from the current Sub-CA. No action needed.
Note: Check your own certificate, not the Developer ID Certification Authority entry in your keychain. That entry is the authority itself, and it’s issued by Apple Root CA, whose Organizational Unit is also Apple Certification Authority.
Create a replacement certificate
-
Sign in to Certificates, Identifiers & Profiles.
-
Click Certificates in the sidebar, then click the add button (+).
-
Under Software, select Developer ID Application or Developer ID Installer, then click Continue. If you hold both types, repeat these steps for each, since one certificate does not cover the other.
-
If you’re asked to select a Developer ID Certificate Intermediary, choose G2 Sub-CA (Xcode 11.4.1 or later). Any other option might issue a certificate from the expiring Certificate Authority.
-
Follow the instructions to create a certificate signing request. Upload it, then download your new certificate.
-
Double-click the downloaded file to install it in your keychain, then update your systems to sign with the new certificate.
Because you can hold up to five Developer ID Application and five Developer ID Installer certificates at a time, you can create and test a replacement before your current certificate expires.