Post

Replies

Boosts

Views

Activity

Reply to Developer ID Certificate (How to replace damaged certificate?)
@Quinn OK, following your advice: the one you’re looking for is Developer ID - G2 (Expiring 09/17/2031 00:00:00 UTC). If you download that and Quick Look it in the Finder, you’ll see its Subject Name details match the Issuer Name details from your screen shot. I downloaded and saw a file named DeveloperIDG2CA.cer (see annotation #5). In the Finder, I selected DeveloperIDG2CA.cer in the Downloads folder and chose File -> QuickLook (see annotation #6). The names in DeveloperIDG2CA.cer match the names in my untrusted Developer ID Application. (That's the one with the period from 01-21-2025 to 01-22-2030.) QUESTIONS Will adding DeveloperIDG2CA.cer to my login keychain change my untrusted Developer ID Application (from 01-21-2025 to 01-22-2030) to trusted (i.e., become valid)? How do I add DeveloperIDG2CA.cer to my login keychain?
Jan ’25
Reply to Developer ID Certificate (How to replace damaged certificate?)
@Quinn You write that the "most common cause is a missing issuer" for an invalid certificate. You suggest downloading the Apple Intermediaries that match the following two fields in the invalid certificate's Issue Name section from the Apple PKI page. Common Name Organizational Unit My invalid certificate shows two names (see annotation #3). On the Apple PKI page, I see these Apple Intermediate Certificates (see annotation #4). However, the Common Name and Organizational Unit names do not precisely match the Apple Intermediate Certificates page names. QUESTIONS Which Apple Intermediate Certificates do I download and install in KeyChain? How do I install the intermediary certificates? (Do I double-click the downloaded certificate?)
Jan ’25
Reply to Developer ID Certificate (How to replace damaged certificate?)
@Quinn I appreciate your respponse. The issue appears to be a missing issuer since I see a red cross. (See annotation #2 in my original post.) In your post Fixing an untrusted code signing certificate, you write in the section titled "Check for a missing issuer", If there’s a missing issuer in the chain of trust between your code signing identity’s certificate and a trusted anchor, Keychain Access shows a red cross with the text “… certificate is not trusted”. So what do I need to do? QUESTIONS How do I obtain the missing issuer? How do I correct the Developer ID Application so its status becomes "This certificate is valid"?
Jan ’25