"StoreKit Testing in Xcode" certificate is not trusted on iOS 26

Hello.

I have setup a StoreKit testing in the app that was and still is perfectly working on iOS 18.

Unfortunately when run on iOS 26 the following error gets printed in the console after calling Transaction.currentEntitlement(for:) method:

Failed to verify certificate chain due to client recoverable failure:
Error Domain=NSOSStatusErrorDomain Code=-67843 "“StoreKit Testing in Xcode” certificate is not trusted" UserInfo={NSLocalizedDescription=“StoreKit Testing in Xcode” certificate is not trusted, NSUnderlyingError=0x109de7e10 {Error Domain=NSOSStatusErrorDomain Code=-67843 "Certificate 0 “StoreKit Testing in Xcode” has errors: Root is not trusted;" UserInfo={NSLocalizedDescription=Certificate 0 “StoreKit Testing in Xcode” has errors: Root is not trusted;}}}

I'm not seeting any StoreKit Testing certificates in phone's certificate trust settings.

This test was performed on iOS 26.0 (23A341) with app built in Xcode 16.4.

FB20339145

It only happened in a single simulator, while others were intact. I did the reset of that particular simulator and the issue went away.

Just the night before the issue, my mac crashed and the shutdown stall file appeared in the DiagnosticReports folder

My original report was closed with notice that the issue has been fixed in iOS 27 beta 4. Unfortunately, while running iOS 27.0.1, I recently encountered this problem once again, but with a slightly different error message.

Failed to verify certificate chain due to client recoverable failure:
Error Domain=NSOSStatusErrorDomain Code=-67818 "“StoreKit Testing in Xcode” certificate is expired" UserInfo={NSLocalizedDescription=“StoreKit Testing in Xcode” certificate is expired, NSUnderlyingError=0x11ba5ef40 {Error Domain=NSOSStatusErrorDomain Code=-67818 "Certificate 0 “StoreKit Testing in Xcode” has errors: Certificate is not temporally valid;" UserInfo={NSLocalizedDescription=Certificate 0 “StoreKit Testing in Xcode” has errors: Certificate is not temporally valid;}}}

I managed to obtain the faulty certificate used by the OS using the following code and that certificate was indeed expired.

if let jws = try? await AppTransaction.shared.jwsRepresentation {
    var header = String(jws.split(separator: ".")[0])
        .replacingOccurrences(of: "-", with: "+")
        .replacingOccurrences(of: "_", with: "/")
    header += String(repeating: "=", count: (4 - header.count % 4) % 4)
    if let headerData = Data(base64Encoded: header),
       let json = try? JSONSerialization.jsonObject(with: headerData) as? [String: Any],
       let chain = json["x5c"] as? [String],
       let der = Data(base64Encoded: chain[0]) {
        let url = URL.temporaryDirectory.appending(path: "StoreKitTestingInXcode.cer")
        try? der.write(to: url)
        print("Certificate written to \(url.path())")
    }
}

Looks like there's a bug in iOS preventing it from creating a new certificate. The same issue with a different certificate was also observed on macOS 26.6 with a Catalyst app. I don't have any expired certificates in my Keychain, so it looks like this problematic certificate can't be deleted by the user alone.

New report: FB25081130

"StoreKit Testing in Xcode" certificate is not trusted on iOS 26
 
 
Q