When updating our Developer ID Application certificate, we encountered an issue where the Apple Developer portal consistently returns the exact same certificate file, regardless of the CSR submitted.
Observed Behavior & Test Steps:
We generated multiple new CSRs using both OpenSSL in the command line and Keychain Access (Certificate Assistant) on macOS following Apple's official guide: https://developer.apple.com/help/account/certificates/create-a-certificate-signing-request
We uploaded these distinct CSRs to the Developer Portal (Certificates -> Add New -> Developer ID Application) on separate attempts.
After downloading the issued .cer files, we performed a binary comparison (diff/checksum) across all of them. The comparison confirmed that the downloaded certificate files are 100% binary identical across all attempts.
Key Pairing Verification:
To further verify the key pairing, we checked the public key modulus hashes of the local Private Key and the downloaded .cer file via OpenSSL:
Check local Private Key Modulus Hash:
openssl rsa -noout -modulus -in new_developer_id.key | openssl md5
Check downloaded Certificate Modulus Hash:
openssl x509 -noout -modulus -in developer_identity.cer -inform DER | openssl md5
The resulting MD5 hashes do not match. Attempting to export them to PKCS#12 (.p12) consistently fails with the error:
no certificate matches private key.
Question:
Could this be related to a profile caching or binding issue on our team account, or is there a recommended way to clear this state and obtain a newly issued certificate?
Any guidance or advice would be greatly appreciated.