Certificates, Identifiers & Profiles

RSS for tag

Discuss the technical details of security certificates, identifiers, and profiles used by the OS to ensure validity of apps and services on device.

Certificates, Identifiers & Profiles Documentation

Posts under Certificates, Identifiers & Profiles subtopic

Post

Replies

Boosts

Views

Activity

New Capabilities Request Tab in Certificates, Identifiers & Profiles
You can now easily request access to managed capabilities for your App IDs directly from the new Capability Requests tab in Certificates, Identifiers & Profiles > Identifiers. With this update, view available capabilities in one convenient location, check the status of your requested capabilities, and see any notes from Apple related to your requests. Learn more about capability requests.
0
0
3.5k
Jun ’25
Apple Distribution signature fails its designated requirement — possible Unicode normalization issue
App Store Connect rejects my iOS Flutter app with error 90035: “Code failed to satisfy specified code requirement(s).” The error affects the main app executable, App.framework, and Flutter.framework. Environment: macOS 26.5.2 Xcode 26.6 Flutter 3.44.8 Individual Apple Developer Program membership The Release archive and App Store IPA build successfully. The exported IPA is signed with an Apple Distribution certificate and contains the correct TeamIdentifier. However, verification reports: Runner.app: valid on disk Runner.app: does not satisfy its designated Requirement The certificate Common Name contains a non-ASCII character: “Ç”. The generated designated requirement appears to represent this character using a decomposed Unicode form. I suspect a Unicode-normalization mismatch between the certificate Common Name and the embedded designated requirement. I am also unable to create a local Apple Distribution certificate: Xcode Manage Certificates reports: “The data couldn’t be read because it isn’t in the correct format.” The Apple Developer certificate portal reports “An unexpected error occurred” after I upload a valid CSR. Has anyone encountered this issue when an Apple Distribution certificate Common Name contains a non-ASCII character? Is there a supported way to regenerate the cloud-managed certificate or have Apple repair the team’s certificate state? I can provide sanitized codesign output if an Apple engineer needs additional diagnostic information.
15
0
1.3k
17h
Xcode CodeSign fails with errSecInternalComponent despite valid Apple Development certificate
Hi everyone, I’m trying to get my iOS app running on a physical iPhone for real-device testing, but I’m blocked by a persistent code-signing issue in Xcode. The project compiles successfully, but when I select my physical iPhone as the destination, the build fails during the signing stage: errSecInternalComponent Command CodeSign failed with a nonzero exit code The app therefore never gets installed on the device. What I’ve checked: Xcode recognises my Apple Development certificate. security find-identity -v -p codesigning reports the identity as valid. The certificate is present in my login keychain. Keychain Access shows the certificate with its private key underneath it. My login keychain is unlocked. The keychain search list contains my login keychain and the System keychain. I checked both keychains for the corresponding private key. There are no custom trust settings. The particularly strange part is that signing fails outside Xcode too. I tested signing /usr/bin/true directly using the same Apple Development identity, and that also fails with: errSecInternalComponent I also attempted to repair the private key’s signing access/partition list, but received: The specified item is no longer valid. It may have been deleted from the keychain. Certificate situation Xcode → Manage Certificates currently shows two Apple Development certificates: One current certificate One older certificate marked “Not in Keychain” When I try to create a new Apple Development certificate, Xcode says: You already have a current Development certificate or a pending certificate request. This is the only Mac I have used with this Apple Developer account, so there isn’t another Mac from which I can recover or export the original private key. What should I do? I’m trying to understand the safest next step without making the certificate/keychain situation worse. Should I: Revoke the older certificate and create a new development certificate/private-key pair? Try to repair the existing signing identity/private key? Take another Apple-supported approach? The immediate goal is to get the app onto a physical iPhone so I can begin real-device testing, followed by QA/beta testing and App Store launch. Any advice on what is actually causing errSecInternalComponent in this situation, and the safest way to resolve it, would be greatly appreciated. I can provide additional Terminal output, screenshots, or Xcode logs if helpful. Thanks!
1
1
41
1d
App Settings silently fails to select Team / generate Personal Team certificate
Hello, trying to create a simple utility for personal use using Swift Playgrounds. I want to install the app locally on my iPad, I don’t want to have Swift Playgrounds open to run. Have not been able to resolve. See below: Environment: iPadOS Version: iPadOS 26.6.2 (23G90) Hardware: iPad Pro M4 Swift Playgrounds Version: 4.5+ Steps to Reproduce: Create a new App project (+ App button). Open App Settings > Team & Bundle Identifier. Ensure a free Apple ID is signed in. Tap the user's name under the "Team" list. Expected Result: The UI should register the selection, generate a local provisioning profile, and reveal the "Install on this iPad" button. If the user needs to accept a web agreement, an alert should guide them. Actual Result: Nothing happens. The row registers the touch visually, but the state remains "No Team Selected, Unknown Bundle Identifier". No error message is thrown, blocking local installation entirely. Thanks
1
1
72
2d
Unique App ID prefix migration stalled; Mac App Store validation fails with 90286/91130 on a universal-purchase app
My two apps, com.qrafter.Qrafter and com.qrafter.QrafterPro, have been on the iOS App Store since 2011, and their App IDs still use my team's unique App ID prefix 99T3FA87E9 instead of the Team ID GH4CGS3B5H. I'm adding native Mac versions to the same App Store records (universal purchase), so the bundle IDs can't change. Every profile Apple generates for these App IDs pairs com.apple.application-identifier = 99T3FA87E9.com.qrafter.Qrafter with com.apple.developer.team-identifier = GH4CGS3B5H. iOS uploads are accepted, but Mac App Store validation (xcrun altool --validate-app -t macos) rejects even a minimal one-window app with exactly two errors: Invalid code signing entitlements. … the "99T3FA87E9.com.qrafter.Qrafter" value for the com.apple.application-identifier key … isn't supported. This value should be a string that starts with your Team ID, followed by a dot ("."), followed by the bundle ID. (90286) Invalid Provisioning Profile. … Invalid 'com.apple.application-identifier' entitlement value. (91130) Following "Code Signing Identifiers Explained" (thread 811970), I requested the prefix migration through Contact Us on 4 September (case 102953576372). On 20 September Developer Support asked me to confirm the one-time keychain data loss described in "App ID Prefix Change and Keychain Access" (thread 706128), and I confirmed. Since then the case has had no reply despite follow-ups on 24 and 29 September, and as of 6 October both App IDs still show 99T3FA87E9. Two questions: Is there anything else I need to do to get case 102953576372 completed, or a better route to escalate it? Is there any way to ship a Mac App Store build for these App IDs before the migration, or is the migration the only path? I have a minimal sample project and the full validation log if that helps.
2
0
126
4d
Correctly requesting com.apple.developer.driverkit.userclient-access
I'm asking about how to ask for an addition to a managed entitlement, where we already have a grant of that entitlement (with a different value) and we already have other managed entitlements granted. This post https://developer.apple.com/forums/thread/789176 tells me I can request entitlements at the Requests tab here: https://developer.apple.com/account/resources/, which leads me to this form: https://developer.apple.com/contact/request/system-extension/ The form URL doesn't specify a particular App Identifier, but is the Identifier implied with this form submission? Or, put another way, is the entitlement we're asking for attached only to the Team ID, or also to the bundle ID of the app which is going to use the entitlement? So if I made another app which talks to my dext, I'd have to ask again for userclient-access to the same dext, but from a different bundle ID? The form says "Which DriverKit entitlements do you need" and "select all that apply", but I'm unclear about whether I need to request ALL the DriverKit entitlements we need for all our apps, or only for the specific App Identifier I reached this form from. It also isn't clear if I need to check both the USB Transport and the UserClient Access boxes in my case. We already have UserClient Access granted for at least one bundle ID, and I want to add another. We already have USB. Transport granted for two different vendor IDs. Do I need to mention that in my request here, and also check the USB Transport box, although I'm not requesting any new vendor ID values? I don't want to end up with new profiles which break new builds of existing apps which were relying on previously-granted entitlements that are now missing from the newly-generated profiles. Here: https://developer.apple.com/forums/thread/822652 user JackLongbow submitted a request for UserClient Access for two bundle IDs, presumably in the form of a simple two-line string like this: com.turing.TuringTouch com.turing.TuringTouch.TouchDriver but the resulting provisioning profile was malformed, it contained this value under com.apple.developer.driverkit.userclient-access <string>com.turing.TuringTouch com.turing.TuringTouch.TouchDriver</string> the Forum post said that the approved entitlement looks like this: <array> <string>com.turing.TuringTouch</string> <string>com.turing.TuringTouch.TouchDriver</string> <string>com.turing.TuringTouchDriver</string> <string>com.turing.virtualpad</string> <string>com.turingdraw.DigidrawTouch.DigidrawDriver</string> </array> Should I be formatting my request as above, as a chunk of xml, or is a plain text list of bundle IDs, one per line, acceptable? Is there a way for us to get a summary of all the managed entitlements already granted to our team? At present, it seems like I have to pick a particular profile, download it, and QuickLook at it - but not all profiles contain all entitlements, just as apps don't have to claim all the entitlements the profile offers .
1
0
661
1w
Developer ID Application Issue: Repeatedly getting the same certificate
When updating our Developer ID Application certificate, we encountered an issue where the Apple Developer portal consistently returns the exact same certificate file, regardless of the CSR submitted. Observed Behavior & Test Steps: We generated multiple new CSRs using both OpenSSL in the command line and Keychain Access (Certificate Assistant) on macOS following Apple's official guide: https://developer.apple.com/help/account/certificates/create-a-certificate-signing-request We uploaded these distinct CSRs to the Developer Portal (Certificates -> Add New -> Developer ID Application) on separate attempts. After downloading the issued .cer files, we performed a binary comparison (diff/checksum) across all of them. The comparison confirmed that the downloaded certificate files are 100% binary identical across all attempts. Key Pairing Verification: To further verify the key pairing, we checked the public key modulus hashes of the local Private Key and the downloaded .cer file via OpenSSL: Check local Private Key Modulus Hash: openssl rsa -noout -modulus -in new_developer_id.key | openssl md5 Check downloaded Certificate Modulus Hash: openssl x509 -noout -modulus -in developer_identity.cer -inform DER | openssl md5 The resulting MD5 hashes do not match. Attempting to export them to PKCS#12 (.p12) consistently fails with the error: no certificate matches private key. Question: Could this be related to a profile caching or binding issue on our team account, or is there a recommended way to clear this state and obtain a newly issued certificate? Any guidance or advice would be greatly appreciated.
4
0
976
1w
Cloud-managed distribution signing writes a non-ASCII certificate name decomposed (NFD) into the designated requirement, so every upload fails ITMS-90035
Every App Store Connect upload I sign with my Cloud Managed Apple Distribution certificate is rejected with ITMS-90035 ("Code failed to satisfy specified code requirement(s)") for the app binary and its widget extension. It happens from Xcode Cloud and from a manual Organizer upload alike. I think I have found the cause, and it looks like a Unicode normalization bug in cloud-managed signing. The certificate holder's name contains an umlaut: "Apple Distribution: Jonathan Thorsten Müller (…)". In the certificate the "ü" is precomposed (NFC, UTF-8 c3 bc). In the designated requirement that the export writes into the signature it is decomposed (NFD, "u" + U+0308, UTF-8 75 cc 88): certificate subject CN ... 4d c3 bc 6c 6c 65 72 ... ("Müller", NFC) designated requirement leaf CN ... 4d 75 cc 88 6c 6c 65 72 ... ("Müller", NFD) The bytes differ, so the signature can never satisfy its own designated requirement. It reproduces with Xcode 27.0's App template, unmodified, and without uploading anything: Archive for a generic iOS device. With no distribution identity in the local keychain, export for App Store Connect to a folder (export options: method app-store-connect, destination export, signingStyle automatic). DistributionSummary.plist shows "Cloud Managed Apple Distribution". xcodebuild -exportArchive -archivePath MyApp.xcarchive -exportPath out -exportOptionsPlist ExportOptions.plist -allowProvisioningUpdates Verify the exported app: codesign --verify --strict -vv Payload/MyApp.app Result: "valid on disk", then "does not satisfy its designated Requirement". Compare the requirement with the certificate's subject: codesign -d -r- Payload/MyApp.app codesign -d --extract-certificates Payload/MyApp.app openssl x509 -inform DER -in codesign0 -noout -subject -nameopt RFC2253,-esc_msb | xxd The same archive exported with a regular Apple Distribution certificate (same name, private key in my keychain) writes the NFC form, verifies, and App Store Connect accepts that upload. That works for manual uploads only. Xcode Cloud always signs with the cloud-managed certificate, so I cannot distribute from Xcode Cloud at all. Setup: Xcode 27.0 (27A266a) locally and in Xcode Cloud, automatic signing, one team, no custom code-signing flags. Product name, bundle IDs and file names are plain ASCII. Questions: Is this a known issue with cloud-managed signing and non-ASCII certificate names? Is there a supported way to have Xcode Cloud sign without hitting it in the meantime? If you see ITMS-90035 on Xcode Cloud and your name (or your team's) has an accent or umlaut in it, you may be hitting the same thing: run step 3 on an exported IPA and check.
3
0
522
1w
Developer ID provisioning profile missing Sensitive Content Analysis entitlement
I’m trying to distribute a macOS application outside the Mac App Store using Developer ID signing and notarization. The Sensitive Content Analysis capability is enabled for this App ID in Certificates, Identifiers & Profiles. My application requires the following entitlement: com.apple.developer.sensitivecontentanalysis.client However, when I create and download a new Developer ID provisioning profile for this App ID, the generated profile does not contain this entitlement. I have regenerated and downloaded the profile after confirming that Sensitive Content Analysis is enabled. I also decoded the newly generated .provisionprofile to inspect its entitlements. It contains the application identifier, team identifier, and keychain access groups, but does not contain com.apple.developer.sensitivecontentanalysis.client. As a result, Xcode will not export the Developer ID build because the application requests the Sensitive Content Analysis entitlement but the provisioning profile does not authorize it. Does anyone know the answers to these questions: Is com.apple.developer.sensitivecontentanalysis.client supported for macOS applications distributed outside the Mac App Store using Developer ID? If it is supported, why is the entitlement not being included in newly generated Developer ID provisioning profiles for this App ID? Is there an additional approval, agreement, or configuration required for this entitlement to be included in a Developer ID profile? Sensitive Content Analysis is a required feature of this application, so removing the entitlement is not an option for our distribution build.
4
0
1.5k
1w
iPadOS DriverKit Capability Request Issues
We have a complete iPadOS DriverKit USB extension for a Stripe Reader M2 (USB-C, M-series iPad). Development builds sign and run. We cannot ship Ad Hoc, App Store, or Enterprise builds because the distribution DriverKit entitlements are either not granted or not present in the provisioning profile Apple generates. Stripe’s iOS USB instructions say to request the entitlement at developer.apple.com/system-extensions: select HID and USB Transport, and enter USB vendor ID 11369. Platform is iPadOS. The extension also needs com.apple.developer.driverkit. The host app uses com.apple.developer.driverkit.communicates-with-drivers. We have two teams. The driver bundle ID is prefixed with the host app bundle ID and signed with the same team. Inc — Team ID HPL6Q4V5TF (Development, Ad Hoc, App Store) Host app Driver extension com.atxinnovation.union.development com.atxinnovation.union.development.usbDriver com.atxinnovation.union.qa com.atxinnovation.union.qa.usbDriver com.atxinnovation.union.production com.atxinnovation.union.production.usbDriver These are not granted. Latest submission is system-extensions request 39WL64S3LR (September 3, 2026). That form has no status page, and we have received no email. LLC — Team ID 3MAPQA4NZ6 (Enterprise in-house) Host app Driver extension com.atxinnovation.union.enterprise com.atxinnovation.union.enterprise.usbDriver Capability request ACL9VQ3BA4. The portal shows DriverKit and DriverKit USB Transport – VendorID granted and enabled on com.atxinnovation.union.enterprise.usbDriver. The Universal Distribution profile POS Prod USB Driver (platform iOS, active, expires 2027/01/22, UUID a3627c1e-451d-4d62-b871-1cb6fe21431e, created 2026-09-02 16:05:20 UTC) lists those capabilities as enabled on the Review Provisioning Profile page. The downloaded profile does not contain them. Decoding it yields only: application-identifier com.apple.developer.team-identifier get-task-allow keychain-access-groups The string driverkit does not appear in the profile. We regenerated it five times, including deleting and recreating the profile, with the same result. DriverKit development profiles for the corresponding development App ID do contain com.apple.developer.driverkit and com.apple.developer.driverkit.transport.usb. Xcode then fails the archive: Provisioning profile "POS Prod USB Driver" doesn't include the com.apple.developer.driverkit entitlement. We also do not know which idVendor values the VendorID grant assigned. The extension must match them exactly. We need 11369. What we already tried July 30: Account Holder submitted DriverKit and DriverKit USB Transport for both teams through the system-extension Contact Us form. No confirmation email. That form does not collect bundle IDs. Those July requests later showed up on the host App ID com.atxinnovation.union.enterprise, not on the usbDriver App IDs. August 12: Resubmitted on each usbDriver App ID under Certificates, Identifiers & Profiles → Capability Requests. Enterprise request ACL9VQ3BA4. August 27: Developer Support case 20000149322724. The reply pointed us back at the capability status page. September 2: Enterprise grant appeared. Enabling it on the App ID and regenerating the distribution profile still produced a profile with no DriverKit entitlements. Developer Support case 102951939894. No resolution. September 3: Resubmitted the Inc team via the system-extensions form (39WL64S3LR). The form would not accept another LLC submission because that App ID is already granted. No status since. What we are Requesting Grant DriverKit, HID, and USB Transport (vendor ID 11369) for iPadOS — Development, Ad Hoc, and App Store — on the three Inc driver App IDs above. Assistance debugging the issue of failing to embed the already-granted DriverKit entitlements in the LLC Enterprise distribution profile for com.atxinnovation.union.enterprise.usbDriver, and confirmation of the assigned idVendor values.
1
8
1.7k
2w
codesign authorization dialog hangs; XCTest re-sign fails with errSecInternalComponent while standalone signing succeeds
I’m seeing a reproducible code-signing failure on macOS 26.6.2 with Xcode 26.6 while building an iOS XCTest bundle for a physical device. A newly created Apple Development identity is valid and can successfully sign and verify a standalone test binary using /usr/bin/codesign. However, xcodebuild build-for-testing reaches the first XCTest re-sign operation and the macOS Keychain authorization dialog for the same development private key becomes unresponsive after entering the login Keychain password and clicking “Always Allow.” The failing command is effectively: /usr/bin/codesign --force --sign -o runtime --timestamp=none ... libXCTestSwiftSupport.dylib and returns: errSecInternalComponent The exact same development certificate successfully signs a standalone binary immediately beforehand. The build is running from an ordinary logged-in Terminal session, not SSH or CI. After aborting the build, inspection showed the XCTest artifacts retained Apple’s original Software Signing certificate rather than the Development certificate, confirming the re-sign did not complete. I have already recreated the login Keychain once and recreated the Apple Development identity. I do not want to make further Keychain ACL/partition changes without understanding the underlying cause. Question: What diagnostic should I collect to determine why SecurityAgent/codesign cannot complete private-key authorization for the XCTest re-sign operation when direct signing with the same identity succeeds?
3
0
636
2w
Persistent ITMS-90034 on new Individual account despite verified Apple Distribution signature
Hello, I am experiencing persistent ITMS-90034 when trying to upload the first iOS app from a newly enrolled Individual Apple Developer Program account. The exact error is: Validation failed (409) Missing or invalid signature. The bundle at "Payload/[App].app" is not signed using an Apple submission certificate. (ID: 90034) I have already performed extensive signing checks and troubleshooting: Apple Developer Program membership is active. A valid Apple Distribution certificate is installed in Keychain together with its private key. security find-identity -v -p codesigning reports both Apple Development and Apple Distribution as valid identities. The correct Team and Bundle ID are selected. Automatic signing is enabled in Xcode. Provisioning profile caches and DerivedData were deleted, profiles were downloaded again, and a completely fresh archive was created. Xcode's App Store Connect export review explicitly shows: Certificate: Apple Distribution App Store provisioning profile for the correct Bundle ID get-task-allow = false beta-reports-active = true I then exported the IPA locally using Xcode's App Store Connect distribution workflow and independently inspected the actual exported binary with codesign. The main application reports: Identifier=[Bundle ID] Authority=Apple Distribution: [Name] ([Team ID]) Authority=Apple Worldwide Developer Relations Certification Authority Authority=Apple Root CA TeamIdentifier=[Team ID] I also separately checked the embedded Capacitor.framework and Cordova.framework. Both are signed with the same Apple Distribution identity and Team ID and show the same WWDR -> Apple Root CA trust chain. I checked Keychain as suggested in similar forum discussions. The Apple Distribution certificate has its private key, the WWDR intermediate certificates are present and valid, and certificate verification reports: "...certificate verification successful." Despite all of the above, a fresh upload from Xcode Organizer still consistently fails with the same ITMS-90034. This appears very similar to other recent reports involving newly enrolled Individual Developer accounts where correctly signed binaries are rejected by App Store Connect. I also opened an Apple Developer Support case (case 20000149684934). So far I have received general signing/troubleshooting documentation, but the issue remains unresolved. At this point, is there any additional local signing verification I should perform, or could this indicate an account/team-level App Store Connect signing validation issue that needs to be investigated on Apple's side? I would especially appreciate guidance from Apple DTS on what diagnostic information would be useful to distinguish a local certificate-chain issue from an App Store Connect/account-side validation issue. Thank you.
3
0
1.2k
3w
Certificate on keychain not found by codesign
Since my Apple Distribution signing certificate had expired I recently got a new one via https://developer.apple.com/account/resources/certificates/list and installed in on my login keychain. Since I had some issues with signing I suspected that codesign might still be trying to use an old expired certificate (as they have the same name "Apple Distribution: ()"). So to fix this I figured I could just delete the old expired certificate from Keychain Access so there was only the valid new certificate there with the same name. However, after doing this and trying to use it with codesign I get the following error error: The specified item is no longer valid. It may have been deleted from the keychain. In other words it seems it's not finding the new valid certificate and somehow still linking the name to the old certificate that it rightly guesses is removed. Following the tips from https://developer.apple.com/forums/thread/701514 I used security find-identity -p codesigning -v to check for installed codesigning certificates, and this listed the new certificate as expected. Using another tip in the same post I saw that you can also use the certificate hash as an identifier beside the name, and using this I can use it with codesign to sign. However, it's still not finding it via the name (or rather, it's still finding the old now removed one). What could be the reason for codesign not finding the correct new valid certificate based on the name and instead still finding the old one? Maybe there's some reference set somewhere to point the name towards specifically the old certificate?
1
0
567
3w
"How to" for dext distribution
I have a DriverKit system extension (dext) that uses PCIDriverKit. I would like to get the build environment straightened out to successfully distribute the dext and associated software to end users. There are three types of software involved: The Dext-hosting application - this is the application that must be installed to /Applications/, and will perform the registration of the dext. The dext is deployed "within" this application, and can be found in the /Contents/Library/SystemExtensions folder of the app bundle. The dext itself - this is the actual binary system extension, which will be registered by its owning application, and will operate in its own application space independent of the hosting application. Additional applications that communicate with the dext - these are applications which will connect to the dext through user clients, but these applications do not contain the dext themselves. There are multiple locations where settings need to be exactly correct for each type of software to be signed, provisioned, and notarized properly in order to be distributed to users: developer.apple.com - where "identifiers" and "provisioning profiles" are managed. Note that there are differences in access between "Team Agent", "Admin", and "Developer" at this site. Xcode project's Target "Signing & Capabilities" tab - this is where "automatically manage signing" can be selected, as well as team selection, provisioning profile selection, and capabilities can be modified. Xcode project's Target "Build Settings" tab - this is where code signing identity, code signing development team, code signing entitlements file selection, Info.plist options and file selection, and provisioning profile selection. Xcode's Organizer window, which is where you manage archives and select for distribution. In this case, I am interested in "Developer ID" Direct Distribution - I want the software signed with our company's credentials (Team Developer ID) so that users know they can trust the software. Choosing "automatically manage signing" does not work for deployment. The debug versions of software include DriverKit (development) capability (under App ID configuration at developer.apple.com), and this apparently must not be present in distributable provisioning. I believe this means that different provisioning needs to occur between debug and release builds? I have tried many iterations of selections at all the locations, for all three types of binaries, and rather than post everything that does not work, I am asking, "what is supposed to work?"
22
0
4.6k
Sep ’26
ppq.apple.com unavailable — developer-signed apps cannot be verified
Hello, ppq.apple.com appears to be unavailable. The issue is reproducible from multiple networks/devices. Requests to https://ppq.apple.com fail, preventing iOS from verifying developer-signed applications. This results in the device displaying an error indicating that an Internet connection is required to verify the developer/app. The issue appears to be server-side rather than related to the developer certificate or provisioning profile. Affected: (tested on) ppq.apple.com HTTPS / TCP 443 iOS 9.3.4 iPhone 5S [07/09/2026/20:07 + Zurich] Example: curl -I https://ppq.apple.com Response: HTTP/2 404 server: Apple date: Mon, 07 Sep 2026 18:08:13 GMT content-type: text/plain; charset=UTF-8 content-length: 0 x-b3-spanid: bdf368a2edbdbef7 x-b3-traceid: bdf368a2edbdbef7 x-b3-sampled: 1 strict-transport-security: max-age=31536000; includeSubdomains x-frame-options: SAMEORIGIN x-content-type-options: nosniff x-xss-protection: 1; mode=block Please investigate the availability of the PPQ service.
0
1
435
Sep ’26
How to get help with Signing and Notarization...
I have been trying to use Apple Developer Support to help with issues I'm having preventing me from signing and notarizing my apps. Delayed and not helpful responses from support. This has been going on for several weeks. I find it hard to believe that a Multi-Trillion Dollar company can't help me with my issues. I have what I think is a good certificate and private key as well as my App-Sepcific Password. The problem is that when trying to sign my apps, I get a popup indicating that that it's trying to sign in to Keychain using my first Name (Steve). My login on my system is "Stephen" which works fine for login and anything that wants to access Keychain. I need some help trying to resolve this.
1
0
796
Aug ’26
How to release an App ID stuck on a personal (free) team so it can be registered under my paid organization team?
I have two Apple Developer accounts under different Apple IDs: a free "Personal Team" account and a separate paid Organization account. Before my organization's Program enrollment was approved, I built an app to a physical device using Xcode signed into my personal account, which auto-registered an App ID under that personal team. Now that my organization account is active, I can't register the same App ID under the organization — both the web portal and Xcode's automatic signing return "not available," since it's already reserved under my personal team. Since personal (free) accounts have no web portal access, I can't see or manage that registration anywhere to release it myself. I own both accounts. Is there any self-service way to release an App ID from a personal team, or is contacting Apple Developer Support the only option? If support is required, is there a faster route than the standard contact form (I submitted a request several days ago with no reply yet)?
1
0
893
Aug ’26
Develop Certificate Has Wrong Apple ID???
When trying to develop an Apple Shortcut, the shortcut doesn't appear (after many open, quit, adding permissions, etc.). My only Apple Account is my name associated with an Apple ID of QZ99..... However, when I try to check one (of many reasons) why it does not show up with Terminal: codesign -dv --verbose=4 "/Applications/My App.app" etc, it shows something "rejected" Authority=Apple Worldwide Developer Relations Certification Authority Authority=Apple Root CA Signed Time=Aug 25, 2026 at 1:26:38 PM Info.plist entries=22 TeamIdentifier=QZ99... Runtime Version=26.5.0 Sealed Resources version=2 rules=13 files=4 Internal requirements count=1 size=204 /Applications/Write Create Date from Original.app: rejected origin=Apple Development: My Account (K533...) The K533... is different than my Team ID of QZ99... Could that be a reason my app is not registered with Shortcuts? Is that expected functionality? I guess I expected my Team ID to appear everywhere even after I deleted my account in Xcode, removed a current and expired certificate associated with K533 in Keychain, and then added my account back, and let Xcode regenerate a certificate.
2
0
712
Aug ’26
NSE Filtering Entitlement not carried over after App Store app transfer
We completed an App Store app transfer and the Notification Service Extension Filtering Entitlement (com.apple.developer.usernotifications.filtering) did not transfer with the app. App Apple ID: 6760007376 NSE Bundle ID: io.nolink.ios.nse New Team ID: M85WA8W78C Previous Team ID: V2E3A94DC9 The app, bundle IDs, and App Store presence all moved normally, but the entitlement is not available on the new team, so we cannot sign the NSE with the configuration the app previously shipped with. Our app is an encrypted messenger and this breaks incoming call handling for live users. Two questions: Is there an official process for re-associating a previously approved entitlement with the receiving team after a transfer, or does the new team always have to submit a fresh request? Could entitlements tied to a specific App ID move with the app during a transfer, the same way bundle IDs do? We have an open support case, but wanted to raise the general question here too.
2
0
1.4k
Aug ’26
Xcode Personal Team certificate shows “Missing Private Key” and cannot be replaced
I use a free Apple Personal Team with Xcode for on-device testing. My Apple Development certificate created on 15 August 2026 shows “Missing Private Key”, and Xcode is not allowing me to create a fresh replacement certificate. I have already contacted Apple Developer Program Support, and they directed me to the Apple Developer Forums for technical assistance. How can I revoke/reset the unusable certificate or clear the certificate state for my Personal Team so that Xcode can create a new Apple Development certificate?
1
0
363
Aug ’26
New Capabilities Request Tab in Certificates, Identifiers & Profiles
You can now easily request access to managed capabilities for your App IDs directly from the new Capability Requests tab in Certificates, Identifiers & Profiles > Identifiers. With this update, view available capabilities in one convenient location, check the status of your requested capabilities, and see any notes from Apple related to your requests. Learn more about capability requests.
Replies
0
Boosts
0
Views
3.5k
Activity
Jun ’25
Apple Distribution signature fails its designated requirement — possible Unicode normalization issue
App Store Connect rejects my iOS Flutter app with error 90035: “Code failed to satisfy specified code requirement(s).” The error affects the main app executable, App.framework, and Flutter.framework. Environment: macOS 26.5.2 Xcode 26.6 Flutter 3.44.8 Individual Apple Developer Program membership The Release archive and App Store IPA build successfully. The exported IPA is signed with an Apple Distribution certificate and contains the correct TeamIdentifier. However, verification reports: Runner.app: valid on disk Runner.app: does not satisfy its designated Requirement The certificate Common Name contains a non-ASCII character: “Ç”. The generated designated requirement appears to represent this character using a decomposed Unicode form. I suspect a Unicode-normalization mismatch between the certificate Common Name and the embedded designated requirement. I am also unable to create a local Apple Distribution certificate: Xcode Manage Certificates reports: “The data couldn’t be read because it isn’t in the correct format.” The Apple Developer certificate portal reports “An unexpected error occurred” after I upload a valid CSR. Has anyone encountered this issue when an Apple Distribution certificate Common Name contains a non-ASCII character? Is there a supported way to regenerate the cloud-managed certificate or have Apple repair the team’s certificate state? I can provide sanitized codesign output if an Apple engineer needs additional diagnostic information.
Replies
15
Boosts
0
Views
1.3k
Activity
17h
Xcode CodeSign fails with errSecInternalComponent despite valid Apple Development certificate
Hi everyone, I’m trying to get my iOS app running on a physical iPhone for real-device testing, but I’m blocked by a persistent code-signing issue in Xcode. The project compiles successfully, but when I select my physical iPhone as the destination, the build fails during the signing stage: errSecInternalComponent Command CodeSign failed with a nonzero exit code The app therefore never gets installed on the device. What I’ve checked: Xcode recognises my Apple Development certificate. security find-identity -v -p codesigning reports the identity as valid. The certificate is present in my login keychain. Keychain Access shows the certificate with its private key underneath it. My login keychain is unlocked. The keychain search list contains my login keychain and the System keychain. I checked both keychains for the corresponding private key. There are no custom trust settings. The particularly strange part is that signing fails outside Xcode too. I tested signing /usr/bin/true directly using the same Apple Development identity, and that also fails with: errSecInternalComponent I also attempted to repair the private key’s signing access/partition list, but received: The specified item is no longer valid. It may have been deleted from the keychain. Certificate situation Xcode → Manage Certificates currently shows two Apple Development certificates: One current certificate One older certificate marked “Not in Keychain” When I try to create a new Apple Development certificate, Xcode says: You already have a current Development certificate or a pending certificate request. This is the only Mac I have used with this Apple Developer account, so there isn’t another Mac from which I can recover or export the original private key. What should I do? I’m trying to understand the safest next step without making the certificate/keychain situation worse. Should I: Revoke the older certificate and create a new development certificate/private-key pair? Try to repair the existing signing identity/private key? Take another Apple-supported approach? The immediate goal is to get the app onto a physical iPhone so I can begin real-device testing, followed by QA/beta testing and App Store launch. Any advice on what is actually causing errSecInternalComponent in this situation, and the safest way to resolve it, would be greatly appreciated. I can provide additional Terminal output, screenshots, or Xcode logs if helpful. Thanks!
Replies
1
Boosts
1
Views
41
Activity
1d
App Settings silently fails to select Team / generate Personal Team certificate
Hello, trying to create a simple utility for personal use using Swift Playgrounds. I want to install the app locally on my iPad, I don’t want to have Swift Playgrounds open to run. Have not been able to resolve. See below: Environment: iPadOS Version: iPadOS 26.6.2 (23G90) Hardware: iPad Pro M4 Swift Playgrounds Version: 4.5+ Steps to Reproduce: Create a new App project (+ App button). Open App Settings > Team & Bundle Identifier. Ensure a free Apple ID is signed in. Tap the user's name under the "Team" list. Expected Result: The UI should register the selection, generate a local provisioning profile, and reveal the "Install on this iPad" button. If the user needs to accept a web agreement, an alert should guide them. Actual Result: Nothing happens. The row registers the touch visually, but the state remains "No Team Selected, Unknown Bundle Identifier". No error message is thrown, blocking local installation entirely. Thanks
Replies
1
Boosts
1
Views
72
Activity
2d
Unique App ID prefix migration stalled; Mac App Store validation fails with 90286/91130 on a universal-purchase app
My two apps, com.qrafter.Qrafter and com.qrafter.QrafterPro, have been on the iOS App Store since 2011, and their App IDs still use my team's unique App ID prefix 99T3FA87E9 instead of the Team ID GH4CGS3B5H. I'm adding native Mac versions to the same App Store records (universal purchase), so the bundle IDs can't change. Every profile Apple generates for these App IDs pairs com.apple.application-identifier = 99T3FA87E9.com.qrafter.Qrafter with com.apple.developer.team-identifier = GH4CGS3B5H. iOS uploads are accepted, but Mac App Store validation (xcrun altool --validate-app -t macos) rejects even a minimal one-window app with exactly two errors: Invalid code signing entitlements. … the "99T3FA87E9.com.qrafter.Qrafter" value for the com.apple.application-identifier key … isn't supported. This value should be a string that starts with your Team ID, followed by a dot ("."), followed by the bundle ID. (90286) Invalid Provisioning Profile. … Invalid 'com.apple.application-identifier' entitlement value. (91130) Following "Code Signing Identifiers Explained" (thread 811970), I requested the prefix migration through Contact Us on 4 September (case 102953576372). On 20 September Developer Support asked me to confirm the one-time keychain data loss described in "App ID Prefix Change and Keychain Access" (thread 706128), and I confirmed. Since then the case has had no reply despite follow-ups on 24 and 29 September, and as of 6 October both App IDs still show 99T3FA87E9. Two questions: Is there anything else I need to do to get case 102953576372 completed, or a better route to escalate it? Is there any way to ship a Mac App Store build for these App IDs before the migration, or is the migration the only path? I have a minimal sample project and the full validation log if that helps.
Replies
2
Boosts
0
Views
126
Activity
4d
Correctly requesting com.apple.developer.driverkit.userclient-access
I'm asking about how to ask for an addition to a managed entitlement, where we already have a grant of that entitlement (with a different value) and we already have other managed entitlements granted. This post https://developer.apple.com/forums/thread/789176 tells me I can request entitlements at the Requests tab here: https://developer.apple.com/account/resources/, which leads me to this form: https://developer.apple.com/contact/request/system-extension/ The form URL doesn't specify a particular App Identifier, but is the Identifier implied with this form submission? Or, put another way, is the entitlement we're asking for attached only to the Team ID, or also to the bundle ID of the app which is going to use the entitlement? So if I made another app which talks to my dext, I'd have to ask again for userclient-access to the same dext, but from a different bundle ID? The form says "Which DriverKit entitlements do you need" and "select all that apply", but I'm unclear about whether I need to request ALL the DriverKit entitlements we need for all our apps, or only for the specific App Identifier I reached this form from. It also isn't clear if I need to check both the USB Transport and the UserClient Access boxes in my case. We already have UserClient Access granted for at least one bundle ID, and I want to add another. We already have USB. Transport granted for two different vendor IDs. Do I need to mention that in my request here, and also check the USB Transport box, although I'm not requesting any new vendor ID values? I don't want to end up with new profiles which break new builds of existing apps which were relying on previously-granted entitlements that are now missing from the newly-generated profiles. Here: https://developer.apple.com/forums/thread/822652 user JackLongbow submitted a request for UserClient Access for two bundle IDs, presumably in the form of a simple two-line string like this: com.turing.TuringTouch com.turing.TuringTouch.TouchDriver but the resulting provisioning profile was malformed, it contained this value under com.apple.developer.driverkit.userclient-access <string>com.turing.TuringTouch com.turing.TuringTouch.TouchDriver</string> the Forum post said that the approved entitlement looks like this: <array> <string>com.turing.TuringTouch</string> <string>com.turing.TuringTouch.TouchDriver</string> <string>com.turing.TuringTouchDriver</string> <string>com.turing.virtualpad</string> <string>com.turingdraw.DigidrawTouch.DigidrawDriver</string> </array> Should I be formatting my request as above, as a chunk of xml, or is a plain text list of bundle IDs, one per line, acceptable? Is there a way for us to get a summary of all the managed entitlements already granted to our team? At present, it seems like I have to pick a particular profile, download it, and QuickLook at it - but not all profiles contain all entitlements, just as apps don't have to claim all the entitlements the profile offers .
Replies
1
Boosts
0
Views
661
Activity
1w
Developer ID Application Issue: Repeatedly getting the same certificate
When updating our Developer ID Application certificate, we encountered an issue where the Apple Developer portal consistently returns the exact same certificate file, regardless of the CSR submitted. Observed Behavior & Test Steps: We generated multiple new CSRs using both OpenSSL in the command line and Keychain Access (Certificate Assistant) on macOS following Apple's official guide: https://developer.apple.com/help/account/certificates/create-a-certificate-signing-request We uploaded these distinct CSRs to the Developer Portal (Certificates -> Add New -> Developer ID Application) on separate attempts. After downloading the issued .cer files, we performed a binary comparison (diff/checksum) across all of them. The comparison confirmed that the downloaded certificate files are 100% binary identical across all attempts. Key Pairing Verification: To further verify the key pairing, we checked the public key modulus hashes of the local Private Key and the downloaded .cer file via OpenSSL: Check local Private Key Modulus Hash: openssl rsa -noout -modulus -in new_developer_id.key | openssl md5 Check downloaded Certificate Modulus Hash: openssl x509 -noout -modulus -in developer_identity.cer -inform DER | openssl md5 The resulting MD5 hashes do not match. Attempting to export them to PKCS#12 (.p12) consistently fails with the error: no certificate matches private key. Question: Could this be related to a profile caching or binding issue on our team account, or is there a recommended way to clear this state and obtain a newly issued certificate? Any guidance or advice would be greatly appreciated.
Replies
4
Boosts
0
Views
976
Activity
1w
Cloud-managed distribution signing writes a non-ASCII certificate name decomposed (NFD) into the designated requirement, so every upload fails ITMS-90035
Every App Store Connect upload I sign with my Cloud Managed Apple Distribution certificate is rejected with ITMS-90035 ("Code failed to satisfy specified code requirement(s)") for the app binary and its widget extension. It happens from Xcode Cloud and from a manual Organizer upload alike. I think I have found the cause, and it looks like a Unicode normalization bug in cloud-managed signing. The certificate holder's name contains an umlaut: "Apple Distribution: Jonathan Thorsten Müller (…)". In the certificate the "ü" is precomposed (NFC, UTF-8 c3 bc). In the designated requirement that the export writes into the signature it is decomposed (NFD, "u" + U+0308, UTF-8 75 cc 88): certificate subject CN ... 4d c3 bc 6c 6c 65 72 ... ("Müller", NFC) designated requirement leaf CN ... 4d 75 cc 88 6c 6c 65 72 ... ("Müller", NFD) The bytes differ, so the signature can never satisfy its own designated requirement. It reproduces with Xcode 27.0's App template, unmodified, and without uploading anything: Archive for a generic iOS device. With no distribution identity in the local keychain, export for App Store Connect to a folder (export options: method app-store-connect, destination export, signingStyle automatic). DistributionSummary.plist shows "Cloud Managed Apple Distribution". xcodebuild -exportArchive -archivePath MyApp.xcarchive -exportPath out -exportOptionsPlist ExportOptions.plist -allowProvisioningUpdates Verify the exported app: codesign --verify --strict -vv Payload/MyApp.app Result: "valid on disk", then "does not satisfy its designated Requirement". Compare the requirement with the certificate's subject: codesign -d -r- Payload/MyApp.app codesign -d --extract-certificates Payload/MyApp.app openssl x509 -inform DER -in codesign0 -noout -subject -nameopt RFC2253,-esc_msb | xxd The same archive exported with a regular Apple Distribution certificate (same name, private key in my keychain) writes the NFC form, verifies, and App Store Connect accepts that upload. That works for manual uploads only. Xcode Cloud always signs with the cloud-managed certificate, so I cannot distribute from Xcode Cloud at all. Setup: Xcode 27.0 (27A266a) locally and in Xcode Cloud, automatic signing, one team, no custom code-signing flags. Product name, bundle IDs and file names are plain ASCII. Questions: Is this a known issue with cloud-managed signing and non-ASCII certificate names? Is there a supported way to have Xcode Cloud sign without hitting it in the meantime? If you see ITMS-90035 on Xcode Cloud and your name (or your team's) has an accent or umlaut in it, you may be hitting the same thing: run step 3 on an exported IPA and check.
Replies
3
Boosts
0
Views
522
Activity
1w
Developer ID provisioning profile missing Sensitive Content Analysis entitlement
I’m trying to distribute a macOS application outside the Mac App Store using Developer ID signing and notarization. The Sensitive Content Analysis capability is enabled for this App ID in Certificates, Identifiers & Profiles. My application requires the following entitlement: com.apple.developer.sensitivecontentanalysis.client However, when I create and download a new Developer ID provisioning profile for this App ID, the generated profile does not contain this entitlement. I have regenerated and downloaded the profile after confirming that Sensitive Content Analysis is enabled. I also decoded the newly generated .provisionprofile to inspect its entitlements. It contains the application identifier, team identifier, and keychain access groups, but does not contain com.apple.developer.sensitivecontentanalysis.client. As a result, Xcode will not export the Developer ID build because the application requests the Sensitive Content Analysis entitlement but the provisioning profile does not authorize it. Does anyone know the answers to these questions: Is com.apple.developer.sensitivecontentanalysis.client supported for macOS applications distributed outside the Mac App Store using Developer ID? If it is supported, why is the entitlement not being included in newly generated Developer ID provisioning profiles for this App ID? Is there an additional approval, agreement, or configuration required for this entitlement to be included in a Developer ID profile? Sensitive Content Analysis is a required feature of this application, so removing the entitlement is not an option for our distribution build.
Replies
4
Boosts
0
Views
1.5k
Activity
1w
Renewal of certificates
Hi, I have a hard time renewing my certificates. The double click on the .cer file just opens the Keychain Acces but doesn't install anything. I'm missing a step. Thanks in advance for your help.
Replies
1
Boosts
0
Views
139
Activity
1w
iPadOS DriverKit Capability Request Issues
We have a complete iPadOS DriverKit USB extension for a Stripe Reader M2 (USB-C, M-series iPad). Development builds sign and run. We cannot ship Ad Hoc, App Store, or Enterprise builds because the distribution DriverKit entitlements are either not granted or not present in the provisioning profile Apple generates. Stripe’s iOS USB instructions say to request the entitlement at developer.apple.com/system-extensions: select HID and USB Transport, and enter USB vendor ID 11369. Platform is iPadOS. The extension also needs com.apple.developer.driverkit. The host app uses com.apple.developer.driverkit.communicates-with-drivers. We have two teams. The driver bundle ID is prefixed with the host app bundle ID and signed with the same team. Inc — Team ID HPL6Q4V5TF (Development, Ad Hoc, App Store) Host app Driver extension com.atxinnovation.union.development com.atxinnovation.union.development.usbDriver com.atxinnovation.union.qa com.atxinnovation.union.qa.usbDriver com.atxinnovation.union.production com.atxinnovation.union.production.usbDriver These are not granted. Latest submission is system-extensions request 39WL64S3LR (September 3, 2026). That form has no status page, and we have received no email. LLC — Team ID 3MAPQA4NZ6 (Enterprise in-house) Host app Driver extension com.atxinnovation.union.enterprise com.atxinnovation.union.enterprise.usbDriver Capability request ACL9VQ3BA4. The portal shows DriverKit and DriverKit USB Transport – VendorID granted and enabled on com.atxinnovation.union.enterprise.usbDriver. The Universal Distribution profile POS Prod USB Driver (platform iOS, active, expires 2027/01/22, UUID a3627c1e-451d-4d62-b871-1cb6fe21431e, created 2026-09-02 16:05:20 UTC) lists those capabilities as enabled on the Review Provisioning Profile page. The downloaded profile does not contain them. Decoding it yields only: application-identifier com.apple.developer.team-identifier get-task-allow keychain-access-groups The string driverkit does not appear in the profile. We regenerated it five times, including deleting and recreating the profile, with the same result. DriverKit development profiles for the corresponding development App ID do contain com.apple.developer.driverkit and com.apple.developer.driverkit.transport.usb. Xcode then fails the archive: Provisioning profile "POS Prod USB Driver" doesn't include the com.apple.developer.driverkit entitlement. We also do not know which idVendor values the VendorID grant assigned. The extension must match them exactly. We need 11369. What we already tried July 30: Account Holder submitted DriverKit and DriverKit USB Transport for both teams through the system-extension Contact Us form. No confirmation email. That form does not collect bundle IDs. Those July requests later showed up on the host App ID com.atxinnovation.union.enterprise, not on the usbDriver App IDs. August 12: Resubmitted on each usbDriver App ID under Certificates, Identifiers & Profiles → Capability Requests. Enterprise request ACL9VQ3BA4. August 27: Developer Support case 20000149322724. The reply pointed us back at the capability status page. September 2: Enterprise grant appeared. Enabling it on the App ID and regenerating the distribution profile still produced a profile with no DriverKit entitlements. Developer Support case 102951939894. No resolution. September 3: Resubmitted the Inc team via the system-extensions form (39WL64S3LR). The form would not accept another LLC submission because that App ID is already granted. No status since. What we are Requesting Grant DriverKit, HID, and USB Transport (vendor ID 11369) for iPadOS — Development, Ad Hoc, and App Store — on the three Inc driver App IDs above. Assistance debugging the issue of failing to embed the already-granted DriverKit entitlements in the LLC Enterprise distribution profile for com.atxinnovation.union.enterprise.usbDriver, and confirmation of the assigned idVendor values.
Replies
1
Boosts
8
Views
1.7k
Activity
2w
codesign authorization dialog hangs; XCTest re-sign fails with errSecInternalComponent while standalone signing succeeds
I’m seeing a reproducible code-signing failure on macOS 26.6.2 with Xcode 26.6 while building an iOS XCTest bundle for a physical device. A newly created Apple Development identity is valid and can successfully sign and verify a standalone test binary using /usr/bin/codesign. However, xcodebuild build-for-testing reaches the first XCTest re-sign operation and the macOS Keychain authorization dialog for the same development private key becomes unresponsive after entering the login Keychain password and clicking “Always Allow.” The failing command is effectively: /usr/bin/codesign --force --sign -o runtime --timestamp=none ... libXCTestSwiftSupport.dylib and returns: errSecInternalComponent The exact same development certificate successfully signs a standalone binary immediately beforehand. The build is running from an ordinary logged-in Terminal session, not SSH or CI. After aborting the build, inspection showed the XCTest artifacts retained Apple’s original Software Signing certificate rather than the Development certificate, confirming the re-sign did not complete. I have already recreated the login Keychain once and recreated the Apple Development identity. I do not want to make further Keychain ACL/partition changes without understanding the underlying cause. Question: What diagnostic should I collect to determine why SecurityAgent/codesign cannot complete private-key authorization for the XCTest re-sign operation when direct signing with the same identity succeeds?
Replies
3
Boosts
0
Views
636
Activity
2w
Persistent ITMS-90034 on new Individual account despite verified Apple Distribution signature
Hello, I am experiencing persistent ITMS-90034 when trying to upload the first iOS app from a newly enrolled Individual Apple Developer Program account. The exact error is: Validation failed (409) Missing or invalid signature. The bundle at "Payload/[App].app" is not signed using an Apple submission certificate. (ID: 90034) I have already performed extensive signing checks and troubleshooting: Apple Developer Program membership is active. A valid Apple Distribution certificate is installed in Keychain together with its private key. security find-identity -v -p codesigning reports both Apple Development and Apple Distribution as valid identities. The correct Team and Bundle ID are selected. Automatic signing is enabled in Xcode. Provisioning profile caches and DerivedData were deleted, profiles were downloaded again, and a completely fresh archive was created. Xcode's App Store Connect export review explicitly shows: Certificate: Apple Distribution App Store provisioning profile for the correct Bundle ID get-task-allow = false beta-reports-active = true I then exported the IPA locally using Xcode's App Store Connect distribution workflow and independently inspected the actual exported binary with codesign. The main application reports: Identifier=[Bundle ID] Authority=Apple Distribution: [Name] ([Team ID]) Authority=Apple Worldwide Developer Relations Certification Authority Authority=Apple Root CA TeamIdentifier=[Team ID] I also separately checked the embedded Capacitor.framework and Cordova.framework. Both are signed with the same Apple Distribution identity and Team ID and show the same WWDR -> Apple Root CA trust chain. I checked Keychain as suggested in similar forum discussions. The Apple Distribution certificate has its private key, the WWDR intermediate certificates are present and valid, and certificate verification reports: "...certificate verification successful." Despite all of the above, a fresh upload from Xcode Organizer still consistently fails with the same ITMS-90034. This appears very similar to other recent reports involving newly enrolled Individual Developer accounts where correctly signed binaries are rejected by App Store Connect. I also opened an Apple Developer Support case (case 20000149684934). So far I have received general signing/troubleshooting documentation, but the issue remains unresolved. At this point, is there any additional local signing verification I should perform, or could this indicate an account/team-level App Store Connect signing validation issue that needs to be investigated on Apple's side? I would especially appreciate guidance from Apple DTS on what diagnostic information would be useful to distinguish a local certificate-chain issue from an App Store Connect/account-side validation issue. Thank you.
Replies
3
Boosts
0
Views
1.2k
Activity
3w
Certificate on keychain not found by codesign
Since my Apple Distribution signing certificate had expired I recently got a new one via https://developer.apple.com/account/resources/certificates/list and installed in on my login keychain. Since I had some issues with signing I suspected that codesign might still be trying to use an old expired certificate (as they have the same name "Apple Distribution: ()"). So to fix this I figured I could just delete the old expired certificate from Keychain Access so there was only the valid new certificate there with the same name. However, after doing this and trying to use it with codesign I get the following error error: The specified item is no longer valid. It may have been deleted from the keychain. In other words it seems it's not finding the new valid certificate and somehow still linking the name to the old certificate that it rightly guesses is removed. Following the tips from https://developer.apple.com/forums/thread/701514 I used security find-identity -p codesigning -v to check for installed codesigning certificates, and this listed the new certificate as expected. Using another tip in the same post I saw that you can also use the certificate hash as an identifier beside the name, and using this I can use it with codesign to sign. However, it's still not finding it via the name (or rather, it's still finding the old now removed one). What could be the reason for codesign not finding the correct new valid certificate based on the name and instead still finding the old one? Maybe there's some reference set somewhere to point the name towards specifically the old certificate?
Replies
1
Boosts
0
Views
567
Activity
3w
"How to" for dext distribution
I have a DriverKit system extension (dext) that uses PCIDriverKit. I would like to get the build environment straightened out to successfully distribute the dext and associated software to end users. There are three types of software involved: The Dext-hosting application - this is the application that must be installed to /Applications/, and will perform the registration of the dext. The dext is deployed "within" this application, and can be found in the /Contents/Library/SystemExtensions folder of the app bundle. The dext itself - this is the actual binary system extension, which will be registered by its owning application, and will operate in its own application space independent of the hosting application. Additional applications that communicate with the dext - these are applications which will connect to the dext through user clients, but these applications do not contain the dext themselves. There are multiple locations where settings need to be exactly correct for each type of software to be signed, provisioned, and notarized properly in order to be distributed to users: developer.apple.com - where "identifiers" and "provisioning profiles" are managed. Note that there are differences in access between "Team Agent", "Admin", and "Developer" at this site. Xcode project's Target "Signing & Capabilities" tab - this is where "automatically manage signing" can be selected, as well as team selection, provisioning profile selection, and capabilities can be modified. Xcode project's Target "Build Settings" tab - this is where code signing identity, code signing development team, code signing entitlements file selection, Info.plist options and file selection, and provisioning profile selection. Xcode's Organizer window, which is where you manage archives and select for distribution. In this case, I am interested in "Developer ID" Direct Distribution - I want the software signed with our company's credentials (Team Developer ID) so that users know they can trust the software. Choosing "automatically manage signing" does not work for deployment. The debug versions of software include DriverKit (development) capability (under App ID configuration at developer.apple.com), and this apparently must not be present in distributable provisioning. I believe this means that different provisioning needs to occur between debug and release builds? I have tried many iterations of selections at all the locations, for all three types of binaries, and rather than post everything that does not work, I am asking, "what is supposed to work?"
Replies
22
Boosts
0
Views
4.6k
Activity
Sep ’26
ppq.apple.com unavailable — developer-signed apps cannot be verified
Hello, ppq.apple.com appears to be unavailable. The issue is reproducible from multiple networks/devices. Requests to https://ppq.apple.com fail, preventing iOS from verifying developer-signed applications. This results in the device displaying an error indicating that an Internet connection is required to verify the developer/app. The issue appears to be server-side rather than related to the developer certificate or provisioning profile. Affected: (tested on) ppq.apple.com HTTPS / TCP 443 iOS 9.3.4 iPhone 5S [07/09/2026/20:07 + Zurich] Example: curl -I https://ppq.apple.com Response: HTTP/2 404 server: Apple date: Mon, 07 Sep 2026 18:08:13 GMT content-type: text/plain; charset=UTF-8 content-length: 0 x-b3-spanid: bdf368a2edbdbef7 x-b3-traceid: bdf368a2edbdbef7 x-b3-sampled: 1 strict-transport-security: max-age=31536000; includeSubdomains x-frame-options: SAMEORIGIN x-content-type-options: nosniff x-xss-protection: 1; mode=block Please investigate the availability of the PPQ service.
Replies
0
Boosts
1
Views
435
Activity
Sep ’26
How to get help with Signing and Notarization...
I have been trying to use Apple Developer Support to help with issues I'm having preventing me from signing and notarizing my apps. Delayed and not helpful responses from support. This has been going on for several weeks. I find it hard to believe that a Multi-Trillion Dollar company can't help me with my issues. I have what I think is a good certificate and private key as well as my App-Sepcific Password. The problem is that when trying to sign my apps, I get a popup indicating that that it's trying to sign in to Keychain using my first Name (Steve). My login on my system is "Stephen" which works fine for login and anything that wants to access Keychain. I need some help trying to resolve this.
Replies
1
Boosts
0
Views
796
Activity
Aug ’26
How to release an App ID stuck on a personal (free) team so it can be registered under my paid organization team?
I have two Apple Developer accounts under different Apple IDs: a free "Personal Team" account and a separate paid Organization account. Before my organization's Program enrollment was approved, I built an app to a physical device using Xcode signed into my personal account, which auto-registered an App ID under that personal team. Now that my organization account is active, I can't register the same App ID under the organization — both the web portal and Xcode's automatic signing return "not available," since it's already reserved under my personal team. Since personal (free) accounts have no web portal access, I can't see or manage that registration anywhere to release it myself. I own both accounts. Is there any self-service way to release an App ID from a personal team, or is contacting Apple Developer Support the only option? If support is required, is there a faster route than the standard contact form (I submitted a request several days ago with no reply yet)?
Replies
1
Boosts
0
Views
893
Activity
Aug ’26
Develop Certificate Has Wrong Apple ID???
When trying to develop an Apple Shortcut, the shortcut doesn't appear (after many open, quit, adding permissions, etc.). My only Apple Account is my name associated with an Apple ID of QZ99..... However, when I try to check one (of many reasons) why it does not show up with Terminal: codesign -dv --verbose=4 "/Applications/My App.app" etc, it shows something "rejected" Authority=Apple Worldwide Developer Relations Certification Authority Authority=Apple Root CA Signed Time=Aug 25, 2026 at 1:26:38 PM Info.plist entries=22 TeamIdentifier=QZ99... Runtime Version=26.5.0 Sealed Resources version=2 rules=13 files=4 Internal requirements count=1 size=204 /Applications/Write Create Date from Original.app: rejected origin=Apple Development: My Account (K533...) The K533... is different than my Team ID of QZ99... Could that be a reason my app is not registered with Shortcuts? Is that expected functionality? I guess I expected my Team ID to appear everywhere even after I deleted my account in Xcode, removed a current and expired certificate associated with K533 in Keychain, and then added my account back, and let Xcode regenerate a certificate.
Replies
2
Boosts
0
Views
712
Activity
Aug ’26
NSE Filtering Entitlement not carried over after App Store app transfer
We completed an App Store app transfer and the Notification Service Extension Filtering Entitlement (com.apple.developer.usernotifications.filtering) did not transfer with the app. App Apple ID: 6760007376 NSE Bundle ID: io.nolink.ios.nse New Team ID: M85WA8W78C Previous Team ID: V2E3A94DC9 The app, bundle IDs, and App Store presence all moved normally, but the entitlement is not available on the new team, so we cannot sign the NSE with the configuration the app previously shipped with. Our app is an encrypted messenger and this breaks incoming call handling for live users. Two questions: Is there an official process for re-associating a previously approved entitlement with the receiving team after a transfer, or does the new team always have to submit a fresh request? Could entitlements tied to a specific App ID move with the app during a transfer, the same way bundle IDs do? We have an open support case, but wanted to raise the general question here too.
Replies
2
Boosts
0
Views
1.4k
Activity
Aug ’26
Xcode Personal Team certificate shows “Missing Private Key” and cannot be replaced
I use a free Apple Personal Team with Xcode for on-device testing. My Apple Development certificate created on 15 August 2026 shows “Missing Private Key”, and Xcode is not allowing me to create a fresh replacement certificate. I have already contacted Apple Developer Program Support, and they directed me to the Apple Developer Forums for technical assistance. How can I revoke/reset the unusable certificate or clear the certificate state for my Personal Team so that Xcode can create a new Apple Development certificate?
Replies
1
Boosts
0
Views
363
Activity
Aug ’26