Upcoming expiration of Developer ID Certification Authority (Sub-CA)

The original Developer ID Certification Authority (Sub-CA) expires on February 1, 2027. Certificates issued by this authority will stop working on that date.

What to do:

  1. Check if you’re affected. In Certificates, Identifiers & Profiles, look for certificates expiring on or before February 1, 2027. See Replacing Developer ID certificates issued from the previous Sub-CA for help identifying your certificate’s authority.
  1. Create a new certificate. Generate a replacement from the current authority, Developer ID Certification Authority (G2). Note: This certificate authority is valid until 2031, but the certificates issued by the certificate authority expire annually and must be renewed each year.
  • If you’re using Xcode 11.4 or earlier, update before creating your new certificate.
  • When prompted for a Developer ID Certificate Intermediary, select G2 Sub-CA. Choosing another option may issue a certificate that also expires in 2027.
  1. Re-sign based on what you distribute.
  • Installer packages (.pkg): Starting February 1, 2027, .pkg files signed with an affected certificate will no longer install. Re-sign all packages with your new certificate before this date.
  • Mac apps: Previously signed and notarized Mac software (with a secure timestamp) will keep working—no action needed. For future updates, sign with your new certificate and include a secure timestamp for notarization.