Mail from Apple: your Developer ID certificate expires in 2027 – what to do now

Apple is telling developers that their Developer ID certificates stop working on February 1, 2027. Who is affected, what is actually urgent, and the inconspicuous radio button that held me up.

EIn Mac mit geöffnetem XCode

Some emails from Apple need to be read twice. This one opens with “Your team holds one or more Developer ID certificates issued by the original Developer ID Certification Authority (Sub-CA)” and does not get any catchier after that. The short version: on February 1, 2027, a certificate authority expires, and everything it issued stops working on that day.

I took the mail apart and renewed the certificate. Here is what it means and what needs doing.

What Apple is actually saying

You only need a Developer ID certificate if you distribute Mac software outside the Mac App Store, for example as a download from your own website. The software is signed with the certificate so that macOS launches it without a warning.

These certificates are not issued by Apple directly, but by an intermediate, the “Developer ID Certification Authority”. The original intermediate expires on February 1, 2027. A successor with the suffix “G2” has been around for a long time and is valid until 2031. If you still hold a certificate from the old one, you need a new one from the new one.

Pure App Store apps and iOS apps are not affected. If you don’t distribute any Mac software outside Apple’s store, you can file the mail away.

What is urgent and what is not

This is the most important part of the mail, and it sits at the very bottom.

Installer packages (.pkg) are urgent. Packages signed with an old certificate will no longer install from February 1, 2027. They have to be re-signed with the new certificate and replaced before then.

Apps are not urgent. Mac apps that are already signed and notarized with a secure timestamp keep working. Only the next update has to be signed with the new certificate.

Step 1: Check whether you are affected

In your developer account, Certificates, Identifiers & Profiles lists every certificate with its expiry date. The ones that matter are of type “Developer ID Application” and “Developer ID Installer” and expire on or before February 1, 2027. How to tell which authority issued a certificate is explained on Apple’s help page Replacing Developer ID certificates issued from the previous Sub-CA.

Step 2: Create the certificate signing request

For a new certificate, Apple wants a request file, a CSR for short. Your Mac creates it:

  1. Open Keychain Access.
  2. In the menu bar: Keychain Access → Certificate Assistant → “Request a Certificate From a Certificate Authority…”.
  3. Enter your own email address and your name.
  4. Under “Request is:”, choose “Saved to disk”.
  5. Click “Continue” and save the file.

Step 3: Create the new certificate

Only the team’s Account Holder can create Developer ID certificates.

  1. In your developer account, click the plus next to the certificates.
  2. Choose the type: “Developer ID Application” for apps, “Developer ID Installer” for .pkg packages. If you distribute both, you need both.
  3. Under “Developer ID Certificate Intermediary”, select G2 Sub-CA. This is the one place where you must not click the wrong thing: according to Apple, the other option may give you a certificate that also expires in 2027.
  4. Upload the CSR file and download the certificate.

If you are still on Xcode 11.4 or earlier, Apple asks you to update first.

Step 4: Install and check

Double-clicking the downloaded file puts the certificate into your keychain. Under “My Certificates” it should then appear with a private key you can expand. If the key is missing, the CSR was created on a different Mac.

In Terminal, this command lists all signing identities:

security find-identity -v -p codesigning

As long as the old and the new certificate sit side by side, both carry the same name. In build scripts it helps to pass the hash of the new certificate instead of the name. If the keychain shows the certificate as not trusted, the intermediate certificate “Developer ID – G2” is missing. You will find it on Apple’s Certificate Authority page.

Step 5: Re-sign

For .pkg packages:

productsign --sign "Developer ID Installer: Name (TEAMID)" old.pkg new.pkg
xcrun notarytool submit new.pkg --keychain-profile "PROFILE" --wait
xcrun stapler staple new.pkg

Then replace the download files. For apps, it is enough to use the new certificate for the next update. Xcode picks it up by itself with automatic signing. If you sign in CI, export certificate and key as a .p12 and store both there again.

Three things to remember

Don’t revoke. The old certificate expires by itself. If you revoke it early, you risk that software you have already distributed no longer launches.

Put it in your calendar. The new certificate authority is valid until 2031, but according to Apple’s mail, the certificates it issues expire annually and have to be renewed every year.

It is smaller than the mail sounds. One request file, one certificate, one option called G2. It’s done in a few minutes.