The original Developer ID Certification Authority (Sub-CA) expires on February 1, 2027. Certificates issued by this authority will stop working on that date.
What to do:
- See if you are affected. In Certificates, Identifiers & Profiles, look for certificates on or before February 1, 2027. See Replace Developer ID Certificates from the previous Sub-CA for help identifying your Certificate Authority.
- Create a new certificate. Generate a replacement of the current authority, Developer ID Certification Authority (G2). Note: This certification authority is valid until 2031, but the certificates issued by the certification authority expire every year and must be renewed every year.
- If you are using Xcode 11.4 or earlier, update before creating your new certificate.
- When asked for a developer ID certificate intermediary, choose G2 Sub-CA. Choosing another option can issue a certificate that also expires in 2027.
- New characters based on what you distribute.
- Installer packages (.pkg): Starting February 1, 2027, .pkg files signed with an affected certificate will no longer be installed. Sign all packages with your new certificate before this date.
- Mac Apps: Previously signed and notarized Mac software (with a secure timestamp) will continue to work – no action required. For future updates, sign with your new certificate and include a secure time stamp for notarization.
