Developer ID Certification Authority将于2027年2月1日到期
Apple于2026年10月1日宣布,原有的Developer ID Certification Authority将于2027年2月1日到期,用它签发的证书签名的安装包自该日起“will no longer install”(将无法再安装)。 已公证的App不受影响:“Previously signed and notarized Mac software (with a secure timestamp) will keep working.”(此前已签名并公证、带有安全时间戳的Mac软件将继续正常运行)1 接替它的颁发机构G2自2022年1月27日起签发证书,但Apple为使用旧版Xcode的团队继续提供原有颁发机构,因此一个团队可能同时持有两个颁发机构各自签发的证书。23 Apple给出的判断依据不是到期日期,而是证书颁发者名称中的Organizational Unit(组织单位)。
下文介绍从钥匙串、安装包和App中读出这一字段的命令;展示这些命令在我自己的Mac上对66个Developer ID App和4个安装器的输出,其中49个App和全部4个安装器都链接到即将到期的颁发机构;指出Apple公告中有一句话与我能查验的证书不符;最后给出我会采用的重新签名顺序。4
TL;DR
- 日期。 原有颁发机构的证书于2027年2月1日22:12:15 UTC终止,与其起始时间相隔整整15年,精确到秒。Apple原文:“Certificates issued by this authority will stop working on that date.”(此颁发机构签发的证书将于该日失效)14
- 安装包停止,已公证的App不停。 “.pkg files signed with an affected certificate will no longer install”(用受影响证书签名的.pkg文件将无法再安装),而带有安全时间戳的已公证软件“will keep working”(将继续正常运行)。1
- 看颁发者。 原有颁发机构签发的证书,其颁发者的Organizational Unit是“Apple Certification Authority”;现行颁发机构签发的证书则是“G2”。Apple指出,到期日期“doesn’t prove which authority issued a certificate”(无法证明证书由哪个颁发机构签发)。2
- 一台Mac的样本。 我的“下载”文件夹里用Developer ID签名的4个安装器全部链接到原有颁发机构,最新的一个签名于2025年12月29日。“应用程序”文件夹中的66个Developer ID App里,49个链接到原有颁发机构,17个链接到G2。4
- 到目前为止,证书过期并未让带时间戳的软件停止工作。 链接到原有颁发机构的49个App中有6个所用的签名证书已在2022年至2026年5月之间过期,另有1个安装器的证书在2017年过期。Gatekeeper目前全部接受这7个。按照Apple的公告,对安装包而言,颁发机构本身的到期将终结这种待遇。14
- 一处不符。 Apple称G2证书“expire annually”(每年到期)。然而我已安装的App上的全部12张G2证书,以及我自己在2026年5月申请的证书,有效期都是5年。两个页面都没有说明一年期从何时开始实行。124
Apple宣布了什么?
公告很短。开头写道:“The original Developer ID Certification Authority (Sub-CA) expires on February 1, 2027. Certificates issued by this authority will stop working on that date.”(原有的Developer ID Certification Authority(Sub-CA)将于2027年2月1日到期。此颁发机构签发的证书将于该日失效)1 随后是三个步骤:确认是否受影响、创建新证书、重新签名。第三步取决于您分发的是什么:
- 安装包。 “Starting February 1, 2027, .pkg files signed with an affected certificate will no longer install. Re-sign all packages with your new certificate before this date.”(自2027年2月1日起,用受影响证书签名的.pkg文件将无法再安装。请在此日期前用新证书重新签名所有安装包)
- Mac App。 “Previously signed and notarized Mac software (with a secure timestamp) will keep working”(此前已签名并公证、带有安全时间戳的Mac软件将继续正常运行),无需任何操作;同时“For future updates, sign with your new certificate and include a secure timestamp for notarization.”(今后的更新请用新证书签名,并为公证加入安全时间戳)1
公告链接的帮助页面这样描述对签名的影响:“After that date, certificates issued from the original authority can no longer be used for signing and must be replaced with certificates from the current Developer ID Certification Authority (G2).”(该日期之后,原有颁发机构签发的证书将不能再用于签名,必须替换为现行Developer ID Certification Authority(G2)签发的证书)页面还列出了“Required role: Account Holder.”(所需角色:Account Holder)2
App与安装包区别对待,这与Apple一贯以来对过期证书的说法相近。关于App,Apple的Developer ID帮助页面写道:“As long as your Developer ID certificate was valid when you compiled your app, then users can download and run your app, even after the expiration date of the certificate.”(只要编译App时Developer ID证书有效,即使证书过期,用户仍可下载并运行您的App)关于安装器,Apple的各个页面说法不一,甚至同一页面内部也自相矛盾。同一个帮助页面写着“Your installer package will only launch if your Developer ID Installer certificate is valid.”(只有在Developer ID Installer证书有效时,安装包才会启动)证书概览页面中Developer ID Installer一条则两头拉扯:用户“can still install packages that were signed with this certificate as long as the package includes a trusted timestamp”(只要安装包带有可信时间戳,仍可安装用此证书签名的安装包),可两句之后又说“new installations won’t be possible until you have re-signed your installer package with a valid Developer ID Installer certificate”(在用有效的Developer ID Installer证书重新签名安装包之前,将无法进行新的安装)。5 10月1日的公告没有给安装包留出时间戳例外。
公告只谈到安装。它没有说明已经通过受影响安装包装好的软件会怎样,也没有说明通过设备管理推送的安装、或用installer命令执行的安装,是否与用户自己打开的安装包同样处理。它也没有提到已签名的磁盘映像。关于第一点,概览页面中关于过期安装器证书的条目写道:“Previously installed apps will continue to run.”(此前已安装的App将继续运行)15
为什么会有两个颁发机构?
证书的有效期不能超过签发它的颁发机构。Apple 2022年的支持页面把这一点写成了规则:“Certificates cannot be issued with a validity period that extends past the intermediate certificate’s expiration date.”(证书的有效期不得超出中间证书的到期日期)3 我能找到的2022年以前的Developer ID证书,有效期都是5年;因此从2022年2月起,只剩5年寿命的原有颁发机构就无法再签发足期证书了。Apple的对策是启用第二个颁发机构:“Starting January 27, 2022, the digital certificates you use to sign your software and installer packages on macOS will be issued from the new Developer ID intermediate certificate that expires on September 16, 2031.”(自2022年1月27日起,您在macOS上用于签名软件和安装包的数字证书将由新的Developer ID中间证书签发,该中间证书于2031年9月16日到期)(证书本身的终止时间是2031年9月17日00:00:00 GMT,按太平洋时间仍是9月16日。)34
原有颁发机构仍然继续提供。针对“running Xcode 11.4 or earlier”(使用Xcode 11.4或更早版本)的团队,Apple写道:“the Apple Developer website will continue to offer Developer ID certificates associated with the original intermediate certificate. Newly issued certificates from this intermediate certificate will be valid for less than five years”(Apple Developer网站将继续提供与原有中间证书关联的Developer ID证书。由此中间证书新签发的证书有效期将不足五年),这一选项“will be available for at least one year, starting January 27, 2022”(自2022年1月27日起至少提供一年)。3
我Mac上的证书同时印证了这段历史的两面。链接到原有颁发机构的49个App共使用27张不同的签名证书。其中2022年2月之前签发的5张,有效期均为5年。2022年2月8日及之后签发的22张,全部终止于同一秒,即2027年2月1日22:12:15 UTC,也就是原有颁发机构自身的最后一秒;这22张中最新的一张签发于2026年1月15日。在G2问世近四年之后,原有颁发机构仍在签发证书,而且每一张都比前一张更短。4
如何判断我的证书由哪个颁发机构签发?
Apple的帮助页面从开发者门户入手:“Any certificates expiring on or before February 1, 2027, are likely affected. However, the expiration date alone doesn’t prove which authority issued a certificate.”(在2027年2月1日或之前到期的证书很可能受到影响。但仅凭到期日期无法证明证书由哪个颁发机构签发)它给出的理由是:“A team can hold a certificate from each authority with identical names, such as the same Developer ID Installer entry twice, differing only in expiration date.”(一个团队可能持有两个颁发机构各自签发、名称完全相同的证书,例如同一个Developer ID Installer条目出现两次,只有到期日期不同)Apple的检验方法在Keychain Access中进行:选中证书,“expand the Issuer Name field, and review the Organizational Unit field”(展开颁发者名称字段,查看Organizational Unit字段)。“Apple Certification Authority”表示“The certificate was issued from the previous Sub-CA. Replace this certificate.”(该证书由之前的Sub-CA签发,请替换此证书);“G2”表示“The certificate was issued from the current Sub-CA. No action needed.”(该证书由现行Sub-CA签发,无需操作)。页面还附了一条提醒:“Check your own certificate, not the Developer ID Certification Authority entry in your keychain. That entry is the authority itself, and it’s issued by Apple Root CA, whose Organizational Unit is also Apple Certification Authority.”(请检查您自己的证书,而不是钥匙串中的Developer ID Certification Authority条目。那个条目是颁发机构本身,由Apple Root CA签发,而Apple Root CA的Organizational Unit同样是Apple Certification Authority)2
同样的检验也可以在终端里完成,分三处来看。
钥匙串中的证书。
security find-certificate -a -c "Developer ID Installer" -p \
| openssl crl2pkcs7 -nocrl -certfile /dev/stdin \
| openssl pkcs7 -print_certs -noout
-a参数会返回所有匹配项,鉴于Apple关于同名证书的提醒,这一点很重要;整条管道会为每张证书打印一行subject和一行issuer。要查看App签名证书,把名称换成“Developer ID Application”即可。我的Mac上有一张Developer ID Application证书,没有Installer证书;用系统自带的/usr/bin/openssl读取,其issuer行为issuer=/CN=Developer ID Certification Authority/OU=G2/O=Apple Inc./C=US。Homebrew的OpenSSL 3会打印相同的字段,只是以逗号分隔。名称没有匹配时,什么都不会打印。4
已发布的安装包。
pkgutil --check-signature YourProduct.pkg
输出列出签名状态、公证状态、可信时间戳和证书链。要看的日期位于第二个条目“Developer ID Certification Authority”下方。在我的4个安装器上,这里都是Expires: 2027-02-01 22:12:15 +0000。G2自身的证书终止于2031年9月17日(GMT),因此由G2签发的证书签名的安装包,这里应当显示那个日期。不过我手头没有用G2签名的安装包,无法加以证实。4
App。 仅靠codesign -dvv是不够的:两个颁发机构共用同一个通用名称(Common Name),无论属于哪一个,Authority=各行的内容都一样。请提取证书链,读取中间证书:
codesign -d --extract-certificates=/tmp/chain. YourApp.app
openssl x509 -inform DER -in /tmp/chain.1 -noout -subject -enddate
对“应用程序”文件夹中一个用G2签名的App,第二条命令会在subject中打印OU=G2,并打印notAfter=Sep 17 00:00:00 2031 GMT。对由原有颁发机构签发的证书签名的App,则打印OU=Apple Certification Authority和notAfter=Feb 1 22:12:15 2027 GMT。4
一台Mac上的软件说明了什么?
安装器。 我的“下载”文件夹里有4个用Developer ID签名的安装包,来自两家厂商,4个全部链接到原有颁发机构。其中3个出自同一家厂商,分别签名于2025年9月28日、12月14日和12月29日,所用的安装器证书签发于2022年4月13日,终止于2027年2月1日。也就是说,这家厂商在九个月前仍在用原有颁发机构签发的证书签名安装包。第4个签名于2014年2月,所用证书已于2017年3月29日过期。4
Gatekeeper的安装评估spctl -a -t install -vv目前将这4个全部接受为“Notarized Developer ID”,包括签名证书在九年前就已过期的那一个。这一结果符合证书概览页面安装器条目中关于可信时间戳的那句话,而不符合同一条目中“new installations won’t be possible”(将无法进行新的安装)那句话,也不符合Developer ID帮助页面的说法。这也恰恰是Apple公告所说的、安装包在2月1日将失去的行为。我无法在10月测试2月的情况,因此那天会发生什么,是Apple的说法,而不是我的观察。145
App。 我“应用程序”文件夹中用Developer ID签名的66个App里,49个链接到原有颁发机构,17个链接到G2。66个签名全部带有安全时间戳。Gatekeeper将其中63个报告为“Notarized Developer ID”,这正是Apple所说的会继续正常运行的组合:原有颁发机构下49个中的46个,以及G2下的全部17个。其余3个都在原有颁发机构之下:其中2个评估失败,报错“a sealed resource is missing or invalid”,这是一个关于包内容的错误;另一个签名于2018年7月,被接受为未经公证的Developer ID。Apple那句话针对的是已公证的软件,至于最后这种App会怎样,公告没有说明。14
原有颁发机构下的49个App中,有6个所用的签名证书在2026年10月1日之前就已过期,最早的在2022年8月,最晚的在2026年5月。Gatekeeper全部接受这6个,其中5个被接受为已公证。Apple针对App的规则,即签名时证书有效就足够,已经在我日常使用的软件上生效。45
公告中哪句话不符?
公告这样描述G2:“This certificate authority is valid until 2031, but the certificates issued by the certificate authority expire annually and must be renewed each year.”(该证书颁发机构有效期至2031年,但由它签发的证书每年到期,必须每年续期)帮助页面也是同样的说法:“Certificates issued from G2 are valid for one year and must be renewed annually.”(G2签发的证书有效期为一年,必须每年续期)12
我能查验的G2证书都不是一年期。我Mac上用G2签名的17个App共使用12张不同的签名证书,签发时间从2023年2月到2026年5月29日不等,有效期全部是5年;其中3张签发于2026年4月和5月。我自己的Developer ID Application证书签发于2026年5月10日,终止于2031年5月11日。4
两个页面都没有说明一年有效期从何时开始实行;我在公告发布后也没有再创建证书,所以无法说出今天签发的证书会带着怎样的有效期。不妨按每年续期来规划,同时读一读您实际拿到的证书上的日期。如果今后一年期证书成为常规,那么Apple各页面之间、以及概览页面同一条目内部,关于过期安装器证书的分歧就会变得更加要紧:如果可信时间戳那句话成立,安装包就能比证书活得更久;如果其他说法成立,就不能。我手头唯一的数据点是上文那个2014年的安装包,Gatekeeper至今仍接受它。这几句话孰轻孰重,是我的解读,并非Apple的说法。
我会按什么顺序处理?
- 盘点。 对两类证书都运行钥匙串检查,并对您仍提供下载的每个安装包(包括旧版本)运行
pkgutil --check-signature。这项安装包检查同样适用于其他厂商的安装器,借此可以找出团队所部署的、需要厂商提供重新签名构建的那些安装器。 - 替换。 如果颁发者显示为“Apple Certification Authority”,就创建一张G2证书。帮助页面的步骤说,如果系统要求选择“Developer ID Certificate Intermediary”(Developer ID证书中间机构),请选择“G2 Sub-CA (Xcode 11.4.1 or later)”,因为“Any other option might issue a certificate from the expiring Certificate Authority”(任何其他选项都可能由即将到期的证书颁发机构签发证书);公告也警告:“Choosing another option may issue a certificate that also expires in 2027.”(选择其他选项可能会签发一张同样于2027年到期的证书)如果两类证书您都持有,则需要“repeat these steps for each, since one certificate does not cover the other”(对每一类分别重复这些步骤,因为一张证书不能替代另一张)。公告还补充了一个前提:“If you’re using Xcode 11.4 or earlier, update before creating your new certificate.”(如果您使用的是Xcode 11.4或更早版本,请在创建新证书之前先更新)12
- 旧证书失效前先测试。 Apple写道:“Because you can hold up to five Developer ID Application and five Developer ID Installer certificates at a time, you can create and test a replacement before your current certificate expires.”(由于您最多可同时持有五张Developer ID Application证书和五张Developer ID Installer证书,可以在当前证书到期前创建并测试替换证书)2
- 重新签名安装包。
productsign手册写道:“If you run productsign on a product archive that was previously signed, the existing signature will be replaced”(对已签名的产品归档运行productsign,现有签名将被替换),并说可信时间戳“is enabled by default when signing with a Developer ID identity”(使用Developer ID身份签名时默认启用)。它还会嵌入“any intermediate certificates that are found in the keychain”(在钥匙串中找到的所有中间证书),因此应当先把G2中间证书放进钥匙串(手册中的--cert选项按通用名称指定中间证书,而两个颁发机构共用同一个名称,所以我不会依赖它在两者之间做选择)。Apple 2022年的页面说,Xcode 13.2或更高版本会自动下载它,否则“you can download it from the Certificate Authority page”(可从Certificate Authority页面下载)。用名称“Developer ID Certification Authority”运行上文的钥匙串管道,即可列出一台Mac上有哪些颁发机构;我的Mac上两个都有。然后对结果重新公证并装订。公证这一步是我的解读,而不是Apple的原话:重新签名后的安装包已经是另一个文件。我没有Developer ID Installer证书,因此没有实际执行这一步。34 - 检查结果。 对重新签名后的文件运行
pkgutil --check-signature,颁发机构下方应当不再显示2027年的日期;spctl -a -t install -vv应当仍然显示“Notarized Developer ID”。 - App签名始终带上时间戳。 安全时间戳是Apple点名的、软件能够继续运行所依赖的属性;对于今后,Apple的指示也是“sign with your new certificate and include a secure timestamp for notarization”(用新证书签名,并为公证加入安全时间戳)。1
这个截止日期是本季第二项与安装器有关的变化。第一项在macOS 27本身:未指明主机架构的安装包现在默认为arm64。哪些安装包会因此受到影响,见Golden Gate一文;反正要重新签名安装器的团队,可以两项一并检查。该版本面向Mac开发者的其余内容见macOS 27发布说明一文;工具链方面见Xcode 27一文和Intel一文;跨团队容器一文介绍了一项会让已发布的Mac App在读取时不经提示直接失败的变化;ld64一文介绍了两项会让Mac构建中断的工具链变化。
常见问题
Developer ID Certification Authority何时到期?
2027年2月1日。原有颁发机构的证书于当天22:12:15 UTC终止。现行颁发机构G2于2031年9月终止:Apple的支持页面写的是9月16日,而证书本身写的是9月17日00:00:00 GMT。134
我的Developer ID App会在2027年2月1日无法启动吗?
对于已公证并带有安全时间戳签名的软件,Apple的回答是不会:这类软件“will keep working”(将继续正常运行),无需任何操作。签名带有时间戳时,codesign -dvv YourApp.app会打印一行Timestamp=;对已公证的App,spctl -a -t exec -vv YourApp.app会报告“source=Notarized Developer ID”。14
由原有颁发机构签发的证书签名的.pkg安装器会怎样?
Apple原文:“Starting February 1, 2027, .pkg files signed with an affected certificate will no longer install. Re-sign all packages with your new certificate before this date.”(自2027年2月1日起,用受影响证书签名的.pkg文件将无法再安装。请在此日期前用新证书重新签名所有安装包)1
如何检查安装包由哪个颁发机构签名?
对它运行pkgutil --check-signature,查看证书链中“Developer ID Certification Authority”条目下方的日期。Expires: 2027-02-01 22:12:15 +0000表示原有颁发机构。4
G2证书的有效期是一年还是五年?
Apple的公告和帮助页面都说是一年。我在2026年10月1日能查验的每一张G2证书,包括最新一张于2026年5月29日签发的,有效期都是五年。两个页面都没有说明一年期从何时开始。124
团队中谁可以创建替换证书?
帮助页面列出:“Required role: Account Holder.”(所需角色:Account Holder)2
参考来源
-
Apple,“Upcoming expiration of Developer ID Certification Authority (Sub-CA),” 开发者新闻,2026年10月1日,引用。 ↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩
-
Apple,“Replacing Developer ID certificates issued from the previous Sub-CA,” 开发者账户帮助,2026年10月1日获取:引用了开头段落、“Find out if your certificates are affected”和“Create a replacement certificate”。 ↩↩↩↩↩↩↩↩↩↩
-
Apple,“Developer ID Intermediate Certificate Updates,” 2026年10月1日获取,引用,包括对“Why was the Developer ID Intermediate Certificate updated if the previous version doesn’t expire until 2027?”的回答。 ↩↩↩↩↩↩
-
作者于2026年10月1日在一台运行macOS 27.0(26A428)的Mac上进行的检查。未安装任何软件。颁发机构:用
/usr/bin/openssl(LibreSSL 3.3.6)读取security find-certificate -a -c "Developer ID Certification Authority" -p的输出,显示原有颁发机构(OU=Apple Certification Authority)有效期为Feb 1 22:12:15 2012 GMT至Feb 1 22:12:15 2027 GMT,G2有效期为Sep 22 18:55:10 2021 GMT至Sep 17 00:00:00 2031 GMT。我自己的证书:通过正文中的钥匙串管道和openssl x509 -noout -startdate -enddate查看,颁发者OU=G2,有效期为2026年5月10日至2031年5月11日;同一管道使用“Developer ID Installer”时不打印任何内容;Homebrew的OpenSSL 3.6.3打印issuer=CN=Developer ID Certification Authority, OU=G2, O=Apple Inc., C=US;管道使用“Developer ID Certification Authority”时打印两个subject,一个为OU=Apple Certification Authority,一个为OU=G2,均由Apple Root CA签发。安装包:对~/Downloads中4个用Developer ID签名的.pkg文件运行pkgutil --check-signature,并从每个安装包的目录表(xar --dump-toc)中读取嵌入的证书:3个来自同一家厂商,可信时间戳分别为2025年9月28日、12月14日和12月29日,签名证书有效期为2022年4月13日至2027年2月1日;1个来自另一家厂商,可信时间戳为2014年2月3日,签名证书有效期为2012年3月28日至2017年3月29日;每条证书链的颁发机构条目均显示“Expires: 2027-02-01 22:12:15 +0000”;spctl -a -t install -vv对全部4个均打印“accepted”和“source=Notarized Developer ID”。App:对/Applications及其下一级文件夹中所有签名颁发者为“Developer ID Application”的App(共66个)运行codesign -dvv和codesign -d --extract-certificates:中间证书的Organizational Unit在49个上为“Apple Certification Authority”,在17个上为“G2”;66个全部报告Timestamp=行。按序列号统计,那49个共使用27张不同的签名证书,其中5张签发于2017年8月至2021年5月之间,有效期各为5年,22张签发于2022年2月8日至2026年1月15日之间,全部终止于Feb 1 22:12:15 2027 GMT;那17个共使用12张,签发于2023年2月9日至2026年5月29日之间,有效期各为5年,其中3张签发于2026年4月和5月。对同样66个运行spctl -a -t exec -vv:63个为“source=Notarized Developer ID”(原有颁发机构46个,G2 17个),1个为“source=Developer ID”,2个为“a sealed resource is missing or invalid”。有6个App(涉及5张证书)的签名证书在2026年10月1日之前已终止(2022年8月9日至2026年5月26日);6个全部被接受,其中5个被接受为已公证。man productsign,引用。 ↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩ -
Apple,“Developer ID certificates,” 开发者账户帮助,“Manage Developer ID certificate and provisioning profile expiration”;以及“Certificates overview,” “Expired or revoked certificates”中的Developer ID Application与Developer ID Installer条目,均于2026年10月1日获取,引用。 ↩↩↩↩