- Apple says one of its Developer ID signing authorities lapses on February 1, 2027, and certificates it issued stop working that day.
- Apple says affected installer packages (.pkg) will not install after that date. Mac software notarized earlier with a secure timestamp keeps working.
- Find certificates that expire by that date, issue replacements from Apple's newer authority, and re-sign affected installers before the deadline.
A signature is a promise with an end date
When software names its maker, a certificate backs that claim. Certificates expire. Someone has to renew them.
Apple has published a date for one of them. Its first Developer ID intermediary authority, called the Sub-CA, lapses on February 1, 2027. Apple says certificates it issued stop working on that day.
The people who sign Mac software can sit apart from the people who sell it. A date in a developer portal can pass unseen. The first sign may be a customer whose install fails.
Background: how the chain of trust works
This section is WebPulse background. Apple's notice does not explain the mechanism, so treat this as general explanation.
A Developer ID certificate is not trusted on its own. An intermediary authority vouches for it. That is the Sub-CA. Apple's root vouches for the Sub-CA. The result is a chain of three links: your certificate, the Sub-CA, the root.
A check is only as good as the whole chain. If one link has expired, anything checked against that chain afterward can fail.
An installer package is checked when a person installs it. At that moment the chain has to hold. After February 1, 2027, the Sub-CA link will be gone. That fits Apple's statement that affected .pkg files will no longer install.
A secure timestamp works like a dated receipt. It records that the signature was made while the chain was still valid. Apple names the timestamp as the condition for notarized Mac software to keep working. Apple's notice does not say why.
What breaks and what does not
Installer packages are the exposed item. Apple says .pkg files signed with an affected certificate stop installing from February 1, 2027. Every package signed with an affected certificate must be re-signed before then.
Mac software is treated differently. Apple says software that was signed and notarized earlier, with a secure timestamp, keeps working. No action is needed for it. For future updates, Apple says to sign with the new certificate and add a secure timestamp.
So old apps that were notarized with a secure timestamp are not the main concern. The installers you still hand out are. Check places such as download pages, internal catalogues and deployment tools.
The fix in four steps
Each step is small. Together they need one owner.
First, find your exposure. Open Certificates, Identifiers & Profiles in your Apple developer account. List every certificate that expires on or before February 1, 2027. Apple has a help page for working out which authority issued yours.
Second, issue a replacement from Apple's newer authority, Developer ID Certification Authority (G2). Apple says that authority is valid until 2031.
Third, read the prompt with care. It asks for a Developer ID Certificate Intermediary. Pick G2 Sub-CA. Apple warns that any other choice may produce a certificate that also ends in 2027.
Fourth, check your tools. Teams on Xcode 11.4 or earlier must update before they create the new certificate.
The longer lesson: renewal is now routine
One detail matters for planning. The G2 authority runs until 2031. But Apple says each certificate it issues lasts one year and must be renewed annually.
That makes signing a yearly task, not a one-off clean-up. A team that treats this as a single project will meet the next expiry unprepared.
This is WebPulse's interpretation, not Apple's statement. The deadline shows whether anyone owns the signing identity. If the answer is a developer who left, or a laptop nobody can find, that is the real finding.
Questions to put to your team
Who owns the Developer ID certificates? Is that person named in writing? Which certificates expire on or before February 1, 2027?
Which installer packages do you distribute, and where? Include internal and customer-facing ones. Will each be re-signed before the deadline? Who confirms it installs afterward?
Is the renewal date for the new certificate on a calendar with a named owner? About four months remain. That is enough to do this calmly. It is too little to start in January.
A certificate is cheap to renew and costly to forget. Apple has given early notice. The rest is a calendar entry and an owner.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Apple.





