Developer ID Certificates Expire Feb 1, 2027: What You Need to Do

Apple’s original Developer ID Certification Authority Sub-CA is set to expire on February 1, 2027, rendering certificates issued by the legacy authority invalid and halting the installation of unupdated software packages. Developers must generate replacement certificates from the current Developer ID Certification Authority G2, which remains valid until 2031, developer.apple.com reported.

Checking Developer Accounts for Expiring Certificates

Within the Apple developer portal under Certificates, Identifiers & Profiles, maintainers need to inspect their active signing credentials. Any profile displaying an expiration date on or before February 1, 2027, relies on the legacy Sub-CA and requires immediate rotation.

Developers utilizing Xcode 11.4 or earlier must update their Integrated Development Environment before issuing any replacement certificates.

Generating Replacement G2 Sub-CA Certificates

Replacing an expiring credential requires explicitly targeting the modern intermediary during creation. When the developer portal prompts for a Developer ID Certificate Intermediary, engineers must select the G2 Sub-CA option. Choosing any alternate or legacy path risks issuing a replacement certificate that inherits the same 2027 expiration wall.

While the G2 certificate authority itself remains valid through 2031, individual certificates issued from it carry an annual expiration window.

Expired Certificates Block Installer Packages After February 2027

The operational impact of the expiration depends entirely on distribution formats. Installer packages ending in the .pkg extension face a hard operational cutoff. Starting February 1, 2027, macOS will refuse to install any .pkg file signed with an affected, expired certificate, regardless of when it was built.

Mac applications already signed, notarized, and embedded with a secure timestamp will continue functioning without interruption. No retroactive action is required for legacy app binaries resting on user machines. However, any future updates or patches distributed for those applications must be signed with the new G2-backed certificate and include a valid secure timestamp for notarization.

Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

Luke Humphries wins World Grand Prix final against Gerwyn Price