From ca84a14ec04e0171d84bc1634e208db232ec7552 Mon Sep 17 00:00:00 2001 From: Hyuri Date: Thu, 17 Sep 2026 05:18:34 -0300 Subject: [PATCH 1/5] Note "certificate is not trusted" issue under expired system certificates MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit When an intermediate certificate is expired in the system — seems to be the **Developer ID** certificate —, instead of `This certificate is valid`, one will see `"Developer ID Application: [...]" certificate is not trusted` instead. This adds a note on how to solve that issue — upgrading the system, or installing a fresh version of the intermediate certificate. --- docs/en/how-to/code-signing/macOS.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/docs/en/how-to/code-signing/macOS.md b/docs/en/how-to/code-signing/macOS.md index 910a878c7c..ab26abebf4 100644 --- a/docs/en/how-to/code-signing/macOS.md +++ b/docs/en/how-to/code-signing/macOS.md @@ -105,6 +105,9 @@ Congratulations! You've just successfully installed the Developer ID Application The *specific type* of the certificate you have just created is quite precious, and you should make sure to keep it safe. A single Developer ID Application Certificate can be used to [sign, notarize and distribute multiple applications](https://developer.apple.com/forums/thread/657993) outside of the Mac App store, which is why a [very limited number of them](https://help.apple.com/xcode/mac/current/#/dev3a05256b8) can be created on a particular Developer Account. You should consider making a backup copy, which will require you to export the certificate together with the associated private key from the Keychain. The procedure for doing so is [documented by Apple](https://support.apple.com/guide/keychain-access/import-and-export-keychain-items-kyca35961/mac). +/// note | Issue: "certificate is not trusted" +If instead of `This certificate is valid` you see `"Developer ID Application: [...]" certificate is not trusted` in red, it most likely means the **Developer ID** intermediate certificate in your system, needed to validate your application certificate, is expired. To fix the issue, you need to either upgrade your system to the latest version (recommended), or download the latest [Developer ID - G2 certificate](https://www.apple.com/certificateauthority/DeveloperIDG2CA.cer). Other up-to-date certificates can also be downloaded from [Apple PKI](https://www.apple.com/certificateauthority) if needed. + /// ## Other types of Code Signing identities From 0a90357bb1053babcdaa529e0fae8ca3aecc8125 Mon Sep 17 00:00:00 2001 From: Hyuri Date: Thu, 17 Sep 2026 22:03:12 -0300 Subject: [PATCH 2/5] Add line break around "/// note" markup for safety of translation Co-authored-by: Russell Keith-Magee --- docs/en/how-to/code-signing/macOS.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/en/how-to/code-signing/macOS.md b/docs/en/how-to/code-signing/macOS.md index ab26abebf4..dc4e8451d4 100644 --- a/docs/en/how-to/code-signing/macOS.md +++ b/docs/en/how-to/code-signing/macOS.md @@ -106,6 +106,7 @@ Congratulations! You've just successfully installed the Developer ID Application The *specific type* of the certificate you have just created is quite precious, and you should make sure to keep it safe. A single Developer ID Application Certificate can be used to [sign, notarize and distribute multiple applications](https://developer.apple.com/forums/thread/657993) outside of the Mac App store, which is why a [very limited number of them](https://help.apple.com/xcode/mac/current/#/dev3a05256b8) can be created on a particular Developer Account. You should consider making a backup copy, which will require you to export the certificate together with the associated private key from the Keychain. The procedure for doing so is [documented by Apple](https://support.apple.com/guide/keychain-access/import-and-export-keychain-items-kyca35961/mac). /// note | Issue: "certificate is not trusted" + If instead of `This certificate is valid` you see `"Developer ID Application: [...]" certificate is not trusted` in red, it most likely means the **Developer ID** intermediate certificate in your system, needed to validate your application certificate, is expired. To fix the issue, you need to either upgrade your system to the latest version (recommended), or download the latest [Developer ID - G2 certificate](https://www.apple.com/certificateauthority/DeveloperIDG2CA.cer). Other up-to-date certificates can also be downloaded from [Apple PKI](https://www.apple.com/certificateauthority) if needed. /// From 45adb944c4bd72af684b3594d3144ffc66542bc0 Mon Sep 17 00:00:00 2001 From: Hyuri Date: Thu, 17 Sep 2026 22:37:53 -0300 Subject: [PATCH 3/5] Add change note 3060.doc.md --- changes/3060.doc.md | 1 + 1 file changed, 1 insertion(+) create mode 100644 changes/3060.doc.md diff --git a/changes/3060.doc.md b/changes/3060.doc.md new file mode 100644 index 0000000000..ca21aa8bb5 --- /dev/null +++ b/changes/3060.doc.md @@ -0,0 +1 @@ +Added note in the docs about expired intermediate **Developer ID** Apple certificates resulting in **Developer ID Application** certificates being marked as `"Developer ID Application: [...]" certificate is not trusted` instead of `This certificate is valid` in Keychain Access after installing, and how to fix the issue. From 9a4ab2343aaf31e2b6bb41222b562c753eacd8f0 Mon Sep 17 00:00:00 2001 From: Hyuri Date: Mon, 21 Sep 2026 08:14:17 -0300 Subject: [PATCH 4/5] Add "PKI" to spelling_wordlist --- docs/spelling_wordlist | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/spelling_wordlist b/docs/spelling_wordlist index 58fadafdf6..d00064d96d 100644 --- a/docs/spelling_wordlist +++ b/docs/spelling_wordlist @@ -259,3 +259,4 @@ Xcode Xr Xs MSVC +PKI From 3d4bce58572d5a8fb2611ab50bf9e14a0f9b8a64 Mon Sep 17 00:00:00 2001 From: Russell Keith-Magee Date: Tue, 22 Sep 2026 09:05:29 +0800 Subject: [PATCH 5/5] Minor updates. --- changes/3060.doc.md | 1 - changes/3060.misc.md | 1 + docs/en/how-to/code-signing/macOS.md | 4 ++-- docs/spelling_wordlist | 22 +++++++++++----------- 4 files changed, 14 insertions(+), 14 deletions(-) delete mode 100644 changes/3060.doc.md create mode 100644 changes/3060.misc.md diff --git a/changes/3060.doc.md b/changes/3060.doc.md deleted file mode 100644 index ca21aa8bb5..0000000000 --- a/changes/3060.doc.md +++ /dev/null @@ -1 +0,0 @@ -Added note in the docs about expired intermediate **Developer ID** Apple certificates resulting in **Developer ID Application** certificates being marked as `"Developer ID Application: [...]" certificate is not trusted` instead of `This certificate is valid` in Keychain Access after installing, and how to fix the issue. diff --git a/changes/3060.misc.md b/changes/3060.misc.md new file mode 100644 index 0000000000..18f2032166 --- /dev/null +++ b/changes/3060.misc.md @@ -0,0 +1 @@ +A note was added in the docs about expired intermediate Developer ID Apple certificates. diff --git a/docs/en/how-to/code-signing/macOS.md b/docs/en/how-to/code-signing/macOS.md index dc4e8451d4..2416b62c9a 100644 --- a/docs/en/how-to/code-signing/macOS.md +++ b/docs/en/how-to/code-signing/macOS.md @@ -105,9 +105,9 @@ Congratulations! You've just successfully installed the Developer ID Application The *specific type* of the certificate you have just created is quite precious, and you should make sure to keep it safe. A single Developer ID Application Certificate can be used to [sign, notarize and distribute multiple applications](https://developer.apple.com/forums/thread/657993) outside of the Mac App store, which is why a [very limited number of them](https://help.apple.com/xcode/mac/current/#/dev3a05256b8) can be created on a particular Developer Account. You should consider making a backup copy, which will require you to export the certificate together with the associated private key from the Keychain. The procedure for doing so is [documented by Apple](https://support.apple.com/guide/keychain-access/import-and-export-keychain-items-kyca35961/mac). -/// note | Issue: "certificate is not trusted" +/// note | Issue: "Certificate is not trusted" -If instead of `This certificate is valid` you see `"Developer ID Application: [...]" certificate is not trusted` in red, it most likely means the **Developer ID** intermediate certificate in your system, needed to validate your application certificate, is expired. To fix the issue, you need to either upgrade your system to the latest version (recommended), or download the latest [Developer ID - G2 certificate](https://www.apple.com/certificateauthority/DeveloperIDG2CA.cer). Other up-to-date certificates can also be downloaded from [Apple PKI](https://www.apple.com/certificateauthority) if needed. +If, when you install the certificate, you receive an error that "'Developer ID Application: [...]' certificate is not trusted", it most likely means your Developer ID intermediate certificate has expired. The intermediate certificate is needed to validate your application certificate; it is provided by Apple as part of the Xcode developer tools, and is updated regularly. If you have an older macOS or Xcode installation, it's possible you have an out of date intermediate certificate. To fix this issue, you need to either upgrade your system to the latest versions of macOS and Xcode (recommended), or download and install the latest [Developer ID - G2 certificate](https://www.apple.com/certificateauthority/DeveloperIDG2CA.cer). Other up-to-date certificates can also be downloaded from [Apple PKI](https://www.apple.com/certificateauthority) if needed. /// diff --git a/docs/spelling_wordlist b/docs/spelling_wordlist index d00064d96d..462edd6095 100644 --- a/docs/spelling_wordlist +++ b/docs/spelling_wordlist @@ -1,11 +1,11 @@ AAB +ABIs ADB adhoc allowlist AlmaLinux amongst APIs -ABIs APK appimage AppImage @@ -46,9 +46,9 @@ cookiecutter Cookiecutter cryptographic CTRL -CVE Curve customizations +CVE datetime DBus debugpy @@ -62,8 +62,8 @@ dmg DMGs DNS Dockerfile -ECC drawable +ECC embeddable executables FamilyWild @@ -101,10 +101,10 @@ JSON Kerberos keychain Keychain -keystore -keystores keyring keyserver +keystore +keystores linters Linux linuxdeploy @@ -122,11 +122,12 @@ manylinux MkDocs MSI MSIs +MSVC Namespace Napari natively -NET's NDK +NET's NFS NSIS NumPy @@ -142,16 +143,17 @@ PFX phablet PID pipx +PKI PNG PowerShell ppb PR pre precompiled +programmatically proxied Proxied proxying -programmatically PRs PursuedPyBear px @@ -178,9 +180,9 @@ ReST reStructuredText RGB RHEL -RSA rpmbuild rpmsign +RSA rst RTF rumdl @@ -219,8 +221,8 @@ Toolset towncrier tox triaged -troff Triaging +troff TrustedPeople TrustedPublisher TTY @@ -258,5 +260,3 @@ Xauth Xcode Xr Xs -MSVC -PKI