Apple has issued an official notice to macOS software creators regarding the upcoming expiration of its legacy Developer ID intermediate certificate authority. Developers must update their signing credentials and re-sign installer packages to ensure uninterrupted software installation on Mac devices ahead of the February 1, 2027 deadline.
apple developer id sub ca expiration re sign installers
The core of Apple's notice centers on the original Developer ID Certification Authority (Sub-CA) reaching its scheduled expiration on February 1, 2027. Any installer packages (.pkg) signed using credentials issued under this original intermediate authority will cease to function on that date, preventing users from completing new software installations. Apple advises developers to identify affected certificates within their developer account dashboards, switch to the current Developer ID Certification Authority (G2), and re-sign their distribution packages well before the 2027 deadline.
Developer ID Sub-CA Expiration Details
In digital security infrastructures, certificate authorities form a chain of trust. Intermediate certificates, such as Apple's Developer ID Sub-CA, bridge the gap between Apple's root certificate and the end certificates assigned to individual developers. When an intermediate certificate authority expires, the entire chain signed beneath it becomes invalid unless updated credentials are issued from an active authority.
The original Sub-CA was utilized for years to issue certificates for independent macOS application distribution outside the Mac App Store. With its natural end-of-life set for February 2027, Apple has established the Developer ID Certification Authority (G2) as the active replacement. The G2 authority remains valid through 2031. Certificates issued under the G2 framework follow an annual renewal schedule, requiring ongoing compliance from active development teams.
Which Mac Software and Installers Are Affected
The primary impact of this transition falls on standalone installer packages (.pkg files) that were signed with certificates derived from the original Sub-CA. Beginning February 1, 2027, macOS Gatekeeper and system installation subsystems will fail to validate these legacy installer files, preventing them from launching.
Developers who distribute software directly via downloadable .pkg files, disk images containing installer scripts, or custom installation helpers must audit their existing download catalogs. Any installer package that needs to remain downloadable and executable by end users past early 2027 must be generated afresh using a new certificate.
Impact on App Store and Notarized Mac Applications
Software distributed directly through the official Mac App Store is unaffected by this specific intermediate certificate change. Re-signing requirements do not apply to App Store apps because Apple re-signs those binaries using its own internal certificate chain before delivering them to customers.
For non-App Store Mac applications (.app bundles), previously signed software that was submitted through Apple's Notarization service and includes a secure timestamp will continue to run without issue after February 1, 2027. End users who have already installed these applications will not experience service disruptions or launching failures. However, when developers prepare future updates or fresh binary releases, those builds must be signed using certificates generated from the G2 Sub-CA. Recent system software updates, including macOS 27.0.1 Golden Gate, continue to enforce strict security checks on unverified binaries during app execution.
Required Actions for macOS App Developers
Apple outlines a clear, step-by-step workflow for engineering teams to audit and upgrade their code signing tools. Development teams are encouraged to begin auditing their certificates immediately to prevent build pipeline disruptions.
Generating Replacement Certificates via G2 Sub-CA
To begin the migration, developers must log into the Apple Developer portal and navigate to the Certificates, Identifiers & Profiles section. Teams should review all listed Developer ID Application and Developer ID Installer certificates to pinpoint those set to expire on or before February 1, 2027.
When creating replacement certificates, developers must ensure their build environment links to the G2 Sub-CA. Developers utilizing older IDE versions, such as Xcode 11.4 or earlier, must update their development tools before requesting new credentials. Selecting any legacy intermediary during request generation will issue a certificate that still ties back to the expiring 2027 chain. Xcode and command-line tool chains must properly reflect the Developer ID - G2 intermediary.
Re-Signing PKG Installer Packages Before February 2027
Once new G2-backed certificates are active in Keychain Access or automated build pipelines, developers must re-compile or re-sign their target installer packages. Commands utilizing the productsign and codesign command-line utilities should be verified to confirm they anchor correctly to the G2 chain.
For companies offering older, legacy versions of software for download on support portals, re-signing those archived PKG files is necessary if users are expected to install them after January 2027. Ensuring every published download package contains a valid timestamp anchored to the G2 Sub-CA guarantees seamless installation. This preventative maintenance ensures compatibility as Apple advances security enforcement across its operating systems, including updates that phase out legacy features like Rosetta 2 translation in modern hardware architectures.
Apple's advance notice gives development teams ample time to audit build automation systems, update certificate assets, and refresh installer packages before the February 2027 deadline. By adopting the G2 Sub-CA authority early, software creators can maintain uninterrupted distribution and ensure smooth installation experiences for macOS users worldwide.