Skip to content

doc: Note expired system certificate issue in how-to/code-signing/macOS - #3060

Merged
freakboy3742 merged 5 commits into
beeware:mainfrom
hyuri:patch-1
Sep 22, 2026
Merged

freakboy3742 merged 5 commits into
beeware:mainfrom
hyuri:patch-1

Conversation

@hyuri

@hyuri hyuri commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

When an intermediate certificate is expired in the system — seems to be the Developer ID certificate —, instead of This certificate is valid, one will see "Developer ID Application: [...]" certificate is not trusted instead.

This adds a note on how to solve that issue — upgrading the system, or installing a fresh version of the intermediate certificate.

PR Checklist:

  • I will abide by the BeeWare Code of Conduct
  • I have read and have followed the CONTRIBUTING.md file
  • This PR was generated or assisted using an AI tool

Assisted-by:

…ates

When an intermediate certificate is expired in the system — seems to be the **Developer ID** certificate —, instead of `This certificate is valid`, one will see `"Developer ID Application: [...]" certificate is not trusted` instead.

This adds a note on how to solve that issue — upgrading the system, or installing a fresh version of the intermediate certificate.
@hyuri hyuri changed the title Note "certificate is not trusted" issue under expired system certific… Note expired system certificate issue in how-to/code-signing/macOS Sep 17, 2026
@hyuri hyuri changed the title Note expired system certificate issue in how-to/code-signing/macOS doc: Note expired system certificate issue in how-to/code-signing/macOS Sep 17, 2026

@freakboy3742 freakboy3742 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the PR! It's currently failing CI because of the need for a changenote, and a spelling issue (adding PKI to the spelling dictionary).

The only other thought (and I'm guessing you've fixed the problem, so you don't have the ability to test this any more) - can we catch this failure mode at runtime and provide advice? Do you still have logs from these failed runs?

Comment thread docs/en/how-to/code-signing/macOS.md Outdated
Co-authored-by: Russell Keith-Magee <russell@keith-magee.com>
@hyuri

hyuri commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor Author

[...] I'm guessing you've fixed the problem, so you don't have the ability to test this any more) [...]

Yes, problem fixed on my end so I can't test this any further.

The only other thought [...] can we catch this failure mode at runtime and provide advice? Do you still have logs from these failed runs?

This part of the process is done without running briefcase, so there are no failed runs.
The issue only manifests itself inside Keychain Access, after you install your Developer ID Application certificate.

@hyuri

hyuri commented Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

[...] and a spelling issue (adding PKI to the spelling dictionary).

I thought you meant you were adding it. Sorry. Done now.

@freakboy3742 freakboy3742 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've pushed a couple of minor tweaks, but this is great! Thanks!

@freakboy3742
freakboy3742 merged commit 8c12bac into beeware:main Sep 22, 2026
56 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants