Xcode ios app development code signing

Viewed 23642

When I run my app into my iphone I have this Warning:

unable to build chain to self-signed root for signer "".

My application Installed in iphone but it closed suddenly.

14 Answers

In my case,

1- Open Keychain Access

2- Select login, and click Certificates

3- Double click Apple Worldwide Developer Relations Certificate Authority

4- Open trust section, and set to "Use System Defaults" from "Always Trust"

5- Clean build folder and run

I too had the same error unable to build chain to self-signed root for signer...

My mistake was that I had changed the trust setting of my distribution / developer cert to always trust. When I changed it back to Use system Default it all worked.

I saw other answers and attempted to delete my intermediate keychains and root certificate. But Apple doesn't allow to remove Root certs unless you're in recovery mode and I didn't want to try that. Likely you don't have to delete anything either as this solution works without it.

I just thought I'd add an image to clarify things. I ran into this issue when I was poking around in my Keychain and accidentally changed the default settings.

Identifying the bad certificate:

  1. From you Keychains select Login
  2. From Category select Certificates
  3. Find any Apple Certificate that has the blue + like
  4. Double click on the certificate. You'll see it look like this

enter image description here

  1. Expand the Trust. You'd see something like this:

enter image description here

  1. If it's messed up then the "When using this certificate" is set to "Always Trust" along with the blue

Fixing the bad certificate:

  1. Just set it to "Use System Defaults" and close it.
  2. You'll get a pop up. Type in your password to update settings.
  3. Close KeyChain. Go back to your project, clean and run. Problem should have gone away.
  4. If that didn't work then go back to Keychain and just double check and see if there are any other Apple certificates that are set to Always Trust and repeat the process.
  1. Change your trust settings of your developer certificate in keychain access to system default
  2. Delete all certificates in your local keychain
  3. Quit and relaunch xcode
  4. Clean
  5. Run program on device
  6. When it asks, enter your keychain password and click always trust

The issue could be having your certificate set to always trust, that's the issue I had. If you're getting this warning that stops you from running apps on your device, this should fix everything.

After days of trying to find a consistent way, here is the solution:

Xcode 12.4

It seems like a hack but it works!

  1. Go to Xcode Preferences menu (command+,) and then Accounts tab

  2. click on the gear icon on the bottom left and Export Apple ID and Code Signing Assets... Settings

  3. Set a password for the export

⚠️ You are going to delete all passwords and profiles! Don't forget your password! Writing down your password is highly recommended.

⛔️ This file will contain all your accounts and profiles. Make sure to keep it very secure.

  1. Delete all accounts.

  2. Build and face the new error.

  3. Import them back using your password.

It's working again.

After struggling one day with many answer on forum. I came up with solution works for me. below are steps for fix:

  1. Download below certificate from apple PKI official site https://www.apple.com/certificateauthority/
Root Certificate
  Apple Inc. Root
  Apple Root CA - G3 Root
Intermediate Certificate
   Worldwide Developer Relations - G1 (Expiring 02/07/2023 21:48:47 UTC)
   Worldwide Developer Relations - G3 (Expiring 02/20/2030 00:00:00 UTC)
  1. Download all Certificate and profiles, extension profile specific to your app for development and distribution.
  2. Go to Xcode Preferences menu (command+,) and then Accounts tab. Delete all account
  3. Quit Xcode
  4. Open Key chain and go to login section of Certificate tab
  5. Remove all root and intermediate certificates, Developer ID Certification Authority from key chain.
  6. Remove all your app specific certificate
  7. Open finder, go to location (shift+cmd + g) ~/Library/MobileDevice/Provisioning\ Profiles and remove all certificate
  1. Relaunch Keychain and go to login section of Certificate tab
  2. Drag drop root certificates to keychain (root certificate will be trusted automatically do not make it manually )
  3. Drag drop intermediate certificates to keychain
  4. Drag drop app specific certificate (.p12) to keychain
  1. Open finder, go to location (shift+cmd + g) ~/Library/MobileDevice/Provisioning\ Profiles and add you app specific profiles. Optionally you can login with apple account in Xcode setting and download manually for each profile.
  2. Open Xcode and clean derive data (Shift+ Alt+ cmd+ k), and build it with any device.

This issue happens due to apple has introduced new root certificate and intermediate certificate. Read more detail from https://developer.apple.com/support/wwdr-intermediate-certificate/

Xcode 12.4

xcode -> preferences -> accounts -> select the account -> manage certificate -> click on the + icon on the bottom left of the popup window -> ios development

THen you will see a new certificate created. Now you can run your app.

For me, just performing Product > Clean Build Folder in Xcode was enough to fix the issue.

I'm adding the solution that fixed it for me, and is already on that thread

The key issue here is the root certificate

Export and delete from login/certificate the certifictes named "Apple Worldwide Developer Relations Certification Authority" in your Keychain.

Do the same from system/certificate.

Import in system/certificate only ONE "Apple Worldwide Developer Relations Certification Authority". I imported the one that has the expiration date set to 2030 (not 2023).

You can also download the latest from: https://www.apple.com/certificateauthority/AppleWWDRCAG3.cer

That's all. But again, make sure it is in your Keychain's SYSTEM and you ONLY have ONE root certificate in your Keychain's SYSTEM area, AND NONE in LOGIN area.

You are using Distribution certificate instead of Development Certificate if you are able to install app in debug mode but it closes automatically once installation completed.

It is also important to note that the physical device you are trying to deploy to must be listed in the allowed devices list for that provisioning profile -> you can see this here in the tooltip that pops up from your cert information -> you want to make sure that your device is listed in the "Devices" section.

You can add / remove devices when you create the provisioning profile on the apple developer portal website.

Cert popup

Related