Installing root certificates for APNS

Viewed 1905

we received a message from Apple notifying about CA certficates, old GeoTrust Global CA root certificate will be replaced by AAACertificateServices 5/12/2020. I was checking my App Engine settings and I didn't found any way to configure root certificates, so I suppose that Google manages these certificates. Am I right?

"On March 29, 2021, token and certificate-based HTTP/2 connections to the Apple Push Notification service must incorporate the new root certificate (AAACertificateServices 5/12/2020) which replaces the old GeoTrust Global CA root certificate. To ensure a seamless transition and to avoid push notification delivery failures, verify that both the old and new root certificates for the HTTP/2 interface are included in the Trust Store of each of your notification servers before March 29. If your provider server runs macOS, the GeoTrust Global CA root certificate is in the keychain by default. If your provider server runs macOS 10.14 or later, the AAA Certificate Services root certificate is in the keychain by default. On other systems, you might need to install this certificate yourself. You can download the GeoTrust Global CA root certificate from the GeoTrust Root Certificates website. You can download the “AAACertificateServices 5/12/2020” certificate from the Sectigo KnowledgeBase website."

Kindest regards

1 Answers

My understanding is that Google manages the root certificate unless your app engine app is making use of a custom domain (ie is not served on *.appspot.com) and that you are not using a Google-managed certificate for this custom domain.

Still I would like to be able to formally check that things will work fine in the transition, but I did not find how to do so. Looking at the root certificate of *.appspot.com shows a Global Sign root certificate, not the legacy GeoTrust certificate Apple's APN servers are relying on currently. But as *.appspot.com is currently connecting properly to Apple's APN servers, I guess there is a matter of cross-signing or mutual recognition across certificate authorities which plays a role here.

I would also have expected Apple's sandbox APN server to transition earlier than Production for developers to see failure in their tests environment first, but I haven't seen Apple communicate any specifics on this.

Overall I'm not worried as I understand this is Apple finally migrating to a widely recognized root certificate, whereas the current one was already considered unsafe by many organizations. Also meaning we're quite lucky that connecting to APNs has been working fine out-of-the-box with App Engine until today (and hoping that will last until end of March!)

Related