One of my iPhone Distribution Certificates is about to expire soon.
I've generated the new Certificate with the same teamID and the corresponding Provisioning Profiles for a specific application. The problem I have, is that the old certificate is still used by some other applications in the same group.
The signing process is done through a Jenkins job, which executes a fastlane lane. Until now, Xcode, when exposed to the 2 valid certificates, is always choosing the newest one, which causes applications that are still using the old certificate to fail (signing error):
error: Provisioning profile "xxxx" doesn't include signing certificate "iPhone Distribution: xxxx". (in target 'xxxx' from project 'xxxx')
"xcodebuid --help" yields the following text regarding ExportOptions.plist parameters:
signingCertificate : String
For manual signing only. Provide a certificate name, SHA-1 hash, or automatic selector to use for signing. Automatic selectors allow Xcode to pick the newest installed certificate of a particular type. The available automatic selectors are "Mac App Distribution", "iOS Developer", "iOS Distribution", "Developer ID Application", "Apple Distribution", "Mac Developer", and "Apple Development". Defaults to an automatic certificate selector matching the current distribution method.
If I go to ExportOptions.plist and crete a key to force the SHA-1 (or even the certificate name), the error still appears.
While signing, is it possible to use the ExportOptions.plist file to uniquely identify a specific certificate, when both exist on the same keychain?
Any additional hint which I might have not be aware of?
Thanks in advance
Technological Stack:
- Xcode 11.1
- MacOS 11.4 Big Sur