Apple's Certificate Transparency policy - Apple Support (2024)

Table of Contents
Policy requirements CT logs FAQs

Learn how to comply with Apple's Certificate Transparency policy.

Publicly trusted Transport Layer Security (TLS) server authentication certificates must meet Apple's Certificate Transparency (CT) policy to be evaluated as trusted on Apple platforms.

Certificates that fail to comply with our policy will result in a failed TLS connection, which can break an app’s connection to Internet services or Safari’s ability to seamlessly connect.

Policy requirements

Apple's policy requires at least two Signed Certificate Timestamps (SCT) issued from a CT log — once-approved1 or currently approved2 at the time of check — and either:

  • At least two SCTs from currently approved CT logs with one SCT presented via TLS extension or OCSP Stapling; or

  • At least one embedded SCT from a currently approved log and at least the number of SCTs from once or currently approved logs, based on validity period as detailed in the table below.

For certificates with a notBefore value greater than or equal to April 21, 2021 (2021-04-21T00:00:00Z), the Number of embedded SCTs based on certificate lifetime3:

Certificate lifetime

# of SCTs from separate logs

Maximum # of SCTs per log operator which count towards the SCT requirement

180 days or less

2

1

181 to 398 days

3

2

For certificates with a notBefore value less than April 21, 2021 (2021-04-21T00:00:00Z), the Number of embedded SCTs based on certificate lifetime:

Certificate lifetime

# of SCTs from separate logs

Less than 15 months

2

15 to 27 months

3

27 to 39 months

4

More than 39 months

5

For certificates with a notBefore value equal to or greater than 20210421T00:00:00Z, log operators MAY reject leaf certificates which don’t contain the serverAuth EKU.

Log operators MUST provide a minimum of 45 days’ advance written notice to [email protected] of any changes to the accepted set of leaf certificates their log(s) accepts.

CT logs

Download the current CT Log list and CT Log list schema in JSON format.

1. To be considered "once-approved", the timestamp in the SCT must have been issued from a CT log with a "Qualified" or "Usable" status at the time of the SCT issuance.

2. For CT log status definitions, please refer to Apple’s Certificate Transparency log program: https://support.apple.com/kb/HT209255

3. A certificate's validity period (or lifetime) is defined in line with RFC 5280, Section 4.1.2.5, as "the period of time from notBefore through notAfter, inclusive."

a. Validity period is measured with a day being equal to 86,400 seconds. Any time greater than this indicates an additional day of validity.

Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsem*nt. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Contact the vendor for additional information.

Published Date:

Apple's Certificate Transparency policy - Apple Support (2024)

FAQs

What is certificate transparency iOS? ›

The goal of Apple's Certificate Transparency log program is to establish a set of Certificate Transparency (CT) logs that are trusted on Apple's platforms to provide Signed Certificate Timestamps (SCT) for publicly trusted TLS server authentication certificates.

How do Apple certificates work? ›

Using certificates with Apple devices

A certificate contains a public key, information about the client (or server), and is signed (verified) by a CA. If iOS, iPadOS, macOS, or visionOS can't validate the trust chain of the signing CA, the service encounters an error.

What is the purpose of certificate transparency? ›

CT logs provide access to certificate and issuer information. You can check any domain's certificate issuer, location of the CA, issuance and expiry dates of an SSL certificate, subdomain coverage, history of all the previous certificates, and other important details in CT logs.

Is it good to reduce transparency on iPhone? ›

Make transparent items solid

In this way you simplify those parts of your screen and make them easier to see. Go to Settings > Accessibility > Display & Text Size. Turn on Reduce Transparency.

How much does an Apple certificate cost? ›

Apple Certification exams are offered online and cost $149 USD.

What can certificates do on an iPhone? ›

A certificate is usually restricted for particular uses, such as digital signatures, encryption, and use with web servers. This is called the “key use” restriction. Although it's possible to create one certificate for multiple uses, it's unusual to make one for all possible uses.

How do I check Apple certificates? ›

In the Keychain Access app on your Mac, click Certificates in the Category list, then double-click the certificate you want to evaluate. Choose Keychain Access > Certificate Assistant > Evaluate [certificate name].

What does transparency do on iPhone? ›

When you use AirPods Pro to listen to audio in Transparency mode, you can still hear the world around you. On iPhone, iPad, or Mac, you can customize which sounds come through when you use Transparency mode.

What is transparency app on iPhone? ›

The Transparency app allows you to scan enrolled products to verify their authenticity.

What is a transparency report on iPhone? ›

Apple is committed to your privacy and being transparent about government requests for customer data globally. This report provides information on government requests received.

What does certificate mean on iPhone? ›

The certificate you installed and trusted is used to provide you secure authentication against their RADIUS server and prevent you from connecting to rogue RADIUS server.

Top Articles
What does it mean if my credit score dips?
Bitcoin Price Prediction: No Confirmation of Breakout or Bloodbath, Price Drops Below $66K
Tryst Utah
Gamevault Agent
Http://N14.Ultipro.com
Chatiw.ib
Valley Fair Tickets Costco
Women's Beauty Parlour Near Me
Call Follower Osrs
Camstreams Download
Obituary Times Herald Record
Uvalde Topic
Olivia Ponton On Pride, Her Collection With AE & Accidentally Coming Out On TikTok
More Apt To Complain Crossword
Sams Early Hours
6001 Canadian Ct Orlando Fl
Dr Adj Redist Cadv Prin Amex Charge
Harem In Another World F95
Lonesome Valley Barber
Zalog Forum
Jalapeno Grill Ponca City Menu
Petco Vet Clinic Appointment
Robert Deshawn Swonger Net Worth
Walmart Car Department Phone Number
Qhc Learning
Valic Eremit
Bn9 Weather Radar
Malluvilla In Malayalam Movies Download
Relaxed Sneak Animations
JVID Rina sauce set1
CVS Health’s MinuteClinic Introduces New Virtual Care Offering
Safeway Aciu
Schooology Fcps
Blackstone Launchpad Ucf
The Ride | Rotten Tomatoes
Maybe Meant To Be Chapter 43
Muziq Najm
Weather Underground Bonita Springs
Fifty Shades Of Gray 123Movies
Сталь aisi 310s российский аналог
The best bagels in NYC, according to a New Yorker
Flipper Zero Delivery Time
How Big Is 776 000 Acres On A Map
N33.Ultipro
Worland Wy Directions
Server Jobs Near
How to Find Mugshots: 11 Steps (with Pictures) - wikiHow
Strawberry Lake Nd Cabins For Sale
Craigslist Yard Sales In Murrells Inlet
Escape From Tarkov Supply Plans Therapist Quest Guide
Varsity Competition Results 2022
Latest Posts
Article information

Author: Dr. Pierre Goyette

Last Updated:

Views: 6312

Rating: 5 / 5 (50 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Dr. Pierre Goyette

Birthday: 1998-01-29

Address: Apt. 611 3357 Yong Plain, West Audra, IL 70053

Phone: +5819954278378

Job: Construction Director

Hobby: Embroidery, Creative writing, Shopping, Driving, Stand-up comedy, Coffee roasting, Scrapbooking

Introduction: My name is Dr. Pierre Goyette, I am a enchanting, powerful, jolly, rich, graceful, colorful, zany person who loves writing and wants to share my knowledge and understanding with you.