Apple's Certificate Transparency policy - Apple Support (2024)

Table of Contents
Policy requirements CT logs FAQs

Learn how to comply with Apple's Certificate Transparency policy.

Publicly trusted Transport Layer Security (TLS) server authentication certificates must meet Apple's Certificate Transparency (CT) policy to be evaluated as trusted on Apple platforms.

Certificates that fail to comply with our policy will result in a failed TLS connection, which can break an app’s connection to Internet services or Safari’s ability to seamlessly connect.

Policy requirements

Apple's policy requires at least two Signed Certificate Timestamps (SCT) issued from a CT log — once-approved1 or currently approved2 at the time of check — and either:

  • At least two SCTs from currently approved CT logs with one SCT presented via TLS extension or OCSP Stapling; or

  • At least one embedded SCT from a currently approved log and at least the number of SCTs from once or currently approved logs, based on validity period as detailed in the table below.

For certificates with a notBefore value greater than or equal to April 21, 2021 (2021-04-21T00:00:00Z), the Number of embedded SCTs based on certificate lifetime3:

Certificate lifetime

# of SCTs from separate logs

Maximum # of SCTs per log operator which count towards the SCT requirement

180 days or less

2

1

181 to 398 days

3

2

For certificates with a notBefore value less than April 21, 2021 (2021-04-21T00:00:00Z), the Number of embedded SCTs based on certificate lifetime:

Certificate lifetime

# of SCTs from separate logs

Less than 15 months

2

15 to 27 months

3

27 to 39 months

4

More than 39 months

5

For certificates with a notBefore value equal to or greater than 20210421T00:00:00Z, log operators MAY reject leaf certificates which don’t contain the serverAuth EKU.

Log operators MUST provide a minimum of 45 days’ advance written notice to certificate-transparency-program@group.apple.com of any changes to the accepted set of leaf certificates their log(s) accepts.

CT logs

Download the current CT Log list and CT Log list schema in JSON format.

1. To be considered "once-approved", the timestamp in the SCT must have been issued from a CT log with a "Qualified" or "Usable" status at the time of the SCT issuance.

2. For CT log status definitions, please refer to Apple’s Certificate Transparency log program: https://support.apple.com/kb/HT209255

3. A certificate's validity period (or lifetime) is defined in line with RFC 5280, Section 4.1.2.5, as "the period of time from notBefore through notAfter, inclusive."

a. Validity period is measured with a day being equal to 86,400 seconds. Any time greater than this indicates an additional day of validity.

Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsem*nt. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Contact the vendor for additional information.

Published Date:

Apple's Certificate Transparency policy - Apple Support (2024)

FAQs

What is certificate transparency iOS? ›

The goal of Apple's Certificate Transparency log program is to establish a set of Certificate Transparency (CT) logs that are trusted on Apple's platforms to provide Signed Certificate Timestamps (SCT) for publicly trusted TLS server authentication certificates.

How do Apple certificates work? ›

Using certificates with Apple devices

A certificate contains a public key, information about the client (or server), and is signed (verified) by a CA. If iOS, iPadOS, macOS, or visionOS can't validate the trust chain of the signing CA, the service encounters an error.

What is the purpose of certificate transparency? ›

CT logs provide access to certificate and issuer information. You can check any domain's certificate issuer, location of the CA, issuance and expiry dates of an SSL certificate, subdomain coverage, history of all the previous certificates, and other important details in CT logs.

Is it good to reduce transparency on iPhone? ›

Make transparent items solid

In this way you simplify those parts of your screen and make them easier to see. Go to Settings > Accessibility > Display & Text Size. Turn on Reduce Transparency.

How much does an Apple certificate cost? ›

Apple Certification exams are offered online and cost $149 USD.

What can certificates do on an iPhone? ›

A certificate is usually restricted for particular uses, such as digital signatures, encryption, and use with web servers. This is called the “key use” restriction. Although it's possible to create one certificate for multiple uses, it's unusual to make one for all possible uses.

How do I check Apple certificates? ›

In the Keychain Access app on your Mac, click Certificates in the Category list, then double-click the certificate you want to evaluate. Choose Keychain Access > Certificate Assistant > Evaluate [certificate name].

What does transparency do on iPhone? ›

When you use AirPods Pro to listen to audio in Transparency mode, you can still hear the world around you. On iPhone, iPad, or Mac, you can customize which sounds come through when you use Transparency mode.

What is transparency app on iPhone? ›

The Transparency app allows you to scan enrolled products to verify their authenticity.

What is a transparency report on iPhone? ›

Apple is committed to your privacy and being transparent about government requests for customer data globally. This report provides information on government requests received.

What does certificate mean on iPhone? ›

The certificate you installed and trusted is used to provide you secure authentication against their RADIUS server and prevent you from connecting to rogue RADIUS server.

Top Articles
Mining Difficulty: What Is It And Benefits
Is Buying a Drone Worth It in 2023? (Business and Hobby) - Pilot Institute
Antisis City/Antisis City Gym
Where To Go After Howling Pit Code Vein
Www.1Tamilmv.cafe
Lifebridge Healthstream
Alan Miller Jewelers Oregon Ohio
Boomerang Media Group: Quality Media Solutions
Why Is Stemtox So Expensive
Erskine Plus Portal
National Office Liquidators Llc
Samantha Lyne Wikipedia
Napa Autocare Locator
Spergo Net Worth 2022
Red Devil 9664D Snowblower Manual
Unterwegs im autonomen Freightliner Cascadia: Finger weg, jetzt fahre ich!
Kp Nurse Scholars
China’s UberEats - Meituan Dianping, Abandons Bike Sharing And Ride Hailing - Digital Crew
Kountry Pumpkin 29
Cbssports Rankings
Doublelist Paducah Ky
Toothio Login
The best brunch spots in Berlin
Drying Cloths At A Hammam Crossword Clue
Cardaras Funeral Homes
Spectrum Outage in Queens, New York
Movies - EPIC Theatres
Riverstock Apartments Photos
Shia Prayer Times Houston
Gncc Live Timing And Scoring
Craigslist Middletown Ohio
One Credit Songs On Touchtunes 2022
Terrier Hockey Blog
Metra Schedule Ravinia To Chicago
Studentvue Columbia Heights
Soulstone Survivors Igg
Conroe Isd Sign In
Adam Bartley Net Worth
Easy Pigs in a Blanket Recipe - Emmandi's Kitchen
How To Upgrade Stamina In Blox Fruits
Craigslist Freeport Illinois
Fedex Passport Locations Near Me
Bmp 202 Blue Round Pill
Funkin' on the Heights
Wzzm Weather Forecast
Rick And Morty Soap2Day
Diario Las Americas Rentas Hialeah
Model Center Jasmin
The 5 Types of Intimacy Every Healthy Relationship Needs | All Points North
Diamond Desires Nyc
Grace Charis Shagmag
Latest Posts
Article information

Author: Dr. Pierre Goyette

Last Updated:

Views: 6312

Rating: 5 / 5 (50 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Dr. Pierre Goyette

Birthday: 1998-01-29

Address: Apt. 611 3357 Yong Plain, West Audra, IL 70053

Phone: +5819954278378

Job: Construction Director

Hobby: Embroidery, Creative writing, Shopping, Driving, Stand-up comedy, Coffee roasting, Scrapbooking

Introduction: My name is Dr. Pierre Goyette, I am a enchanting, powerful, jolly, rich, graceful, colorful, zany person who loves writing and wants to share my knowledge and understanding with you.