31 pointsby strongpigeon3 hours ago8 comments
  • gt565k3 hours ago
    Enterprise apps distributed via MDM & signed using in-house distribution certificates are dead in the water too with the error message "Unable to Verify App" showing on start-up.

    Apple's status page is showing no problems (all green).

    This is a really bad look for Apple.

  • strongpigeon3 hours ago
    I'm getting invalid certificates from https://ppq.apple.com. I think that's probably the root cause?
    • astrostl3 hours ago
      Invalid certs according to what? Quoth Claude Code:

      OpenSSL can't validate the cert because it contains a critical extension it doesn't recognize — specifically 1.2.840.113635.100.6.27.3.2, which is an Apple-proprietary OID marked as critical. Per X.509 rules, if a client encounters an unrecognized critical extension, it must reject the cert.

      That said, this is likely intentional on Apple's part — browsers and Apple's own TLS stack (SecureTransport/Network.framework) almost certainly know how to handle this extension. It's a private Apple CA (Apple Server Authentication CA) signing an Apple-internal service endpoint, so it's designed to work within Apple's ecosystem rather than with generic OpenSSL.

      In practice:

        - Works fine in Apple clients (Safari, curl on macOS using the system TLS stack, iOS apps)                                                          
        - Fails with raw OpenSSL or other non-Apple TLS implementations                                                                                     
        - Not a misconfiguration — it's Apple intentionally using a proprietary critical extension on their private PKI
      • strongpigeon3 hours ago
        That's fair. I've never attempted to reach this before so I can't compare and the explanation makes sense.

        The intermittent 502s on the other hand are an issue.

    • gt565k3 hours ago
      Hilarious... their provisioning profile query server has an expired SSL certificate?

      Are you serious Apple?

      • strongpigeon3 hours ago
        It doesn't look expired per se:

          Issued On Wednesday, January 21, 2026 at 9:47:41 AM
          Expires On Wednesday, February 17, 2027 at 10:28:16 AM
        
        What I get is: net::ERR_CERT_AUTHORITY_INVALID
      • xutopia3 hours ago
        OMG my app just got rejected because I didn't have the right screenshots to their liking... an app specifically made to remember stuff like this LOL the irony!
  • xutopia3 hours ago
    For those wondering why this is a big deal it means that every developers attempting to run a development version of an iPhone, iPad or MacOS app cannot run their apps right now.

    This is worse than Github being down and Apple Developers who pay 99$ a year for the privilege of writing software on this ecosystem aren't event getting a status page update: https://developer.apple.com/system-status/

    • ToucanLoucan2 hours ago
      Can confirm. Spent over an hour trying to figure out why I couldn't build to devices just to get frustrated, browse to HN, and here we are.

      I'm looking for a job shoveling pig shit as we speak.

      What genuinely pisses me off is that this isn't noted on their status page, nor is it indicated at all when you, I dunno, revoke and generate certs repeatedly trying to solve a problem you didn't fucking cause.

  • ynac2 hours ago
    Any other services down for anyone? I've had a credit service portal fail for hours today with a notice of server issues. As well as a credit union login with a similar message. These are all first times for me. Some big black cape / hat pressure testing?

    [edit] And FreeUSATax portal. Solar cone today?

  • erkanerol2 hours ago
    Why is all green in the status page? Really really annoying.
  • tariksunean hour ago
    updated that there was an outage on app store connect https://developer.apple.com/system-status/

    edit: working now

  • avicado0oan hour ago
    Finally WORKING!!
  • semtra2 hours ago
    Bro im tryin to sideload and everytime i try to verify my app it doesnt let me what is even going on like i need my spotify back when will the certificates be back up what else can i use to sideload