trusted root certificates, what should be there by default from apple

Following a recent number of incidents with my machine Ive discovered that within my keychain there are over 160 trusted roots often with three for each body, an unqilified, a rsa and a ca g3 version + many more that i personally dont trust. I understand these can be maintained by the user following install of the os but my ability seems to be locked preventing me removing them. Wanted to know if anyone knew how to enable edit access, what the official list should be as im sure its not this large given there are only 13 root identies so at maximum this list should contain 13 certificates to start with. Similarly how do edit/check the certificates that exist right before install of the os from recovery mode to ensure i have a correctly signed copy. My goal is to ensure the version im installing is the apple worldwide release signed by the apple root server from recovery mode. Thanks

MacBook Pro 16″, 13.2

Posted on Mar 23, 2023 5:51 PM

Reply
Question marked as Top-ranking reply

Posted on Mar 23, 2023 6:53 PM

You will want to describe the “incidents” here.


Here are the: Available trusted root certificates for Apple operating systems - Apple Support


The certificate root store is protected by system integrity protection, and cannot be modified.


If the macOS system has been compromised such that changes to the root store are seriously suspected or have been identified, then the entire system has been completely compromised, and the current contents should probably be preserved for offline forensics, and the entire system then wiped and re-installed, and without performing a restore.


Similar questions

1 reply
Question marked as Top-ranking reply

Mar 23, 2023 6:53 PM in response to zach_rzn

You will want to describe the “incidents” here.


Here are the: Available trusted root certificates for Apple operating systems - Apple Support


The certificate root store is protected by system integrity protection, and cannot be modified.


If the macOS system has been compromised such that changes to the root store are seriously suspected or have been identified, then the entire system has been completely compromised, and the current contents should probably be preserved for offline forensics, and the entire system then wiped and re-installed, and without performing a restore.


This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

trusted root certificates, what should be there by default from apple

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.