Rathie2155 wrote:
I found some thing on the developer website suggesting it has to do with device management.
Pretty much everything related to encryption and to distributed authentication is dependent on the Apple trust store.
Adding a locally-trusted certificate within an app bundle (as a developer can do) or adding a certificate using a profile (as an IT group can do) is unrelated to the Apple trust store (as discussed in this “what is this trust store version?” thread).
Here is the previous thread seemingly referenced with the text quoted: Why is there a trusted certificate on my … - Apple Community
The user that initiated that thread never returned to follow-up, and the reply provides some suggestions for finding the source of an added certificate. That thread about an added certificate does not address or particularly reference the Apple system trust store from this thread.
For WS-Trust distributed authentication, a client could use a private certificate chain for single sign-on, or could present a certificate that traces back to the Apple certificate chain for that.