certificate is not standards compliant

Can someone help please ?

I have added a certificate authority to keychain access and selected always trust for all compents. See screenshot please.

But when I visit a web site this is a certificate authority for the certificate is not standards compliant and the always trust component is overwritten. How do I correct this ? Please see screenshot

MacBook Air 13″, macOS 13.4

Posted on Sep 23, 2023 2:31 AM

Reply
Question marked as Top-ranking reply

Posted on Sep 23, 2023 3:27 AM

The user may consider reading this Support Article from Apple


refer below


Lists of available trusted root certificates in macOS


An excerpt from above link


" In light of these findings, we took action to protect users in a security update. Apple products no longer trust the WoSign CA Free SSL Certificate G2 intermediate CA.


To avoid disruption to existing WoSign certificate holders and to allow their transition to trusted roots, Apple products trust individual existing certificates that were issued from this intermediate CA and published to public Certificate Transparency log servers by 2016-09-19.


They will continue to be trusted until they expire, are revoked, or are untrusted at Apple’s discretion. "

7 replies
Question marked as Top-ranking reply

Sep 23, 2023 3:27 AM in response to d0nne11m

The user may consider reading this Support Article from Apple


refer below


Lists of available trusted root certificates in macOS


An excerpt from above link


" In light of these findings, we took action to protect users in a security update. Apple products no longer trust the WoSign CA Free SSL Certificate G2 intermediate CA.


To avoid disruption to existing WoSign certificate holders and to allow their transition to trusted roots, Apple products trust individual existing certificates that were issued from this intermediate CA and published to public Certificate Transparency log servers by 2016-09-19.


They will continue to be trusted until they expire, are revoked, or are untrusted at Apple’s discretion. "

Mar 29, 2024 11:36 PM in response to d0nne11m

I suspect this is because Apple has started marking any certificate with a validity period of greater than 398 days as "not standards compliant.


Apple originally claimed that this would not affect manually added ca's (here: About upcoming limits on trusted certificates – Apple Support (AU))


But we have since found this to not be the case. I can not find an official announcement of this policy.


Other digging on this forum seems to imply that for internally managed CA's, the limit is 825 days.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

certificate is not standards compliant

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.