Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7446095
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 29, 20262026-05-29T12:12:57+00:00 2026-05-29T12:12:57+00:00

Our customer has just joined the iOS Developer Enterprise Program. They have signed the

  • 0

Our customer has just joined the iOS Developer Enterprise Program. They have signed the app (developed by us) with their Enterprise Distribution and installed it succesfully in some devices via MDM.

As far as I know when my non-enterprise distribution certificate expires I have to renew it. This expiration disables all apps signed with the expired certificate as soon as the devices checks the certificate’s validity against Apple’s OCSP server.

Alternatively, I can revoke my non-enterprise distribution before the expiration date and ask for a new one to Apple. Applications signed with the revoked certificate, for example Ad Hoc beta apps, will be disabled according to the same mechanism.

So with my developer program I can’t have two valid distribution certificates at the same time. Ok, as developers we can live with that.

Can our customer have two valid Enterprise Distribution certificates at the same time with the iOS Developer Enterprise Program?

According to Apple:

Certificate Validation

The first time an application is opened on a device, the distribution
certificate is validated by contacting Apple’s OCSP server. Unless the
certificate has been revoked, the app is allowed to run. Inability to
contact or get a response from the OCSP server is not interpreted as a
revocation. To verify the status, the device must be able to reach
ocsp.apple.com. See“Network Configuration Requirements”(page 9).

The OCSP response is cached on the device for the period of time specified
by the OCSP server—currently between 3 and 7 days. The validity of the
certificate will not be checked again until the device has
restarted and the cached response has expired. If a revocation is
received at that time, the app will be prevented from running. Revoking
a distribution certificate will invalidate all of the applications you
have distributed.

An app will not run if the distribution certificate
has expired. Currently, distribution certificates are valid for one
year. A few weeks before your certificate expires, request a new
distribution certificate from the iOS DevCenter, use it to create new
distribution provisioning profiles, and then recompile and distribute the
updated apps to your users. See “Providing Updated Apps” (page 10)

Am I missing something or is is possible that the employees, with potentially hundreds of iOS devices with several In House apps, can’t open their applications while they wait for the resigned apps?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-29T12:12:58+00:00Added an answer on May 29, 2026 at 12:12 pm

    This is an issue that we have been dealing since the last 2 years. The in-house applications do stop working after 1 year. It is a massive exercise for an organization like ours to rebuild hundreds of apps and redeploy it on thousands of devices every year.

    For us it is a month long exercise where we rebuild all our apps and inform all users to get new ones through the distribution channel. Still every year some users are left with non-functional apps.

    I have filed an enhancement request with Apple(Bug ID#9848075) for this and am still waiting for a reply.

    EDIT:
    The above mentioned bug is closed now. Here’s the official response:

    Distribution certs for enterprise are now 3 years in duration.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

In informal conversations with our customer service department, they have expressed dissatisfaction with our
Our app (before authentication) has Customers and Widgets. As you'd expect each customer has
Our customer wants to use their existing active directory to authenticate users on a
our customer is loving the Jasper viewer, but we have a problem. It exports
We developed an asp.net website for one of our customer. We followed our rules
The web application my organization has written to perform customer care functions doesn't have
Our organization currently has an external customer website that allows customers to download files
Say we have a class of Customer and that has a child object of
My company has a ClickOnce application that has been in use with our customers
Our customer would like to know who is online and currently using the custom

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.