CA certificates with additional constraints

Certificate configuration data updates apply additional constraints to certificates included in Apple operating systems.

About certificate configuration data

Certification Authority (CA) certificates play a key role in the security of online communications. To help maintain a high level of security, Apple requires the vendors of certificates included in our operating systems — iOS, iPadOS, macOS, tvOS, watchOS, and visionOS — to comply with industry standards and our program requirements.

Updates to certificate configuration data are sent to user devices automatically and as needed, and they modify the behavior of the CA certificates that are included by default in Apple operating systems. Typically, these updates constrain or entirely block CA certificates to protect users from CA vendors that fail to comply with industry standards.

Learn more about default-included CA certificates.

Learn about the distrust of Symantec CA certificates.

Blocked Certificates

Certificate SHA256 Fingerprint

Certificate Name

e3268f6106ba8b665a1a962ddea1459d2a46972f1f2440329b390b895749ad45

ANF Global Root CA

0f570d7502373a2102e2106faaa8fa4844944a07ee676198484f4d6ce15bea47

Apple Worldwide Developer Relations CA - G7

0ed3ffab6c149c8b4e71058e8668d429abfda681c2fff508207641f0d751a3e5

Autoridad de Certificacion Raiz del Estado Venezolano

f96f23f4c3e79c077a46988d5af5900676a0f039cb645dd17549b216c82440ce

CA Disig Root R1

fcbfe2886206f72b27593c8b070297e12d769ed10ed7930705a8098effc14d17

Certinomis - Autorité Racine

2a99f5bc1174b73cbb1d620884e01c34e51ccb3978da125f0e33268883bf4158

Certinomis - Root CA

152a402bfcdf2cd548054d2275b39c7fca3ec0978078b0f0ea76e561a6c7433e

Certplus Root CA G1

6cc05041e6445e74696c4cfbc9f80f543b7eabbb44b4ce6f787c6a9971c42f17

Certplus Root CA G2

0c258a12a5674aef25f28ba7dcfaeceea348e541e6f5cc4ee63b71b361606ac3

Chambers of Commerce Root

8327bc8c9d69947b3de3c27511537267f59c21b9fa7b613fafbccd53b7024000

Cisco Root CA 2048

e28393773da845a679f2080cc7fb44a3b7a1c3792cb7eb7729fdcb6a8d99aea7

CNNIC ROOT

ae4457b40d9eda96677b0d3c92d57b5177abd7ac1037958356d1e094518be5f2

ComSign CA

507941c74460a0b47086220d4e9932572ab5d1b5bbcb8980ab1cb17651a844d2

ComSign Secured CA

1685ba27fdf24cece203fd829ac3fed5c85460ed0735b2d15751019e951540c0

DigiNotar Public CA 2025

5bf3a3b793465f3767d7c7b4a03d80367c8957c498299c29b903f33fe340af7a

DigiNotar Qualified CA

6bf5533d0ddeaf023d58e401277c26442b1f1af1a0f2dbbd9b2e3ba3a292fb23

DigiNotar Root CA

0d136e439f0ab6e97f3a02a540da9f0641aa554e1d66ea51ae2920d51b2f7217

DigiNotar Root CA

294f55ef3bd7244c6ff8a68ab797e9186ec27582751a791515e3292e48372d61

DigiNotar Root CA G2

71253459e5e64d1f9077a5c458999b67d7d9e70706af680b045eb1d27b79e38f

DigiNotar Services 1024 CA

a6a2217c1d192fe71fce87870167011c26e1a9b8582f5f08d8ecb9b3209f5fdb

DigiNotar Services CA

6639d13cab85df1ad9a23c443b3a60901e2b138d456fa71183578108884ec6bf

Echoworx Root CA2

abd055c297005a89e4458ae34d4bc77e67db0fe1be575842c4efb7e8c3e05839

Facebook Research

37d51006c512eaab626421f1ec8c92013fc5f82ae98ee533eb4619b8deb4d06c

GeoTrust Primary Certification Authority

b478b812250df878635c2aa7ec7d155eaa625ee82916e2cd294361886cd1fbd4

GeoTrust Primary Certification Authority - G3

ef3cb417fc8ebf6f97876c9e4ece39de1ea5fe649141d1028b7d11c0b2298ced

Global Chambersign Root

70b922bfda0e3f4a342e4ee22d579ae598d071cc5ec9c30f123680340388aea5

Government Root Certification Authority

bc104f15a48be709dca542a7e1d4b9df6f054527e802eaa92d595444258afe71

Hellenic Academic and Research Institutions RootCA 2011

6fdb3f76c8b801a75338d8a50a7c02879f6198b57e594d318d3832900fedcd79

KISA RootCA 1

15f0ba00a3ac7af3ac884c072b1011a077bd77c097f40164b2f8598abd83860c

Network Solutions Certificate Authority

56c77128d98c18d91b4cfdffbc25ee9103d4758ea2abad826a90f3457d460eb4

OpenTrust Root CA G1

27995829fe6a7515c1bfe848f9c4761db16c225929257bf40d0894f29ea8baf2

OpenTrust Root CA G2

b7c36231706e81078c367cb896198f1e3208dd926949dd8f5709a410f75b6292

OpenTrust Root CA G3

00309c736dd661da6f1eb24173aa849944c168a43a15bffd192eecfdb6f8dbd2

Qaznet Trust Network

a22dba681e97376e2d397d728aae3a9b6296b9fdba60bc2e11f647f2c675fb37

SECOM Trust Systems CO.,LTD./Security Communication EV RootCA1

4200f5043ac8590ebb527d209ed1503029fbcbd41ca1b506ec27f15ade7dac69

Secure Global CA

91e5cc32910686c5cac25c18cc805696c7b33868c280caf0c72844a2a8eb91e2

SenncomRootCA

3c4fb0b95ab8b30032f432b86f535fe172c185d0fd39865837cf36187fa6f428

Staat der Nederlanden Root CA - G3

c766a9bef2d4071c863a31aa4920e813b2d198608cb7b7cfe21143b836df09ea

StartCom Certification Authority

e17890ee09a3fbf4f48b9c414a17d637b7a50647e9bc752322727fcc1742a911

StartCom Certification Authority

c7ba6567de93a798ae1faa791e712d378fae1f93c4397fea441bb7cbe6fd5995

StartCom Certification Authority G2

21db20123660bb2ed418205da11ee7a85a65e2bc6e55b5af7e7899c8a266d92e

Swisscom Root CA 1

f09b122c7114f4a09bd4ea4f4a99d558b46e4c25cd81140d29c05613914c3841

Swisscom Root CA 2

d95fea3ca4eedce74cd76e75fc6d1ff62c441f0fa8bc77f034b19e5db258015d

Swisscom Root EV CA 2

3b222e566711e992300dc0b15ab9473dafdef8c84d0cef7d3317b4c1821d1436

SwissSign Platinum CA - G2

363f3c849eab03b0a2a0f636d7b86d04d3ac7fcfe26a0a9121ab9795f6e176df

Symantec Class 1 Public Primary Certification Authority - G4

9d190b2e314566685be8a889e27aa8c7d7ae1d8aaddba3c1ecf9d24863cd34b9

Symantec Class 1 Public Primary Certification Authority - G6

fe863d0822fe7a2353fa484d5924e875656d3dc9fb58771f6f616f9d571bc592

Symantec Class 2 Public Primary Certification Authority - G4

cb627d18b58ad56dde331a30456bc65c601a4e9b18dedcea08e7daaa07815ff0

Symantec Class 2 Public Primary Certification Authority - G6

53dfdfa4e297fcfe07594e8c62d5b8ab06b32c7549f38a163094fd6429d5da43

Symantec Class 3 Public Primary Certification Authority - G4

b32396746453442f353e616292bb20bbaa5d23b546450fdb9c54b8386167d529

Symantec Class 3 Public Primary Certification Authority - G6

fabcf5197cdd7f458ac33832d3284021db2425fd6bea7a2e69b7486e8f51f9cc

SZAFIR ROOT CA

8d722f81a9c113c0791df136a2966db26c950a971db46b4199f4ea54b78bfb9f

thawte Primary Root CA

a4310d50af18a6447190372a86afaf8b951ffb431d837f1e5688b45971ed1557

thawte Primary Root CA - G2

4b03f45807ad70f21bfc2cae71c9fde4604c064cf5ffb686bae5dbaad7fdd34c

thawte Primary Root CA - G3

61dab17b03b2c239ae41d6a0712882d1484b821d0eb895d52f0fec634db713b8

TMRG

92d8092ee77bc9208f0897dc05271894e63ef27933ae537fb983eef0eae3eec8

TRUST2408 OCES Primary CA

c1b48299aba5208fe9630ace55ca68a03eda5a519c8802a0d3a673be8f8e557d

Trustis Limited/Trustis FPS Root CA

77dece8000964a74aeed685c0c9301f081a29b6f1803b14230dbd0bac7a39cfc

Trustwave Organization Issuing CA, Level 2

cbb5af185e942a2402f9eacbc0ed5bb876eea3c1223623d00447e4f3ba554b65

VeriSign Class 1 Public Primary Certification Authority - G3

92a9d9833fe1944db366e8bfae7a95b6480c2d6c6c2a1be65d4236b608fca1bb

VeriSign Class 2 Public Primary Certification Authority - G3

a4b6b3996fc2f306b3fd8681bd63413d8c5009cc4fa329c2ccf0e2fa1b140305

VeriSign Class 3 Public Primary Certification Authority

eb04cf5eb1f39afa762f2bb120f296cba520c1b97db1589565b81cb9a17b7244

VeriSign Class 3 Public Primary Certification Authority - G3

69ddd7ea90bb57c93e135dc85ea6fcd5480b603239bdc454fc758b2a26cf7f79

VeriSign Class 3 Public Primary Certification Authority - G4

2399561127a57125de8cefea610ddf2fa078b5c8067f4e828290bfb860e84b3c

VeriSign Universal Root Certification Authority

4b15a4ee04f0bdb6c7ef1a15b63c72006688f7ca3d8ccdc0133b90a739e1aa55

VoiceFive

41a235ab60f0643e752a2db4e914d68c0542167de9ca28df25fd79a693c29072

WoSign CA Free SSL Certificate G2

Constrained Certificates

TLS constrained

These certificates, and the certificates they issue, cannot be used to establish TLS connections.

Certificate SHA256 Fingerprint

Certificate Name

e38655f4b0190c84d3b3893d840a687e190a256d98052f159e6d4a39f589a6eb

Atos TrustedRoot Root CA ECC G2 2020

78833a783bb2986c254b9370d3c20e5eba8fa7840cbf63fe17297a0b0119685e

Atos TrustedRoot Root CA RSA G2 2020

d8e0febc1db2e38d00940f37d27d41344d993e734b99d5656d9778d4d8143624

Certum CA

063e4afac491dfd332f3089b8542e94617d893d7fe944e10a7937ee29d9693c0

Chambers of Commerce Root - 2008

e8e8176536a60cc2c4e10187c3befca20ef263497018f566d5bea0f94d0c111b

DigiCert SMIME ECC P384 Root G5

90370d3efa88bf58c30105ba25104a358460a7fa52dfc2011df233a0f417912a

DigiCert SMIME RSA4096 Root G5

136335439334a7698016a0d324de72284e079d7b5220bb8fbd747816eebebaca

Global Chambersign Root - 2008

22d9599234d60f1d4bc7c7e96f43fa555b07301fd475175089dafb8c25e477b3

Sectigo Public Email Protection Root E46

d5917a7791eb7cf20a2e57eb98284a67b28a57e89182da53d546678c9fde2b4f

Sectigo Public Email Protection Root R46

e44ddb7952261f15005cd60c1d0c38c18cbfd17c273a31f8ed4c8f53e2685f32

Sectigo Public Time Stamping Root E46

4941b001b8a97e961b7817c9d9e960ec4b056bfc915a8c1aabf6ef6b3ac046a5

Sectigo Public Time Stamping Root R46

ad7dd58d03aedb22a30b5084394920ce12230c2d8017ad9b81ab04079bdd026b

SSL.com Client ECC Root CA 2022

1d4ca4a2ab21d0093659804fc0eb2175a617279b56a2475245c9517afeb59153

SSL.com Client RSA Root CA 2022

cecddc905099d8dadfc5b1d209b737cbe2c18cfb2c10c0ff0bcf0d3286fc1aa2

XRamp Global Certification Authority

S/MIME constrained

These certificates, and the certificates they issue, cannot be used to sign or encrypt emails

Certificate SHA256 Fingerprint

Certificate Name

0376ab1d54c5f9803ce4b2e201a0ee7eef7b57b636e8a93c9b8d4860c96f5fa7

AffirmTrust Commercial

0a81ec5a929777f145904af38d5d509f66b5e2c58fcdb531058b0e17f3f0b41b

AffirmTrust Networking

70a73f7f376b60074248904534b11482d5bf0e698ecc498df52577ebf2e93b9a

AffirmTrust Premium

bd71fdf6da97e4cf62d1647add2581b07d79adf8397eb4ecba9c5e8488821423

AffirmTrust Premium ECC

b2fae53e14ccd7ab9212064701ae279c1d8988facb775fa8a008914e663988a8

Atos TrustedRoot Root CA ECC TLS 2021

81a9088ea59fb364c548a6f85559099b6f0405efbf18e5324ec9f457ba00112f

Atos TrustedRoot Root CA RSA TLS 2021

04048028bf1f2864d48f9ad4d83294366a828856553f3b14303f90147f5d40ef

Autoridad de Certificacion Firmaprofesional CIF A62634068

5cc3d78e4e1d5e45547a04e6873e64f90cf9536d1ccc2ef800f355c4c5fd70fd

CFCA EV ROOT

018e13f0772532cf809bd1b17281867283fc48c6e13be9c69812854a490c1b05

DigiCert TLS ECC P384 Root G5

371a00dc0533b3721a7eeb40e8419e70799d2b0a0f2c1d80693165f7cec4ad75

DigiCert TLS RSA4096 Root G5

b085d70b964f191a73e4af0d54ae7a0e07aafdaf9b71dd0862138ab7325a24a2

GlobalSign ECC Root CA - R4

d947432abde7b7fa90fc2e6b59101b1280e0e1c7e4e40fa3c6887fff57a7f4cf

GTS Root R1

349dfa4058c5e263123b398ae795573c4e1313c83fe68f93556cd5e8031b3c7d

GTS Root R4

96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6

ISRG Root X1

69729b8e15a86efc177a57afb7171dfc64add28c2fca8cf1507e34453ccb1470

ISRG Root X2

8fe4fb0af93a4d0d67db0bebb23e37c71bf325dcbcdd240ea04daf58b47e1840

QuoVadis Root CA 2 G3

c90f26f0fb1b4018b22227519b5ca2b53e2ca5b3be5cf18efe1bef47380c5383

Sectigo Public Server Authentication Root E46

7bb647a62aeeac88bf257aa522d01ffea395e0ab45c73f93f65654ec38f25a06

Sectigo Public Server Authentication Root R46

e44ddb7952261f15005cd60c1d0c38c18cbfd17c273a31f8ed4c8f53e2685f32

Sectigo Public Time Stamping Root E46

4941b001b8a97e961b7817c9d9e960ec4b056bfc915a8c1aabf6ef6b3ac046a5

Sectigo Public Time Stamping Root R46

e74fbda55bd564c473a36b441aa799c8a68e077440e8288b9fa1e50e4bbaca11

Security Communication ECC RootCA1

22a2c1f7bded704cc1e701b5f408c310880fe956b5de2a4a44f99c873a25a7c8

SSL.com EV Root Certification Authority ECC

2e7bf16cc22485a7bbe2aa8696750761b0ae39be3b2fe9d0cc6d4ef73491425c

SSL.com EV Root Certification Authority RSA R2

c32ffd9f46f936d16c3673990959434b9ad60aafbb9e7cf33654f144cc1ba143

SSL.com TLS ECC Root CA 2022

8faf7d2e2cb4709bb8e0b33666bf75a5dd45b5de480f8ea8d4bfe6bebc17f2ed

SSL.com TLS RSA Root CA 2022

2ce1cb0bf9d2f9e102993fbe215152c3b2dd0cabde1c68e5319b839154dbb7f5

Starfield Root Certificate Authority - G2

568d6905a2c88708a4b3025190edcfedb1974a606a13c6e5290fcb2ae63edab5

Starfield Services Root Certificate Authority - G2

fd73dad31c644ff1b43bef0ccdda96710b9cd9875eca7e31707af3e96d522bbd

T-TeleSec GlobalRoot Class 3

46edc3689046d53a453fb3104ab80dcaec658b2660ea1629dd7e867990648716

TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 1

Timestamp constrained

These certificates, and the certificates they issue, cannot be used to sign timestamps.

Certificate SHA256 Fingerprint

Certificate Name

e38655f4b0190c84d3b3893d840a687e190a256d98052f159e6d4a39f589a6eb

Atos TrustedRoot Root CA ECC G2 2020

b2fae53e14ccd7ab9212064701ae279c1d8988facb775fa8a008914e663988a8

Atos TrustedRoot Root CA ECC TLS 2021

78833a783bb2986c254b9370d3c20e5eba8fa7840cbf63fe17297a0b0119685e

Atos TrustedRoot Root CA RSA G2 2020

81a9088ea59fb364c548a6f85559099b6f0405efbf18e5324ec9f457ba00112f

Atos TrustedRoot Root CA RSA TLS 2021

e8e8176536a60cc2c4e10187c3befca20ef263497018f566d5bea0f94d0c111b

DigiCert SMIME ECC P384 Root G5

90370d3efa88bf58c30105ba25104a358460a7fa52dfc2011df233a0f417912a

DigiCert SMIME RSA4096 Root G5

018e13f0772532cf809bd1b17281867283fc48c6e13be9c69812854a490c1b05

DigiCert TLS ECC P384 Root G5

371a00dc0533b3721a7eeb40e8419e70799d2b0a0f2c1d80693165f7cec4ad75

DigiCert TLS RSA4096 Root G5

b085d70b964f191a73e4af0d54ae7a0e07aafdaf9b71dd0862138ab7325a24a2

GlobalSign ECC Root CA - R4

d947432abde7b7fa90fc2e6b59101b1280e0e1c7e4e40fa3c6887fff57a7f4cf

GTS Root R1

8d25cd97229dbf70356bda4eb3cc734031e24cf00fafcfd32dc76eb5841c7ea8

GTS Root R2

34d8a73ee208d9bcdb0d956520934b4e40e69482596e8b6f73c8426b010a6f48

GTS Root R3

349dfa4058c5e263123b398ae795573c4e1313c83fe68f93556cd5e8031b3c7d

GTS Root R4

96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6

ISRG Root X1

69729b8e15a86efc177a57afb7171dfc64add28c2fca8cf1507e34453ccb1470

ISRG Root X2

22d9599234d60f1d4bc7c7e96f43fa555b07301fd475175089dafb8c25e477b3

Sectigo Public Email Protection Root E46

d5917a7791eb7cf20a2e57eb98284a67b28a57e89182da53d546678c9fde2b4f

Sectigo Public Email Protection Root R46

c90f26f0fb1b4018b22227519b5ca2b53e2ca5b3be5cf18efe1bef47380c5383

Sectigo Public Server Authentication Root E46

7bb647a62aeeac88bf257aa522d01ffea395e0ab45c73f93f65654ec38f25a06

Sectigo Public Server Authentication Root R46

e74fbda55bd564c473a36b441aa799c8a68e077440e8288b9fa1e50e4bbaca11

Security Communication ECC RootCA1

ad7dd58d03aedb22a30b5084394920ce12230c2d8017ad9b81ab04079bdd026b

SSL.com Client ECC Root CA 2022

1d4ca4a2ab21d0093659804fc0eb2175a617279b56a2475245c9517afeb59153

SSL.com Client RSA Root CA 2022

c32ffd9f46f936d16c3673990959434b9ad60aafbb9e7cf33654f144cc1ba143

SSL.com TLS ECC Root CA 2022

8faf7d2e2cb4709bb8e0b33666bf75a5dd45b5de480f8ea8d4bfe6bebc17f2ed

SSL.com TLS RSA Root CA 2022

Code Signing constrained

These certificates, and the certificates they issue, cannot be used to sign code.

Certificate SHA256 Fingerprint

Certificate Name

e38655f4b0190c84d3b3893d840a687e190a256d98052f159e6d4a39f589a6eb

Atos TrustedRoot Root CA ECC G2 2020

b2fae53e14ccd7ab9212064701ae279c1d8988facb775fa8a008914e663988a8

Atos TrustedRoot Root CA ECC TLS 2021

78833a783bb2986c254b9370d3c20e5eba8fa7840cbf63fe17297a0b0119685e

Atos TrustedRoot Root CA RSA G2 2020

81a9088ea59fb364c548a6f85559099b6f0405efbf18e5324ec9f457ba00112f

Atos TrustedRoot Root CA RSA TLS 2021

e8e8176536a60cc2c4e10187c3befca20ef263497018f566d5bea0f94d0c111b

DigiCert SMIME ECC P384 Root G5

90370d3efa88bf58c30105ba25104a358460a7fa52dfc2011df233a0f417912a

DigiCert SMIME RSA4096 Root G5

018e13f0772532cf809bd1b17281867283fc48c6e13be9c69812854a490c1b05

DigiCert TLS ECC P384 Root G5

371a00dc0533b3721a7eeb40e8419e70799d2b0a0f2c1d80693165f7cec4ad75

DigiCert TLS RSA4096 Root G5

b085d70b964f191a73e4af0d54ae7a0e07aafdaf9b71dd0862138ab7325a24a2

GlobalSign ECC Root CA - R4

d947432abde7b7fa90fc2e6b59101b1280e0e1c7e4e40fa3c6887fff57a7f4cf

GTS Root R1

8d25cd97229dbf70356bda4eb3cc734031e24cf00fafcfd32dc76eb5841c7ea8

GTS Root R2

34d8a73ee208d9bcdb0d956520934b4e40e69482596e8b6f73c8426b010a6f48

GTS Root R3

349dfa4058c5e263123b398ae795573c4e1313c83fe68f93556cd5e8031b3c7d

GTS Root R4

96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6

ISRG Root X1

69729b8e15a86efc177a57afb7171dfc64add28c2fca8cf1507e34453ccb1470

ISRG Root X2

22d9599234d60f1d4bc7c7e96f43fa555b07301fd475175089dafb8c25e477b3

Sectigo Public Email Protection Root E46

d5917a7791eb7cf20a2e57eb98284a67b28a57e89182da53d546678c9fde2b4f

Sectigo Public Email Protection Root R46

c90f26f0fb1b4018b22227519b5ca2b53e2ca5b3be5cf18efe1bef47380c5383

Sectigo Public Server Authentication Root E46

7bb647a62aeeac88bf257aa522d01ffea395e0ab45c73f93f65654ec38f25a06

Sectigo Public Server Authentication Root R46

e44ddb7952261f15005cd60c1d0c38c18cbfd17c273a31f8ed4c8f53e2685f32

Sectigo Public Time Stamping Root E46

4941b001b8a97e961b7817c9d9e960ec4b056bfc915a8c1aabf6ef6b3ac046a5

Sectigo Public Time Stamping Root R46

e74fbda55bd564c473a36b441aa799c8a68e077440e8288b9fa1e50e4bbaca11

Security Communication ECC RootCA1

ad7dd58d03aedb22a30b5084394920ce12230c2d8017ad9b81ab04079bdd026b

SSL.com Client ECC Root CA 2022

1d4ca4a2ab21d0093659804fc0eb2175a617279b56a2475245c9517afeb59153

SSL.com Client RSA Root CA 2022

c32ffd9f46f936d16c3673990959434b9ad60aafbb9e7cf33654f144cc1ba143

SSL.com TLS ECC Root CA 2022

8faf7d2e2cb4709bb8e0b33666bf75a5dd45b5de480f8ea8d4bfe6bebc17f2ed

SSL.com TLS RSA Root CA 2022

Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsement. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Contact the vendor for additional information.

Published Date: