Every App Store Connect upload I sign with my Cloud Managed Apple Distribution certificate is rejected with ITMS-90035 ("Code failed to satisfy specified code requirement(s)") for the app binary and its widget extension. It happens from Xcode Cloud and from a manual Organizer upload alike. I think I have found the cause, and it looks like a Unicode normalization bug in cloud-managed signing.
The certificate holder's name contains an umlaut: "Apple Distribution: Jonathan Thorsten Müller (…)". In the certificate the "ü" is precomposed (NFC, UTF-8 c3 bc). In the designated requirement that the export writes into the signature it is decomposed (NFD, "u" + U+0308, UTF-8 75 cc 88):
certificate subject CN ... 4d c3 bc 6c 6c 65 72 ... ("Müller", NFC)
designated requirement leaf CN ... 4d 75 cc 88 6c 6c 65 72 ... ("Müller", NFD)
The bytes differ, so the signature can never satisfy its own designated requirement.
It reproduces with Xcode 27.0's App template, unmodified, and without uploading anything:
Archive for a generic iOS device.
With no distribution identity in the local keychain, export for App Store Connect to a folder (export options: method app-store-connect, destination export, signingStyle automatic). DistributionSummary.plist shows "Cloud Managed Apple Distribution".
xcodebuild -exportArchive -archivePath MyApp.xcarchive -exportPath out -exportOptionsPlist ExportOptions.plist -allowProvisioningUpdates
Verify the exported app:
codesign --verify --strict -vv Payload/MyApp.app
Result: "valid on disk", then "does not satisfy its designated Requirement".
Compare the requirement with the certificate's subject:
codesign -d -r- Payload/MyApp.app
codesign -d --extract-certificates Payload/MyApp.app
openssl x509 -inform DER -in codesign0 -noout -subject -nameopt RFC2253,-esc_msb | xxd
The same archive exported with a regular Apple Distribution certificate (same name, private key in my keychain) writes the NFC form, verifies, and App Store Connect accepts that upload. That works for manual uploads only. Xcode Cloud always signs with the cloud-managed certificate, so I cannot distribute from Xcode Cloud at all.
Setup: Xcode 27.0 (27A266a) locally and in Xcode Cloud, automatic signing, one team, no custom code-signing flags. Product name, bundle IDs and file names are plain ASCII.
Questions:
Is this a known issue with cloud-managed signing and non-ASCII certificate names?
Is there a supported way to have Xcode Cloud sign without hitting it in the meantime?
If you see ITMS-90035 on Xcode Cloud and your name (or your team's) has an accent or umlaut in it, you may be hitting the same thing: run step 3 on an exported IPA and check.
Topic:
Code Signing
SubTopic:
Certificates, Identifiers & Profiles
Tags:
Xcode Cloud
App Store Connect
Code Signing
Signing Certificates
2
0
46