The final post here - https://developer.apple.com/forums/thread/96570 mentions:
For my case, I think I have come to the point where I can conclude that the certificate for the server must be signed with a root CA that is provided with iOS. If you have a certificate signed with a user-installed (or mdm-installed) root CA, then the SecTrustResult is "proceed" instead of "unspecified", which is OK for Safari and other URLSession uses but not for the apple-app-site-association validation... Which seems like something perhaps related? Or am I clutching at straws?
Topic:
App & System Services
SubTopic:
General
Tags: