This is fantastic help, many thanks Mr Eskimo. We actually met once long long ago, your wisdom is much appreciated.
Now having done all of that this is what I found:
the original profile has 2 certs, and the emitted binary has been signed with the second one of those. In that other thread under "Check the Signing Certificate" there is mention of "the first certificate is the one that matters" - why?
Going back to the original error, it says that the profile included in the bundle is missing the code-signing certificate. Extracting and dumping the signature and dates of all 19 of those shows that the certifcate used for signing is in there, and is not expired.
Seems to me the error is kind of misleading and something else must be amiss, any ideas?
Topic:
Code Signing
SubTopic:
Certificates, Identifiers & Profiles