iOS App Distribution

Sep 5 2023 · Swift 5.9, macOS Ventura 13.4, Xcode 15 Beta

Part 1: Preparing for Distribution

03. Understanding the Trust Chain

Episode complete

Play next episode

Next
About this episode
Leave a rating/review
See forum comments
Cinema mode Mark complete Download course materials
Previous episode: 02. Joining the Apple Developer Program Next episode: 04. The Developer Portal & App Store Connect

Get immediate access to this and 4,000+ other videos and books.

Take your career further with a Kodeco Personal Plan. With unlimited access to over 40+ books and 4,000+ professional videos in a single subscription, it's simply the best investment you can make in your development career.

Learn more Already a subscriber? Sign in.

Transcript: 03. Understanding the Trust Chain

You’ve completed the first step in getting your app on the App Store - becoming a member of the Apple Developer Program.

The next step is to establish a trust chain with Apple. What does that mean?

In order for your app to interact with certain operations, such as push notifications, or getting locations while the app is in the background, the OS must trust your app.

This means your app must be properly signed.

To become properly signed, your app must have a code-signed provisioning profile.

Let’s dive a bit into what you need to make such a profile.

First, your app needs to respond to the question “Who are you?”.

Your app’s answers to this question can be found in the Signing and Capabilities section of your app’s target.

The bundle name and Team ID sections of this screen uniquely identify your app in the App Store ecosystem.

Your team ID is associated with your developer program account, and the bundle name, or App ID, you enter here will match the App Store Connect record App ID.

You’ll learn about App Store Connect later in the course.

Next, you need to answer what you want to do. This isn’t always something that is set, but can include things like access to HealthKit, HomeKit, or CarPlay.

As you enable capabilities under the Signing and Capabilities pane, Xcode will update your entitlements file, so the OS knows exactly what you are trying to do with your app.

Finally, and most importantly, you need to answer the question “Can I trust you?”.

A certificate is generated by Xcode, or can be created in the developer portal, which contains a public key that Apple can use to verify that the signature was created with the corresponding private key.

These 3 items, when combined, form a provisioning profile. Depending on where your app will go, different provisioning profiles will be generated.

Developer provisioning profiles are used when deploying to your local device, and distribution profiles are used when deploying to the App Store, for example.

As mentioned earlier, all of the components of the profiles can be made by Xcode.

With these in hand, Xcode can automatically generate a provisioning profile if automatic signing is enabled in your app target’s Signing and Capabilities tab.

If automatic signing is disabled, you’ll have to set a few things manually. This means you will have to upload a certificate for proper signing to the developer portal. This can be done by going to Xcode -> Settings -> Accounts, selecting your team, and choosing “Manage Certificates”. The plus button in the lower left corner will let you add the certificates of your choosing.

In addition you’ll have to create a provisioning profile on the developer portal and download it to your system. You’ll get to try that out later in the course when you learn about Ad Hoc Distribution.

OK, so you’ve got your trust chain in place, which means you are all set from your side once the app is ready to go. Before we can upload it to the App Store, we need to get some information in place on the server side, which we’ll get into in the next episode.