Urgent.News

What's breaking now, across thousands of outlets.

Tech

How to Solve ITMS-90035 Error: From Signature Chain Troubleshooting to IPA Regeneration

When uploading to the App Store, ITMS-90035 is a typical signing error. Many people first assume the IPA is corrupted, but in reality, this error is more related to certificates, provisioning profiles, signing methods, and export methods. Especially in scenarios like Flutter, uni-app, React Native, HBuilderX, and Jenkins automated builds, this error is more likely to occur. What is ITMS-90035 The…

Abstract editorial illustration

ITMS-90035 is a common signing error that occurs when uploading an IPA to the App Store. This error is often mistakenly attributed to a corrupted IPA, but it is primarily caused by issues with certificates, provisioning profiles, signing methods, and export methods. This error is particularly prevalent in scenarios involving Flutter, uni-app, React Native, HBuilderX, and Jenkins automated builds.

According to Apple, the upload failed due to an invalid signature. To resolve this issue, it is essential to examine the stage of the error. The error can occur during the Xcode archive process, failure to install the IPA, or rejection by Apple after uploading. The most frequent issue is a certificate type mismatch, typically arising when a Development certificate is used for App Store distribution.

Another common problem is a mismatch between the provisioning profile and certificate. To check the provisioning profile, open the .mobileprovision file and verify the name, team identifier, team entitlements, permissions, provisioned devices, and whether it is a test version or enterprise version. A less obvious issue is the inconsistency between the App ID in the profile and the actual Bundle ID used for packaging.

In scenarios involving uni-app on HBuilderX, it is common to encounter issues where the app identifier in the profile file does not match the package name, often due to inconsistencies between manifest.json, Bundle ID, and mobileprovision. A more efficient way to resolve these issues is to regenerate the entire signing chain, including the Bundle ID, certificate, and provisioning profile.

In the Windows environment, this can be accomplished using AppUploader, which allows for the management of Bundle IDs, creation of Distribution certificates, generation of App Store provisioning profiles, and uploading of IPAs without the need for Xcode or Keychain. To regenerate the signing chain, first confirm the Bundle ID, such as com.company.app, ensuring that the Apple developer portal, packaging configuration, and Profile are all consistent.

Next, recreate the Distribution certificate, avoiding the use of the old Development certificate. Afterward, recreate the App Store Profile, ensuring that the Distribution type is selected. Finally, re-export the IPA using Xcode, specifying App Store Connect and avoiding the Ad Hoc option. In CI environments such as Jenkins or Fastlane, issues often arise due to the presence of a certificate but the absence of the private key, which manifests as successful local uploads but failures during Jenkins uploads.

To address this, verify whether the IPA is actually signed correctly. This can be done by unzipping the IPA using the command: unzip app.ipa, followed by checking the Payload/App.app for the presence of _CodeSignature and embedded.mobileprovision files. Additionally, recent updates from Apple highlight stricter regulations regarding legacy upload protocols.

If encountering a "Deprecated Transporter usage" error, it is crucial to upgrade the upload tool or utilize a new upload channel. The command line interface (CLI) upload provides more comprehensive logs for metadata, transporter, signing, and upload session, making it easier to diagnose issues. For instance, using the appuploader_cli command with appropriate parameters can yield detailed error messages.

Ultimately, ITMS-90035 essentially indicates that Apple is verifying the legitimacy and completeness of the IPA's signature. Instead of focusing on the "upload button," troubleshooting should concentrate on ensuring the consistency of the certificate, provisioning profile, Bundle ID, and export method.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Monday 3 August →