Apple Drops Support for SHA-1 Certificates in macOS Catalina and iOS 13 - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Apple Drops Support for SHA-1 Certificates in macOS Catalina and iOS 13

In a new support document, Apple has indicated that macOS Catalina and iOS 13 drop support for TLS certificates signed with the SHA-1 hash algorithm, which is now considered to be insecure. SHA-2 is now required at a minimum.

macos catalina safari
Apple says all TLS server certificates must comply with these new security requirements in macOS Catalina and iOS 13:

  • TLS server certificates and issuing CAs using RSA keys must use key sizes greater than or equal to 2048 bits. Certificates using RSA key sizes smaller than 2048 bits are no longer trusted for TLS.

  • TLS server certificates and issuing CAs must use a hash algorithm from the SHA-2 family in the signature algorithm. SHA-1 signed certificates are no longer trusted for TLS.

  • TLS server certificates must present the DNS name of the server in the Subject Alternative Name extension of the certificate. DNS names in the CommonName of a certificate are no longer trusted.

Effective immediately, any connections to TLS servers violating these new requirements will fail and may cause network failures, apps to fail, and websites to not load in Safari in macOS Catalina and iOS 13, according to Apple.

Google, Microsoft, and Mozilla all deprecated SHA-1 certificates in 2017.

Tags: Safari, SHA-1
Related Forums: iOS 13, macOS Catalina

Popular Stories

iOS 27 on iPhone 17 1

iOS 27 Will Add These New Features to Your iPhone

Saturday May 2, 2026 8:43 am PDT by
Apple is expected to unveil iOS 27 during its WWDC 2026 keynote on June 8, and there are already many rumored features and changes for iPhones. The first developer beta of iOS 27 will likely be available immediately following the keynote, and a public beta typically follows in July. Following beta testing, the software update should be released to all users with a compatible iPhone in...
Apple Event Logo

Apple Just Released a New Accessory

Monday May 4, 2026 8:13 am PDT by
Apple today released a new Pride Edition Sport Loop for the Apple Watch. The band features a rainbow design with 11 colors of woven nylon yarns. The new Pride Edition Sport Loop is available to order now on Apple.com and in the Apple Store app in 40mm, 42mm, and 46mm sizes, and it will be available at Apple Store locations starting later this week. In the U.S., the band costs $49. There...
Apple Announces 2026 Pride Band Watch Face and iPhone Wallpaper Article 2

iOS 26.5 Coming Soon With These New Features

Monday May 4, 2026 8:40 am PDT by
iOS 26.5 is expected to be released next week, following more than a month of beta testing. The update is relatively minor, but there are a couple of new features and changes across the operating system that we have recapped below. iOS 26.5 lays the groundwork for end-to-end encryption for RCS in the Messages app and ads in the Apple Maps app, and it will include a new Pride wallpaper and a...

Top Rated Comments

90 months ago
Nice to see them doing this.

Planned obsolescence...smh...
For an insecure encryption algorithm? I would hope they'd deprecate it (following Google, Firefox etc.).
Score: 17 Votes (Like | Disagree)
keysofanxiety Avatar
90 months ago
Planned obsolescence...smh...
I know, it's a disgrace. Little known fact: very few websites work well on Netscape Navigator either :mad:
Score: 5 Votes (Like | Disagree)
SteveOfTheStow Avatar
90 months ago
For an insecure encryption algorithm? I would hope they'd deprecate it (following Google, Firefox etc.).
There was an implicit /s in vicviper789's post ;)
Score: 5 Votes (Like | Disagree)
90 months ago
There was an implicit /s in vicviper789's post ;)
It’s impossible to tell if someone is being sincere or sarcastic on the internet; which is why we have ‘/s’.
Score: 4 Votes (Like | Disagree)
Soba Avatar
90 months ago
Planned obsolescence...smh...
I get your point and share the frustration, but it's not warranted in this case.

Encryption algorithms have shelf lives, more or less. Weaknesses are periodically discovered that make them vulnerable to cracking or workarounds, as in this case. Generally these problems cannot be fixed in the way ordinary software is patched because the problems are not specific to any vendor and are simply fundamental flaws in the encryption mechanism; the only solution is abandonment of the encryption method and moving on to safer methods.

SHA-1 is over 25 years old and has been known to have problems since at least 2005. Deprecating encryption methods that are known to be too weak or vulnerable is the right thing to do, and if anything, this move is long overdue.
[doublepost=1559832487][/doublepost]
I know, it's a disgrace. Little known fact: very few websites work well on Netscape Navigator either :mad:
I miss Netscape. ;)

I have to laugh at the 40-bit encryption we used in the late 90s (32-bit in some parts of the world). It wasn't thought overly safe even at the time, but that seems just silly, today.
Score: 4 Votes (Like | Disagree)
90 months ago
I miss Netscape. ;)

I have to laugh at the 40-bit encryption we used in the late 90s (32-bit in some parts of the world). It wasn't thought overly safe even at the time, but that seems just silly, today.
Remember when encryption-enabled Netscape was considered a "munition", and was barred from export from the US, so they had a plaintext-only version for the rest of the world?
Score: 2 Votes (Like | Disagree)
Related Apple News: Ipad | South Africa | News | Mac | Politics