A certificate issued by a private Certification Authority (CA) is not trusted on an iOS device, despite appearing valid on Windows systems.
Users may receive certificate trust warnings when accessing websites, services, or applications that use certificates issued by the private CA.
This issue can occur for one of the following reasons:
If iOS encounters a critical extension that it cannot parse, the certificate will not be trusted even if the Root CA certificate has been installed correctly.
Install and trust the Root CA certificate on the iOS device.
If the certificate is still not trusted after installing and trusting the Root CA certificate, inspect the end-entity certificate on the iOS device.
This issue was verified on iOS 13.1.3 (iPhone 8).
iOS requires explicit trust of privately issued Root CA certificates. Installing the certificate alone is not sufficient; full trust must also be enabled through the Certificate Trust Settings menu.
When troubleshooting trust issues, examine certificate extensions carefully. An otherwise valid certificate may be rejected if iOS encounters a critical extension that it cannot interpret. In this particular case, the extension was
Date Created: Saturday, 26 October 2019, 6:32 PM