Signing the network extensionΒΆ

To publish a macOS application with network extensions, it is necessary to notarize and sign it using a corporate Apple Developer account with the Network Extension capability enabled for the application: https://developer.apple.com/documentation/bundleresources/entitlements/com.apple.developer.networking.networkextension

To add this entitlement perform the following steps:

  • In the Certificates, Identifiers and Profiles section of the developer site, enable the Network Extension capability for the Developer ID-signed app and for the extension. Generate new provisioning profiles and download them.

  • On your Mac, import the downloaded provisioning profiles in the Xcode project settings for the top-level application and for the AppProxy extension.

  • To allow Direct Distribution to end users, modify the text in *.entitlements files in the com.apple.developer.networking.networkextension key. It is necessary to replace app-proxy-provider with app-proxy-provider-systemextension, which is required for publishing manually signed network extensions: https://developer.apple.com/forums/thread/737894

Then it is possible to build the Archive configuration in Xcode and notarize the result, to allow publishing the extension application for Direct Distribution or the App Store.

For testing and debugging on test machines, automatic signing in Xcode can be used with a corporate Apple Developer account, without the notarization step of uploading the archive to Apple.