A React Native parking app needs an urgent iOS hotfix, but archiving fails because the App Store provisioning profile expired; what do you check and fix?
answer
- live users are not affected
- profile vs certificate: which expired
- regenerate the profile, keep the App ID
- new certificate means new profile
- track expiry dates before they bite
basics
~20 sAn expired profile blocks new builds, not the app already on the App Store. Check whether only the profile expired or the distribution certificate too; regenerate the profile (or a new certificate first), install it, archive and upload.
solid answer
~40 sFirst, contain the panic: an expired profile or distribution certificate stops you **signing new builds**; the version already on the App Store keeps working for users. Then establish **what** expired. If only the **App Store provisioning profile** did, regenerate it for the same App ID in the developer account, or let automatic signing do it, download it and archive again. If the **distribution certificate** expired too, create a new one first (a new key pair whose private key lands in this Mac's keychain), then a profile that includes it, because a profile only accepts the certificates it lists. Confirm the new profile still carries every entitlement the app uses, such as push. Bump the build number, archive with **Any iOS Device (arm64)**, upload, and afterwards put signing expiry dates on the team's calendar.
go deeper
Know that profiles and certificates expire, that expiry blocks new builds rather than the live app, and that regenerating the profile is the usual fix.
Explain why a new certificate forces a new profile, why the private key must be on the archiving Mac, and why entitlements must be checked on the regenerated profile.
Run the incident calmly: identify what expired, regenerate in the right order, fix every build machine, ship the hotfix and put expiry tracking in place.
Own signing as an operational process with expiry monitoring, key backup and a rehearsed release path, so no hotfix waits on an avoidable signing failure.
## What an expired profile does, and does not, break Apple signing assets have **expiry dates**. When an **App Store provisioning profile** expires, Xcode can no longer use it to sign a new archive, so the hotfix is blocked. What it does **not** do is break the app your users already have: builds distributed through the App Store keep running. That matters for the incident call, because the urgency is the hotfix, not an outage caused by the expiry. ## Step 1: find out exactly what expired | What expired | What still works | What you must create | |---|---|---| | Profile only | The distribution certificate and its private key | A new App Store profile for the same App ID | | Certificate (and so the profile) | Nothing for new signing | A new certificate, then a new profile listing it | | Neither, but the profile is "invalid" | Depends on the cause | Usually a profile regenerated after a change | Check in the Apple Developer account's Certificates, Identifiers & Profiles pages and in Xcode's signing section for the target, which shows the profile, its certificate and any error. ## Step 2: regenerate the missing pieces 1. **If the certificate expired**, create a new distribution certificate. The new key pair's **private key** is created on the Mac that generates the request, so do it on the release machine, or export the key securely afterwards. 2. **Create or regenerate the App Store profile** for the parking app's existing App ID, selecting the current certificate. Keep the same bundle identifier; a new one would be a different app. 3. **Check the entitlements.** If the app uses push reminders or associated domains, the profile must include them. A profile regenerated without a capability produces a different signing failure. 4. **Install it** by downloading it, or let **Automatically manage signing** fetch it; with manual signing, select the new profile for the Release configuration. ## Step 3: ship the hotfix - **Bump the build number** (`CURRENT_PROJECT_VERSION`), and the short version if this is a new user-facing release. - Select **Any iOS Device (arm64)**, run **Product > Archive**, then **Distribute App > App Store Connect > Upload**. - Remember the JavaScript fix is inside `main.jsbundle`; if the fix is JS-only and the app already has an over-the-air update path, that may be faster, but it is a separate release mechanism with its own rules. ## A timeline for the incident call 1. **Minute zero:** state that live users are unaffected and that the blocker is signing new builds. 2. **Diagnosis:** read Xcode's signing error, then confirm in the developer account whether the profile, the certificate or both expired. 3. **Repair:** regenerate in dependency order, certificate first when needed, then the profile, then install on every archiving machine. 4. **Ship:** bump the build number, archive, upload and continue with the normal review path. 5. **Follow-up:** record the new expiry dates and who owns renewal. ## What not to do - **Do not revoke a certificate in a panic.** Revoking is for a compromised key; an expired certificate simply stops being usable. - **Do not create a new App ID** to get a fresh profile; that makes a new app that existing users would never receive. - **Do not sign the hotfix with a development profile**; it cannot be uploaded for App Store distribution. - **Do not assume the CI machine is fixed** because your laptop is; every machine that archives needs the new profile and the certificate's private key. ## Prevention For a team that ships a parking app on a regular cadence: - Record the expiry dates of the distribution certificate and each App Store profile, and renew well ahead of them. - Keep the distribution private key backed up, so a new machine or a new teammate can sign. - Decide deliberately between automatic signing, which refreshes profiles for you, and manual signing, which needs someone to own renewals. - Rehearse a release build shortly before any planned hotfix window, so expiry surprises happen on a quiet day. ## What interviewers listen for A strong answer says immediately that users are unaffected, distinguishes profile expiry from certificate expiry, knows that a new certificate forces a new profile, remembers entitlements, and ends with tracking expiry dates rather than heroics.
- If a React Native team creates a new iOS distribution certificate, why must the App Store profile be regenerated too?A provisioning profile lists the exact certificates allowed to sign the app. A new certificate is not in the old profile's list, so Xcode cannot pair them. Regenerate the App Store profile for the same App ID, selecting the new certificate, and install it on every machine that archives.
- When is revoking an iOS distribution certificate the right move for a React Native team, rather than letting it expire?When its private key may be compromised, for example a leaked export or a lost unencrypted backup, because anyone with the key could sign builds as the team. Revoking invalidates profiles that list it, so plan to create a new certificate and regenerate profiles immediately afterwards.
saying these in an interview costs you the question
- An expired App Store profile makes the live app stop launching for users.
- Creating a new App ID is the fastest way to get a working profile.
- A new distribution certificate works with the old profile unchanged.
- Revoking the certificate is the standard fix for an expired profile.
- Fixing signing on one laptop fixes it for every build machine.