Apple code signing: network requirements

What to open on the firewall so Monopam can manage Apple signing certificates, App IDs and provisioning profiles, and what the build Mac needs if signing and notarization also run there.

All traffic below is outbound. Nothing at Apple connects in to Monopam, and no inbound rule is needed for this feature.

1. Monopam to Apple

Which host to open depends on the Apple program the API key belongs to. The two are separate APIs and a key works with only one of them.

From

To

Port

When

Monopam application server

api.appstoreconnect.apple.com

TCP 443

Standard account (App Store Connect API)

Monopam application server

api.enterprise.developer.apple.com

TCP 443

Apple Developer Enterprise Program account

One of those is the only Apple endpoint Monopam itself calls: certificates, App IDs, devices and provisioning profiles all go through it. Open both only if you manage accounts of both kinds.

  • The gateway is not involved: the call leaves the Monopam application server directly.

  • Authentication is a token Monopam signs with the API key (.p8) held in its vault. There is no Apple ID sign-in and no password, so no traffic to appleid.apple.com.

  • Monopam does not perform OCSP or CRL revocation lookups, so it generates no traffic to ocsp.apple.com or crl.apple.com.

  • Apple judges the signed token against its own clock, so the Monopam server needs working time synchronisation. A server more than a minute out gets every call refused with a "bad token" error.

Verify from the Monopam server:

curl -o /dev/null -w "%{http_code}\n" https://api.appstoreconnect.apple.com/v1/certificates
curl -o /dev/null -w "%{http_code}\n" https://api.enterprise.developer.apple.com/v1/certificates

401 means the path is open (the call is unauthenticated on purpose). A timeout, 000, or a proxy error page means the rule is missing or a proxy is in the way.

2. Monopam to the Mac that receives the identity

From

To

Port

What it is for

Monopam gateway

The build Mac

TCP 22 (SSH)

Installs the signing identity into the login keychain (security import plus set-key-partition-list) so CI can sign without a prompt

Internal traffic only. The gateway opens the connection; the Mac never dials out to Monopam. The SSH account needs permission to run the security commands against the target keychain.

3. The Mac's own Apple access

This is not Monopam traffic. It applies only when the same Mac also builds, signs or notarizes, and it comes from Apple's own list in Use Apple products on enterprise networks.

Host

Port

What it is for

certs.apple.com

TCP 80, 443

Certificate validation

ocsp.apple.com

TCP 80

Certificate validation

ocsp2.apple.com

TCP 443

Certificate validation

crl.apple.com

TCP 80

Certificate validation

valid.apple.com

TCP 443

Certificate validation

ocsp.digicert.com, crl3.digicert.com, crl4.digicert.com

TCP 80

Certificate validation (Apple's CA chain)

api.apple-cloudkit.com

TCP 443

App notarization

devimages-cdn.apple.com, download.developer.apple.com

TCP 80, 443

Xcode and developer tool downloads

If notarization still fails with a network error after these are open, take the hostname out of the notarytool log and add it: Apple's list is generic for enterprise networks, not a build-machine specification.

4. Proxies and IP allowlists

  • Allow by hostname, not by IP. Apple publishes these services as hostnames and the addresses behind them change; an IP allowlist will break without warning.

  • TLS inspection. If the proxy re-signs traffic to the Apple API host, the Monopam server has to trust the proxy's CA or the call fails with a TLS error. Exempting the Apple hosts from inspection is the simpler arrangement.

  • Explicit proxy. If the Monopam server reaches the internet through a proxy, that proxy must be configured for the server process itself; Monopam has no separate proxy setting for Apple.

5. Minimum set

For certificate, App ID and provisioning-profile management through Monopam, one rule is enough:

  • Monopam application server → api.appstoreconnect.apple.com : TCP 443 (standard account)

  • Monopam application server → api.enterprise.developer.apple.com : TCP 443 (Enterprise Program account)

Everything in section 2 is internal, and everything in section 3 belongs to the build machine rather than to Monopam.


Related: Certificates on Apple Developer