What to open on the firewall so Monopam can manage Apple signing certificates, App IDs and provisioning profiles, and what the build Mac needs if signing and notarization also run there.
All traffic below is outbound. Nothing at Apple connects in to Monopam, and no inbound rule is needed for this feature.
1. Monopam to Apple
Which host to open depends on the Apple program the API key belongs to. The two are separate APIs and a key works with only one of them.
|
From |
To |
Port |
When |
|---|---|---|---|
|
Monopam application server |
|
TCP 443 |
Standard account (App Store Connect API) |
|
Monopam application server |
|
TCP 443 |
Apple Developer Enterprise Program account |
One of those is the only Apple endpoint Monopam itself calls: certificates, App IDs, devices and provisioning profiles all go through it. Open both only if you manage accounts of both kinds.
-
The gateway is not involved: the call leaves the Monopam application server directly.
-
Authentication is a token Monopam signs with the API key (
.p8) held in its vault. There is no Apple ID sign-in and no password, so no traffic toappleid.apple.com. -
Monopam does not perform OCSP or CRL revocation lookups, so it generates no traffic to
ocsp.apple.comorcrl.apple.com. -
Apple judges the signed token against its own clock, so the Monopam server needs working time synchronisation. A server more than a minute out gets every call refused with a "bad token" error.
Verify from the Monopam server:
curl -o /dev/null -w "%{http_code}\n" https://api.appstoreconnect.apple.com/v1/certificates
curl -o /dev/null -w "%{http_code}\n" https://api.enterprise.developer.apple.com/v1/certificates
401 means the path is open (the call is unauthenticated on purpose). A timeout, 000, or a proxy error page means the rule is missing or a proxy is in the way.
2. Monopam to the Mac that receives the identity
|
From |
To |
Port |
What it is for |
|---|---|---|---|
|
Monopam gateway |
The build Mac |
TCP 22 (SSH) |
Installs the signing identity into the login keychain ( |
Internal traffic only. The gateway opens the connection; the Mac never dials out to Monopam. The SSH account needs permission to run the security commands against the target keychain.
3. The Mac's own Apple access
This is not Monopam traffic. It applies only when the same Mac also builds, signs or notarizes, and it comes from Apple's own list in Use Apple products on enterprise networks.
|
Host |
Port |
What it is for |
|---|---|---|
|
|
TCP 80, 443 |
Certificate validation |
|
|
TCP 80 |
Certificate validation |
|
|
TCP 443 |
Certificate validation |
|
|
TCP 80 |
Certificate validation |
|
|
TCP 443 |
Certificate validation |
|
|
TCP 80 |
Certificate validation (Apple's CA chain) |
|
|
TCP 443 |
App notarization |
|
|
TCP 80, 443 |
Xcode and developer tool downloads |
If notarization still fails with a network error after these are open, take the hostname out of the notarytool log and add it: Apple's list is generic for enterprise networks, not a build-machine specification.
4. Proxies and IP allowlists
-
Allow by hostname, not by IP. Apple publishes these services as hostnames and the addresses behind them change; an IP allowlist will break without warning.
-
TLS inspection. If the proxy re-signs traffic to the Apple API host, the Monopam server has to trust the proxy's CA or the call fails with a TLS error. Exempting the Apple hosts from inspection is the simpler arrangement.
-
Explicit proxy. If the Monopam server reaches the internet through a proxy, that proxy must be configured for the server process itself; Monopam has no separate proxy setting for Apple.
5. Minimum set
For certificate, App ID and provisioning-profile management through Monopam, one rule is enough:
-
Monopam application server →
api.appstoreconnect.apple.com: TCP 443 (standard account) -
Monopam application server →
api.enterprise.developer.apple.com: TCP 443 (Enterprise Program account)
Everything in section 2 is internal, and everything in section 3 belongs to the build machine rather than to Monopam.
Related: Certificates on Apple Developer