# Invalid Signature from Itunes Connect Message

**URL:** <https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060>\
**Category:** Questions about Thunkable X\
**Created:** [February 15, 2019, 7:20pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060 "2019-02-15T19:20:01Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![doctorsof](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/doctorsof/32/30099_2.png) [@doctorsof](https://community.thunkable.com/u/doctorsof)\
**Post date:** [February 15, 2019, 7:20pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/1 "2019-02-15T19:20:01Z")

</div>

We identified one or more issues with a recent delivery for your app, “…”. Please correct the following issues, then upload again.

Invalid Signature - A sealed resource is missing or invalid. The file at path [thunkablecompanion.app/thunkablecompanion] is not properly signed. Make sure you have signed your application with a distribution certificate, not an ad hoc certificate or a development certificate. Verify that the code signing settings in Xcode are correct at the target level (which override any values at the project level). Additionally, make sure the bundle you are uploading was built using a Release target in Xcode, not a Simulator target. If you are certain your code signing settings are correct, choose “Clean All” in Xcode, delete the “build” directory in the Finder, and rebuild your release target. For more information, please consult [https://developer.apple.com/library/ios/documentation/Security/Conceptual/CodeSigningGuide/Introduction/Introduction.html](https://developer.apple.com/library/ios/documentation/Security/Conceptual/CodeSigningGuide/Introduction/Introduction.html)

Best regards,

The App Store Team

So what can i do?

---

<div class="post-metadata">

**Author:** ![domhnallohanlon](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/domhnallohanlon/32/29554_2.png) [@domhnallohanlon](https://community.thunkable.com/u/domhnallohanlon)\
**Post date:** [February 15, 2019, 7:26pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/2 "2019-02-15T19:26:22Z")

</div>

You can see the full guide of how to do this in our YouTube tutorial:

---

<div class="post-metadata">

**Author:** ![doctorsof](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/doctorsof/32/30099_2.png) [@doctorsof](https://community.thunkable.com/u/doctorsof)\
**Post date:** [February 15, 2019, 7:42pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/3 "2019-02-15T19:42:00Z")

</div>

Thanks.  
I dont have Two Factor Authentication. So i did before lots of time.  
I mixed why it happened.

---

<div class="post-metadata">

**Author:** ![domhnallohanlon](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/domhnallohanlon/32/29554_2.png) [@domhnallohanlon](https://community.thunkable.com/u/domhnallohanlon)\
**Post date:** [February 15, 2019, 8:39pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/4 "2019-02-15T20:39:17Z")

</div>

Are you using the Thunkable .certSigningRequest file or are you generating your own?

---

<div class="post-metadata">

**Author:** ![doctorsof](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/doctorsof/32/30099_2.png) [@doctorsof](https://community.thunkable.com/u/doctorsof)\
**Post date:** [February 15, 2019, 8:40pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/5 "2019-02-15T20:40:41Z")

</div>

You are right i am using own .certSigningRequest file. But how can i create Thunkable .certSigningRequest file because of i dont have Two Factor Authentication. When i watch this video it seems if i have Two Factor Authentication.

---

<div class="post-metadata">

**Author:** ![doctorsof](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/doctorsof/32/30099_2.png) [@doctorsof](https://community.thunkable.com/u/doctorsof)\
**Post date:** [February 16, 2019, 12:51pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/6 "2019-02-16T12:51:57Z")

</div>

> [@doctorsof](#):
>
> how can i create Thunkable .certSigningRequest file

So how can i create Thunkable .certSigningRequest file without Two Factor Authentication?

## \*Certificates. If you have an existing Apple Developer Program account with 2 iOS certificates, you’ll have to revoke one. Apple only allows developers to have 2 iOS certificates at a time and Thunkable creates one when it publishes to your account.

I also uploaded one app 2 months ago and last month another app uploaded why now this happening?

---

<div class="post-metadata">

**Author:** ![doctorsof](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/doctorsof/32/30099_2.png) [@doctorsof](https://community.thunkable.com/u/doctorsof)\
**Post date:** [February 18, 2019, 8:53pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/7 "2019-02-18T20:53:00Z")

</div>

I want to download Thunkable .certSigningRequest file . Will you share it?

---

<div class="post-metadata">

**Author:** ![doctorsof](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/doctorsof/32/30099_2.png) [@doctorsof](https://community.thunkable.com/u/doctorsof)\
**Post date:** [February 20, 2019, 3:33pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/8 "2019-02-20T15:33:21Z")

</div>

Let me Explain my story about publish.  
**1. Turned off 2FA:** I recieved this mail from Itunes Connect. After than i opened 2FA (You can see Second one)  
We identified one or more issues with a recent delivery for your app, “…”. Please correct the following issues, then upload again.

Invalid Signature - A sealed resource is missing or invalid. The file at path [thunkablecompanion.app/thunkablecompanion] is not properly signed. Make sure you have signed your application with a distribution certificate, not an ad hoc certificate or a development certificate. Verify that the code signing settings in Xcode are correct at the target level (which override any values at the project level). Additionally, make sure the bundle you are uploading was built using a Release target in Xcode, not a Simulator target. If you are certain your code signing settings are correct, choose “Clean All” in Xcode, delete the “build” directory in the Finder, and rebuild your release target. For more information, please consult [https://developer.apple.com/library/ios/documentation/Security/Conceptual/CodeSigningGuide/Introduction/Introduction.html](https://developer.apple.com/library/ios/documentation/Security/Conceptual/CodeSigningGuide/Introduction/Introduction.html)

Best regards,

The App Store Team

**2. Turned on 2FA:**  
I didnt login itunes connect from Thunkable.  
I tried lots of time (another browser,another PC) for login (Ios Publish) it happen anything! Just processing again again again no error no login no second section seeing any different area or page.

Theese are really paradox.  
When i close 2FA i will see 1.Option.When i open 2FA i will see 2.Option.  
So what can i do?  
(I did lots of procedure. Change my apple developer mail, password, clean cache or etc. nothing happen anything.I really mixed!)

 ![1](https://us1.discourse-cdn.com/flex015/uploads/thunkable/original/3X/1/d/1db153c05d26802025ae8569a41e725c2854743b.png)

Nothing happen!

 ![2](https://us1.discourse-cdn.com/flex015/uploads/thunkable/original/3X/6/9/69583f82dd43afeef0b94368014b042b59e90e75.png)

---

<div class="post-metadata">

**Author:** ![doctorsof](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/doctorsof/32/30099_2.png) [@doctorsof](https://community.thunkable.com/u/doctorsof)\
**Post date:** [February 22, 2019, 2:41pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/9 "2019-02-22T14:41:16Z")

</div>

> **[iospublishproblem.mp4](https://yadi.sk/i/w8T5S_AXXF76-A)**
>
> View and download from Yandex.Disk

  
I record video for publish.

---

<div class="post-metadata">

**Author:** ![doctorsof](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/doctorsof/32/30099_2.png) [@doctorsof](https://community.thunkable.com/u/doctorsof)\
**Post date:** [March 7, 2019, 6:46am UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/12 "2019-03-07T06:46:58Z")

</div>

Still same error i opened 2FA but same issue. (Apple require 2FA anymore)

> **[iospublishproblem.mp4](https://yadi.sk/i/w8T5S_AXXF76-A)**
>
> View and download from Yandex.Disk

**I fixed… It has a itunes connect and apple id bug**

---

<div class="post-metadata">

**Author:** ![nstasis](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/nstasis/32/27822_2.png) [@nstasis](https://community.thunkable.com/u/nstasis)\
**Post date:** [April 22, 2019, 2:28pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/13 "2019-04-22T14:28:30Z")

</div>

I’m having the same problem.I followed the steps in the video on how to publish but got the same email from Apple Connect:

Dear Developer,

We identified one or more issues with a recent delivery for your app, “Cross The Bridge Project”. Please correct the following issues, then upload again.

**Invalid Signature** - A sealed resource is missing or invalid. The file at path [thunkablecompanion.app/thunkablecompanion] is not properly signed. Make sure you have signed your application with a distribution certificate, not an ad hoc certificate or a development certificate. Verify that the code signing settings in Xcode are correct at the target level (which override any values at the project level). Additionally, make sure the bundle you are uploading was built using a Release target in Xcode, not a Simulator target. If you are certain your code signing settings are correct, choose “Clean All” in Xcode, delete the “build” directory in the Finder, and rebuild your release target. For more information, please consult [https://developer.apple.com/library/ios/documentation/Security/Conceptual/CodeSigningGuide/Introduction/Introduction.html](https://developer.apple.com/library/ios/documentation/Security/Conceptual/CodeSigningGuide/Introduction/Introduction.html)

Best regards,

The App Store Team

---

<div class="post-metadata">

**Author:** ![Emeros](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/emeros/32/31781_2.png) [@Emeros](https://community.thunkable.com/u/Emeros)\
**Post date:** [April 24, 2019, 7:38am UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/14 "2019-04-24T07:38:01Z")

</div>

Do you need to solve this error? Thunkable never answers me a way to solve this, just programmed answers. I’m running the risk of being sued, I need help with this.

---

<div class="post-metadata">

**Author:** ![doctorsof](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/doctorsof/32/30099_2.png) [@doctorsof](https://community.thunkable.com/u/doctorsof)\
**Post date:** [April 24, 2019, 9:55am UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/15 "2019-04-24T09:55:09Z")

</div>

I solved this issue.  
Turn on 2FA, delete your all certificate. After than you can watch step by step this video.

---

<div class="post-metadata">

**Author:** ![nstasis](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/nstasis/32/27822_2.png) [@nstasis](https://community.thunkable.com/u/nstasis)\
**Post date:** [April 24, 2019, 12:44pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/16 "2019-04-24T12:44:57Z")

</div>

That’s what I did…

---

<div class="post-metadata">

**Author:** ![nstasis](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/nstasis/32/27822_2.png) [@nstasis](https://community.thunkable.com/u/nstasis)\
**Post date:** [April 24, 2019, 2:37pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/17 "2019-04-24T14:37:33Z")

</div>

anyone @thunkable wiling to shed some light on this?

---

<div class="post-metadata">

**Author:** ![domhnallohanlon](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/domhnallohanlon/32/29554_2.png) [@domhnallohanlon](https://community.thunkable.com/u/domhnallohanlon)\
**Post date:** [April 24, 2019, 3:14pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/18 "2019-04-24T15:14:17Z")

</div>

hi @Emeros and @nstasis

Can you both please clarify:

1. Whether you are publishing for the first time or updating an existing app
2. Whether you are using your own .certSigningRequest files or the ones provided by Thunkable
3. Whether you have created a distribution certificate or a development certificate

Thanks!

---

<div class="post-metadata">

**Author:** ![nstasis](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/nstasis/32/27822_2.png) [@nstasis](https://community.thunkable.com/u/nstasis)\
**Post date:** [April 24, 2019, 3:16pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/19 "2019-04-24T15:16:02Z")

</div>

First time publishing  
Thunkable certificate  
distribution certificate

Though now I have deleted all those and attempted to redo it from start

---

<div class="post-metadata">

**Author:** ![domhnallohanlon](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/domhnallohanlon/32/29554_2.png) [@domhnallohanlon](https://community.thunkable.com/u/domhnallohanlon)\
**Post date:** [April 24, 2019, 3:21pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/20 "2019-04-24T15:21:50Z")

</div>

Thanks for clarifying.

Let me know how you get on with you next publication attempt, if it doesn’t work can you PM me your project link?

Thanks

---

<div class="post-metadata">

**Author:** ![Emeros](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/emeros/32/31781_2.png) [@Emeros](https://community.thunkable.com/u/Emeros)\
**Post date:** [April 25, 2019, 10:13pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/21 "2019-04-25T22:13:56Z")

</div>

It is not updating, it is the first.  
CSR by Thunkable.  
Distribution certificate.

I already sent the ID in your chat.

---

<div class="post-metadata">

**Author:** ![nstasis](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/nstasis/32/27822_2.png) [@nstasis](https://community.thunkable.com/u/nstasis)\
**Post date:** [May 1, 2019, 6:26pm UTC](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060/22 "2019-05-01T18:26:38Z")

</div>

So it’s been a week since I resubmitted and I haven’t heard back from Apple at all. i don’t even know if it has actually been submitted by Thunkable following the procedure on the video…

[Next page](https://community.thunkable.com/t/invalid-signature-from-itunes-connect-message/69060.md?page=2)
