openssl / openssl/openssl

App Store Connect reports "ITMS-91061: Missing privacy manifest" for OpenSSL.xcframework

Open
#29,072 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

help wanted triaged: bug triaged: feature
Dominant language
C
Stars
30.8k
Forks
11.5k
Avg merge
10m
Merged PRs (30d)
1

Description

When submitting an app to TestFlight / App Store Connect that embeds OpenSSL.xcframework, Apple rejects the binary with the following warning:

ITMS-91061: Missing privacy manifest – Your app includes
"Frameworks/OpenSSL.framework/OpenSSL", which includes BoringSSL / openssl_grpc,
an SDK that was identified in the documentation as a commonly used third-party SDK.
If a new app includes a commonly used third-party SDK, the SDK must include a privacy manifest file.

I have confirmed that:

  • The project embeds OpenSSL.xcframework correctly under Frameworks, Libraries & Embedded Content (Embed & Sign).
  • The xcframework builds successfully for ios-arm64 and ios-arm64_x86_64-simulator.
  • A valid PrivacyInfo.xcprivacy file exists at the root of the xcframework.
  • A placeholder signature.json is also present at the root.
  • The issue persists even after a clean build, re-archive, and re-upload.
Environment

Item: Details
OpenSSL build: OpenSSL.xcframework (3.x branch)
Distribution: App Store Connect → TestFlight
Xcode version: 16.4 (Build 16F6)
macOS version: macOS Sonoma
Target SDK: iOS 17+
Error from Apple: ITMS-91061: Missing privacy manifest
Framework embed method: Dynamic XCFramework (Embed & Sign)
Attempted fixes: Added custom PrivacyInfo.xcprivacy and signature.json — no effect

Expected Behavior
The xcframework should include an official PrivacyInfo.xcprivacy and signature.json so developers can distribute apps using OpenSSL without App Store rejection.

Suggested Resolution

Please:

Add a default PrivacyInfo.xcprivacy (indicating no user data collection).

Provide a valid Apple-signed signature.json generated with Xcode 15.3+ using xcodebuild -sign-xcframework.

Publish the updated OpenSSL.xcframework (and/or OpenSSL-Universal CocoaPod) containing both files.

Reference

Apple’s third-party SDK requirements:
🔗 https://developer.apple.com/support/third-party-SDK-requirements/

🔗 https://developer.apple.com/documentation/bundleresources/adding-a-privacy-manifest-to-your-app-or-third-party-sdk

Reporter
Name: Fiaz Hussain
SDK: CognetIdentityKit (uses OpenSSL internally)
Contact: fiazhussaiin623@gmail.com

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by inspecting the OpenSSL.xcframework packaging for its ios-arm64 and ios-arm64_x86_64-simulator variants, including PrivacyInfo.xcprivacy and signature.json. Review the xcodebuild -sign-xcframework requirement and Apple’s third-party SDK documentation; done means the published framework contains the required files and no longer triggers ITMS-91061 in App Store Connect.

Written by the indexing model from the issue text.

Assessment

Tech stack
c, ios
Domain
cryptography, mobile-dev, release
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.