Skip to content

Glossary

Designated requirement

The code requirement that identifies a signed program, printed by codesign -d -r-; compare it with the csreq stored in TCC.db.

A designated requirement is the code requirement that describes "this program" for code-signing checks: typically its identifier plus the certificate chain it must be signed with, for example an Apple anchor or a Developer ID Team ID. codesign -d -r- /path/to/App.app prints it.

In TCC work, compare the binary's designated requirement with the csreq stored in the row. If they do not match, the file on disk may not be the build that was approved. See decoding csreq code requirements.