Safari integration broken on Big Sur due to expired 1Password signing certificate
I'm using:
- macOS Big Sur 11.7.11
- Safari 16.6.1
- 1Password for Mac 8.10.60
- 1Password for Safari 8.10.60
I know Big Sur is no longer supported by current 1Password releases, and 8.10.62 raised the minimum requirement to macOS Monterey. I'm not asking for new features or ongoing full Big Sur support.
I'm asking whether 1Password could please issue a re-signed maintenance build of the final Big Sur-compatible 1Password for Safari 8.10.60 package, because the Safari integration has now stopped working solely due to an expired signing certificate.
What is failing
The Safari extension displays:
Integration status: Connection problemThe 1Password Browser Helper log reports:
Failed to verify signed with Apple Cert
Connection was not from a process signed by us. Refusing connection.SafariExtensionBindings simultaneously reports the failed XPC connection with errors including:
NSCocoaErrorDomain:4099
BrokenPipe
ConnectionTimeoutChrome and Firefox integration with the same 1Password desktop installation continue to work normally.
The installed 1Password applications also still pass normal on-disk signature verification.
The certificate has expired
I inspected the signing certificate used by the Big Sur-compatible 1Password for Safari build.
Its Apple signing certificate expired on:
2026-08-11 23:16:06 UTCThe certificate used by my 1Password desktop/helper installation is still valid until 2029.
So this appears to be specifically the certificate associated with the old 1Password for Safari / Safari Web Extension component, rather than the desktop application as a whole.
I confirmed that expiry is the cause
As a test, I temporarily changed the Mac's system date to a date before:
2026-08-11 23:16:06 UTCwithout changing the 1Password installation.
Safari immediately connected successfully to the 1Password desktop application again.
Restoring the current date causes the certificate validation problem to return.
So I have been able to reproduce this as:
Current date
↓
Safari extension connects to Browser Helper
↓
1Password validates signing certificate
↓
certificate is expired
↓
Browser Helper refuses connectionbut:
Date before certificate expiry
↓
same 1Password binaries
↓
same Safari version
↓
same XPC connection
↓
certificate validates
↓
integration worksThis seems to rule out Safari preferences, ports, XPC corruption, reinstalling, or a damaged application bundle as the underlying issue.
What I believe needs to be re-signed
Could 1Password please produce a maintenance release based on 8.10.60, signed with a current certificate?
Specifically, the Big Sur-compatible 1Password for Safari package and its embedded Safari Web Extension (.appex) / executable involved in the browser-to-desktop XPC connection need a valid current vendor signature.
If the outer 1Password for Safari.app and its nested extension need to be signed together as part of the normal bundle signing process, then ideally the whole Safari package should simply be rebuilt/re-signed and released as something such as an 8.10.60 maintenance build.
I'm not suggesting users should ad-hoc re-sign it themselves. That wouldn't solve the problem because doing so would replace 1Password's signing identity, and Browser Helper is deliberately checking that the connecting process was signed by 1Password.
This really needs to come from 1Password using the appropriate current signing credentials.
There is precedent for certificate-only maintenance of legacy software
Apple actually did something similar in principle this year.
In 2026 Apple released macOS Big Sur 11.7.11, despite Big Sur otherwise being long out of normal feature support, specifically to extend the certification required for functionality such as iMessage, FaceTime, and device activation to continue working after January 2027.
I realise Apple's update is not technically the same certificate/signing mechanism as this 1Password issue. I'm mentioning it because it demonstrates the broader maintenance principle: older software can receive a very small update whose purpose is simply to renew certificate-dependent functionality rather than add new features or restart normal support.
That seems especially appropriate here because 1Password intentionally left 8.10.60 as the last usable version for Big Sur.
Current versions already received a Safari connection fix
The 1Password 8.12.33 release notes from 12 August 2026 say:
We've fixed an issue where the 1Password browser extension in Safari couldn't connect to the 1Password app.
Issue/reference:
!40819Unfortunately, Big Sur users cannot install that version because 1Password 8.10.62 and later require macOS 12 or newer.
That leaves Big Sur in an unfortunate state:
8.10.60
= last Big Sur-compatible version
= Safari signing certificate has now expired
8.10.62+
= requires macOS 12+
8.12.33
= contains the current Safari connection fix
= cannot run on Big SurWhat I'm requesting
Would the 1Password team please consider one of these?
1. Re-sign the Big Sur-compatible 8.10.60 1Password for Safari package with a current certificate, including its embedded Safari extension as required.
2. Release a small 8.10.60 maintenance build containing only the updated signing/certificate material required for Safari desktop integration.
3. If the Safari fix represented by !40819 contains another change required in addition to re-signing, backport only the minimum necessary Safari integration fix to the final Big Sur-compatible branch.
I'm not asking 1Password to restore Big Sur as a currently supported platform or to backport new features.
I only want the last version that 1Password officially provided for Big Sur to remain operational, rather than permanently losing desktop/Safari integration because a certificate embedded in that final build reached its expiry date.
Given that the application itself still runs correctly and temporarily moving the system clock before the certificate expiration immediately restores the connection, this seems like something that could potentially be addressed with a relatively small maintenance/re-signing release.
Could someone from the 1Password team please pass this to the macOS/Safari engineering team and confirm whether a re-signed Big Sur-compatible build is possible?
