I’m developing a cross-platform desktop/mobile application for Windows, Linux, macOS, and Android.
My company already has an official digital certificate issued by Telekom. It is recognized for legally binding electronic signatures and document signing. In other words, the state recognizes the certificate and the identity behind it.
Yet that apparently isn’t enough for the major software platforms.
Apple wants an annual developer fee if I want normal macOS signing/notarization and distribution without scary warnings.
Google wants developers inside its Play Store ecosystem for normal Android distribution and updates.
Microsoft expects software publishers to use its accepted code-signing trust infrastructure, which usually means paying a commercial CA or using Microsoft’s own signing services if you want Windows to recognize the publisher without warnings.
So my question is: Why are these companies allowed to create their own private definition of “trusted developer,” even when a developer already possesses a legally recognized digital identity certificate?
I understand the technical argument that document signing and code signing are different certificate purposes. But from the developer’s perspective, the result looks like this:
“Your identity is legally verified, but we still won’t treat your software as trusted unless you participate in our approved ecosystem and, in many cases, pay.”
Why isn’t there a vendor-neutral mechanism where a legally recognized organizational certificate can establish publisher identity across operating systems? Is this mainly about security, liability, PKI design, platform control, commercial incentives, or some combination of all of them? And more importantly: what prevents Microsoft, Apple, and Google from abusing their position as platform owners to turn “trust” into a paid gatekeeping mechanism?