The most obvious answer would be that it's being installed by some widely-used piece of software, but I don't know what.
Pity the "Date Modified" column is empty, and I don't think there's really a log of what added things to the keychain.
The most obvious answer would be that it's being installed by some widely-used piece of software, but I don't know what.
Pity the "Date Modified" column is empty, and I don't think there's really a log of what added things to the keychain.
We've worked around the issue for now by not using EV certificates, which isn't a great solution.
Could be just about anything. In my case, my keychain has followed me from one Mac to the next since before the cert that expired today was ever issued, so it could have ended up in there anytime in the last ~8 years from anything I might have had installed dating back to my PowerBook G4...
Virtualization software might be a candidate.
Actually, I just had another thought: Steam. And when I just tried to go to https://store.steampowered.com/, guess what certificate is in the trust chain?