This week a link to The Open Group’s register of UNIX certified products reached the front page of Hacker News, under the observation that Apple’s macOS had quietly disappeared from it. The thread did what threads do: argued about whether it mattered, whether Apple had let the certification lapse, and whether anyone still cares about UNIX branding in 2026.
Nobody counted. So we did. We pulled every page of the register, parsed every certificate it links to, and probed all 183 certificate URLs it exposes.
Apple turning up missing is the least interesting thing in there.
TL;DR
- The register publishes four different views of itself, and they disagree. The UNIX landing page lists 9 certified products. The page that calls itself “the full register” lists 29. The by-company view lists 82. The by-product-standard view lists 114.
- Certifications are retired by wrapping them in an HTML comment. We recovered 52 certificates hidden from every index page, and all 52 still serve a live certificate page at a stable URL.
- All 183 certificate pages return HTTP 200. A control probe of four invented certificate numbers returned 404, so the 200s are real records, not a catch-all.
- Not one of the 183 pages contains the words expiry, valid until, withdrawn, revoked or status. The only date on a certificate is “Registered on”. The median registration year is 2005.
- Apple’s own company page is unlinked from the company index but still live, and still lists 20 current macOS certifications. The story is not that Apple was removed. It is that a register can hold both answers at once and never notice.
What we actually measured
The register is a set of static HTML pages. There is no API, no JSON, no export. We fetched the landing page, the full-register page, the by-company index, the recently-certified page, all 33 published product-standard pages and all 11 per-company pages. From those we extracted every link matching the certificate URL pattern, split into links that render on the page and links that sit inside HTML comments. Then we fetched all 183 distinct certificate pages and parsed company, product, environment, product standard and registration date out of each one.
Every figure below comes from that parse. The control probe matters, so it is worth stating plainly: we requested four certificate numbers that do not exist, and the server returned 404 for each. Absence is detectable on this site, which is what makes the presence of the retired records meaningful.
Finding one: four views, four answers
The register’s front door is titled “The Register of UNIX Certified Products”. It lists nine products from three vendors: IBM, Hewlett Packard Enterprise and The SCO Group.
Click through to the page headed “The full register of certified products” and you get 29 entries, under headings for 11 product standards.
The register’s catalogue lists 33 product standards. Walk those 33 pages individually and you find 114 distinct live certificates. Walk the per-company pages instead and you find 82.
Same register, same afternoon, four numbers: 9, 29, 82, 114. Nothing on any of the four pages tells a reader which one is authoritative, and none of them links to a count.
The cross-view disagreement is not a rounding error either. Forty-nine certificates appear live on a product-standard page but on no company page. Seventeen appear live on a company page but on no product-standard page.
Finding two: retirement is an HTML comment
When a certification stops being current, it does not get a status change. It gets commented out.
We recovered 52 certificates that are wrapped in HTML comments on every index page that references them. Oracle accounts for most of them: an entire Solaris estate going back to Solaris 8 in 2000, plus Solaris 9, Solaris 10 and Oracle Solaris 11. Apple’s macOS 13 Ventura certificates are in there. So is Huawei EulerOS.
Every one of those 52 still answers on its own URL with a normal certificate page. There is no banner, no strikethrough, no superseded notice. The page for Oracle Solaris 11, registered 8 November 2011, is indistinguishable in structure from the page for a certificate that is genuinely current.
The sharpest example is Oracle Solaris 11.4, registered against UNIX V7 on 10 April 2018. The UNIX V7 product standard page lists exactly one certified product, IBM’s AIX 7. Solaris 11.4’s UNIX V7 certificate is commented out of every index on the site, and it returns HTTP 200 today.
If your supplier assurance process resolves a certificate URL and checks for a 200, it has been passing on withdrawn certifications for a quarter of a century.
Finding three: there is no field for “no longer certified”
We grepped all 183 certificate pages for the words expiry, expires, valid until, withdrawn, revoked and status. Zero hits. Not one.
Each certificate carries four facts: company name, product name, environment and “Registered on”. That is the entire data model. It can express that something was certified. It has no way to express that something stopped being certified, which is why the only available mechanism is deletion from an index, and why the preferred mechanism is a comment.
Run the dates and the consequence is visible. The median registration year across all 183 certificates is 2005. Forty-two of them were registered in 2003 alone. The oldest is 3 May 1995 and the newest is 29 August 2025.
Meanwhile the “recently certified products” page carries a generated date of 9 October 2026 and an empty list. The site is being rebuilt. It simply has nothing new to say, and no vocabulary for saying that anything old has ended.
Finding four: who is still listed as a current holder
The SCO Group, Inc. holds 12 live certificates, including the only certification under UNIX 93 and the only one under the Base product standard, both registered 3 May 1995.
The most recent filing on SCO Group’s SEC record is a form type of REVOKED, dated 25 May 2011: a Commission order revoking the company’s Exchange Act registration. There has been nothing since. Fifteen years later it is one of three vendors on the front page of the UNIX register.
It is not alone. Silicon Graphics, Inc. holds four live certificates from January 1998. AT&T Laboratories – Cambridge Limited holds one, for omniORB 2.7.1, certified in May 1999 “on Sun SPARC Ultra 2 running Solaris 2.5.1”. ThinkOne Inc holds one for MICO 2.2.7, whose recorded environment is SUSE Linux 5.3, kernel version 2.0.35, compiled with gcc egcs-2.91.57.
Four product standards are still published with zero certified holders: UNIX 98, XPG3 Commands and Utilities, XPG3 C Language, and Role-Based Access Control. The RBAC page has a heading and nothing underneath it.
Finding five: the Apple answer depends which page you open
Here is the thing the Hacker News thread missed.
Apple is absent from the full-register page and absent from the by-company index. But the UNIX 03 product-standard page still carries two live entries for macOS 26.0 Tahoe, on Apple silicon and on Intel, registered 29 August 2025.
And Apple’s own company page is still there. It is not linked from the company index, which lists six companies, but request it directly and it returns 200 with 20 live certifications: macOS 26.0 Tahoe and macOS 15.0 Sequoia, each on both architectures, across five product standards including UNIX 03.
Apple is not the only unlinked company page. Oracle, Huawei, Fujitsu and a legacy Sun Microsystems page all return 200 and none appear in the company index. The Oracle and Sun pages are byte-identical, same checksum, two URLs. Fujitsu’s certificate renders on the full-register page while its company page is unlinked, so the company index is missing a vendor that the register itself lists.
“Apple was removed from the UNIX registry” is true of two views and false of two others. That is not a correction to the story. That is the story.
Finding six: the data quality underneath
Five certificates are filed under the company name “IBM Corportion”. They are current, they cover AIX 7 and the XLC/C++ compiler, and they were registered on 30 September 2020. A string match on “IBM Corporation” misses all five, which quietly understates IBM’s holdings by 8%.
Hewlett-Packard Company holds 25 certificates and Hewlett Packard Enterprise holds one. The register treats them as unrelated entities with no cross-reference, which is defensible legally and useless to anyone trying to answer “is our HP-UX box covered”.
Registration dates are formatted at least three ways across the set, including “30-September-2020” sitting beside “18-Oct-2017” and “8-Sep-2016”.
Why this belongs on your risk register
It is tempting to file this under charming internet decay. Do not. The register’s own landing page states its purpose: it “enables buyers to specify UNIX conformance in procurements”. That sentence is load-bearing. Conformance clauses citing the Single UNIX Specification are still in live public-sector and enterprise contracts, and the register is the thing those clauses point at.
The failure mode generalises well beyond UNIX, and we see it constantly in supplier assurance work. The pattern is a verification step that returns a boolean when the underlying system cannot represent falsity. A certificate URL that always resolves. A trust centre that serves last year’s audit report at this year’s URL. A compliance badge image hosted by the vendor it certifies. A standards body page with no revocation list. In every case the check passes, the questionnaire gets a tick, and nobody has learned anything.
Four things we would ask of any certification check in a supplier assurance process:
- Prove the register can say no. Probe for a record you know does not exist. If it does not 404, your check is a coin that always lands heads. This takes about a minute and almost nobody does it.
- Read the schema, not the page. If the record has no expiry, status or revocation field, then presence carries no information about currency. Store the registration date and treat anything beyond your own staleness threshold as unverified.
- Reconcile the views. Where a register publishes more than one index, parse all of them and alert on disagreement. The 9-versus-114 gap here was visible in under an hour of scripting, and it is exactly the kind of signal a once-a-year manual review will never surface.
- Diff the source, not the render. Fifty-two retired certificates were sitting in HTML comments in pages we had already downloaded. The retirement history of this register is in its markup, and it is invisible in a browser.
None of this is UNIX-specific. Substitute your ISO certificate checker, your subprocessor list, your SBOM attestation endpoint or your cloud provider’s compliance portal, and ask the same four questions. The answers are usually worse than the one we got here, because at least The Open Group leaves the evidence in the page.
At REPTILEHAUS we build the verification layer behind supplier assurance and compliance workflows: scrapers and probes for registers that have no API, reconciliation jobs that catch a source disagreeing with itself, and the DevOps to run them on a schedule instead of before an audit. If your vendor questionnaire has a column nobody can actually prove, get in touch.
📷 Photo by Maksym Kaharlytskyi on Unsplash

