Troubleshooting & FAQs

Common problems when ordering, installing, and using DigiCert code signing certificates from GeoCerts.

Still stuck? Contact GeoCerts support with the order ID, provisioning method, and a screenshot or exact error text.


USB eToken

The Hardware Certificate Installer says “An unexpected error has occurred”

Usually the initialization code is expired or already used.

Fix: In CertCommand, Reissue Certificate, copy the new initialization code, and run the installer again. See Expired or invalid initialization code.

I forgot the eToken Password (PIN)

If the Administrator Password is still the factory default (48 zeros) or a value you stored, log on as Administrator in SafeNet and set a new PIN. See Reset a forgotten eToken Password.

I lost the Administrator Password

Unrecoverable. Order a new eToken and reissue. See Lost Administrator Password.

The token shows as “SafeNet Token JC 0”

Permanently locked. You cannot unlock it. Replace the eToken and reissue. See SafeNet Token JC 0.

SafeNet does not see the token

  • Install SafeNet Authentication Client for this OS.
  • Try another USB port (avoid unpowered hubs).
  • On Windows, confirm the installer used the latest SafeNet build (older clients can fail with error 5-0x00000030).

Error 8-0x00000062 during install

The token does not support RSA above 2048. Use ECC (p-256 or p-384) in the Hardware Certificate Installer for an urgent sign, or contact support for a compatible token. ECC is not supported by every signing tool.

Error 8-0x00000031

Too many certificates on the token. Remove unused certs in SafeNet (or re-initialize if you can wipe it), then install again.


Azure Key Vault

Merge fails or the key does not match

You must merge into the same Key Vault certificate object that generated the CSR. Do not delete, recreate, or rekey that object. Use a P7B or full-chain PEM. See Azure Key Vault.

EV rejected or key is exportable

Use Premium Key Vault, RSA-HSM, Exportable: No, and key size 3072 or 4096.


AWS CloudHSM

CSR or signing fails with no sign attribute

Generate a new key pair with --private-attributes sign=true. You cannot add sign later. Use CloudHSM CLI, not key_mgmt_util. See AWS CloudHSM.


Java

keytool error: java.lang.Exception: Input not an X.509 certificate

Wrong alias, wrong file format, or wrong keystore. For current public CS certs, sign with PKCS #11 rather than importing a private key into a .jks. See Java (jarsigner).


Ordering and validity

How long is a code signing certificate valid?

Newly issued public CS certificates are capped at 459 days (DigiCert) even on multi-year terms. Reissue during the term. See Change Log and Order a code signing certificate.

Reissue is greyed out

Contact GeoCerts support with the order ID.

Can I move a token cert to KeyLocker or Azure?

Not the same private key. Reissue with the new provisioning method; that generates a new key. See Choose a provisioning method.


← Back to Code Signing