Troubleshooting & FAQs
Common problems when ordering, installing, and using DigiCert code signing certificates from GeoCerts.
Still stuck? Contact GeoCerts support with the order ID, provisioning method, and a screenshot or exact error text.
USB eToken
The Hardware Certificate Installer says “An unexpected error has occurred”
Usually the initialization code is expired or already used.
Fix: In CertCommand, Reissue Certificate, copy the new initialization code, and run the installer again. See Expired or invalid initialization code.
I forgot the eToken Password (PIN)
If the Administrator Password is still the factory default (48 zeros) or a value you stored, log on as Administrator in SafeNet and set a new PIN. See Reset a forgotten eToken Password.
I lost the Administrator Password
Unrecoverable. Order a new eToken and reissue. See Lost Administrator Password.
The token shows as “SafeNet Token JC 0”
Permanently locked. You cannot unlock it. Replace the eToken and reissue. See SafeNet Token JC 0.
SafeNet does not see the token
- Install SafeNet Authentication Client for this OS.
- Try another USB port (avoid unpowered hubs).
- On Windows, confirm the installer used the latest SafeNet build (older clients can fail with error
5-0x00000030).
Error 8-0x00000062 during install
The token does not support RSA above 2048. Use ECC (p-256 or p-384) in the Hardware Certificate Installer for an urgent sign, or contact support for a compatible token. ECC is not supported by every signing tool.
Error 8-0x00000031
Too many certificates on the token. Remove unused certs in SafeNet (or re-initialize if you can wipe it), then install again.
Azure Key Vault
Merge fails or the key does not match
You must merge into the same Key Vault certificate object that generated the CSR. Do not delete, recreate, or rekey that object. Use a P7B or full-chain PEM. See Azure Key Vault.
EV rejected or key is exportable
Use Premium Key Vault, RSA-HSM, Exportable: No, and key size 3072 or 4096.
AWS CloudHSM
CSR or signing fails with no sign attribute
Generate a new key pair with --private-attributes sign=true. You cannot add sign later. Use CloudHSM CLI, not key_mgmt_util. See AWS CloudHSM.
Java
keytool error: java.lang.Exception: Input not an X.509 certificate
Wrong alias, wrong file format, or wrong keystore. For current public CS certs, sign with PKCS #11 rather than importing a private key into a .jks. See Java (jarsigner).
Ordering and validity
How long is a code signing certificate valid?
Newly issued public CS certificates are capped at 459 days (DigiCert) even on multi-year terms. Reissue during the term. See Change Log and Order a code signing certificate.
Reissue is greyed out
Contact GeoCerts support with the order ID.
Can I move a token cert to KeyLocker or Azure?
Not the same private key. Reissue with the new provisioning method; that generates a new key. See Choose a provisioning method.