Passwords, lockouts, and reissue

SafeNet eTokens use two passwords. Mixing them up is the most common way customers permanently brick a token.


The two passwords

Password What it is Default If you lose it
eToken Password (PIN) Unlocks certificates for signing The PIN you set during Hardware Certificate Installer Admin can reset it, or reissue and re-install the certificate
Administrator Password Resets a forgotten PIN; unlocks after failed PIN attempts Factory default: 48 zeros (000000000000000000000000000000000000000000000000) Unrecoverable. DigiCert cannot override it. Buy a new eToken.

There is also a manufacturer PUK (often 000000). DigiCert’s install flow does not use it.

In SafeNet Advanced View, you can Log On to Token (user / PIN) or Log on as Administrator.

SafeNet Advanced View with Log On to Token and Log on as Administrator highlighted


Reset a forgotten eToken Password

If you still have the factory (or known) Administrator Password:

  1. Open SafeNet Authentication Client → Advanced View (gear).
  2. Select the token → Log on as Administrator → enter the Administrator Password (48 zeros if you never changed it).
  3. Set a new eToken Password.
  4. Confirm success and store the new PIN.

SafeNet dialog: Password changed successfully

That is the fastest recovery. You do not need to reissue.


Reissue and re-install

Reissue when:

  • The Administrator Password is lost and you cannot reset the PIN
  • The initialization code expired (“unexpected error” in the Hardware Certificate Installer)
  • You intentionally wipe the token and start over
  • You are inside a multi-year term and the current certificate is approaching the 459-day cap
  1. Log in to CertCommand, open the order, and choose Order Actions → Reissue Certificate. If the option is greyed out, contact support.

    CertCommand Order Actions menu with Reissue Certificate

  2. Choose use existing token (unless you are ordering a replacement eToken).
  3. After reissue, copy the new initialization code and run the Hardware Certificate Installer again (re-initialize if you are wiping the token).

Expired or invalid initialization code

Error: The Initialization Code was invalid, has already been used, or has expired — or a generic An unexpected error has occurred.

Fix: Reissue (or force reissue if Install certificate is missing), then copy the new initialization code and install again. Do not reuse an old code.


SafeNet Token JC 0

If the token name is SafeNet Token JC 0, shows a warning icon, and Rename / Change Password / Unlock are all disabled, the eToken is permanently locked (usually too many failed Administrator Password attempts).

SafeNet Authentication Client showing SafeNet Token JC 0 with actions disabled

You cannot reset this device. Contact GeoCerts support to order a new eToken, then reissue the certificate onto the replacement.


Lost Administrator Password

If you changed the factory 48-zero Administrator Password and then lost it, the token is unrecoverable even if you still remember the eToken PIN for signing—until you hit a lockout you cannot clear. Treat it as needing a replacement token before you get stuck.

Contact GeoCerts support to order a new eToken.


← Back to USB eToken