Choose your language

Choose your login

Support

How can we help?

PaperCut's AI-generated content is continually improving, but it may still contain errors. Please verify as needed.

Lightbulb icon
Lightbulb icon

Here’s your answer

Sources:

* PaperCut is constantly working to improve the accuracy and quality of our AI-generated content. However, there may still be errors or inaccuracies, we appreciate your understanding and encourage verification when needed.

Lightbulb icon

Oops!

We currently don’t have an answer for this and our teams are working on resolving the issue. If you still need help,
User reading a resource

Popular resources

Conversation bubbles

Contact us

Troubleshooting the 'Encryption Credentials have expired' error on macOS

THE PAGE APPLIES TO:

Last updated November 7, 2025

Understanding the ‘Encryption Credentials have expired’ error

The error message “Encryption Credentials have expired” is commonly seen by macOS users when printing to a PaperCut Mobility Print queue. This message typically appears in the print queue window or the CUPS logs, indicating that the SSL certificate used by the Mobility Print server has expired, is not trusted, or is not installed correctly. Windows and iOS clients are usually unaffected.

Common causes

This error can occur for several reasons:

  • The SSL/TLS certificate on the Mobility Print server has expired.
  • The certificate is not installed in the correct location, for example, it was updated on the PaperCut Application Server but not on the Mobility Print server.
  • The certificate does not match the server’s hostname (CN/SAN mismatch).
  • The macOS client is caching old credentials or certificates.

This issue is usually indicated in the CUPS logs on Mac devices, which show messages like Credentials are expired (Credentials have expired.) and STATE: -cups-pki-expired until the certificate is renewed or correctly installed on the Mobility Print server.

Fixing the error

This issue can often be fixed by one of the following solutions.

Ensure the Mobility Print server is using a valid and trusted SSL certificate

For detailed instructions, see Configure Mobility Print to use a trusted TLS/SSL Certificate .

Remove and re-add the printer on the Mac client

After you update the certificate, macOS clients might still cache the old certificate or credentials.

To remove and re-add the printer:

  1. Open System Settings > Printers & Scanners.
  2. Delete the affected printer queue.
  3. Re-add the printer using the Mobility Print setup link or installer.

Clear cached credentials and certificates on macOS

If the error persists, clear any cached credentials or certificates from the client machine.

  1. Open Keychain Access (in Applications > Utilities).
  2. Search for entries related to the Mobility Print server by its hostname or IP address.
  3. Delete any related entries.
  4. Restart the Mac and re-add the printer.

For more details, see ‘Hold for Authentication’ Error in Mac Print Queue .

Additional troubleshooting

If the issue continues, try these additional steps:

  1. Check CUPS logs for certificate errors: For detailed instructions, see How to Enable Debug (collect logs) in CUPS
  2. Ensure the certificate’s CN/SAN matches the server’s hostname used by clients.
  3. If you are using a wildcard certificate, ensure it is valid for the server’s FQDN.

Category: Troubleshooting Articles

Subcategory:


Comments