An expired certificate error stops your document before a single page comes out. Messages such as “Encryption credentials have expired” point to a problem with the certificate or the clock used to check it. Start with the clocks, then replace the expired certificate and refresh your print queue.
Check the printer and device clocks first
An incorrect printer or device clock causes certificate validation failures when its date falls outside the certificate’s validity period.
For an HP printer with the supported browser interface, enter the printer’s IP address in your browser. This opens its Embedded Web Server, or EWS, the printer’s built-in settings page.
Open General > Date and Time. Check Current Printer Time. Select Sync Now if the displayed time is incorrect.
On a Mac, open Apple menu > System Settings > General > Date & Time. Enable Set time and date automatically. Enable Set time zone automatically using your current location.
On an iPhone or iPad, open Settings > General > Date & Time. Enable Set Automatically.
On Windows 11, open Start > Settings > Time & language > Date & time. Turn on Set time automatically. Enable Set time zone automatically, or select the correct Time zone manually.
Try printing again. Correcting the clock does not renew a certificate that has actually expired.
Replace an expired printer certificate
If the certificate has expired, it needs a replacement. Use the procedure matching your printer model and its settings screen.
For HP printers with the certificate-management interface, enter the printer’s IP address in your browser. Open Security > Certificate Management. Follow Create > Create a New Self-Signed Certificate > Next > Create > OK.
Close the browser settings page. Then retry printing from your Mac, iPhone, or iPad.
For supported Brother models, including the MFC-L3720CDW and MFC-L3780CDW, enter https:// followed by the printer’s IP address in your browser. Log in to the printer’s settings. Open Network > Security > Certificate > Create Self-Signed Certificate.
Enter a Common Name matching the printer address or name. Set a valid Valid Date. Choose the Public Key Algorithm and the Digest Algorithm. Click Submit.
On an Epson WF-C5310 or WF-C5390 that uses a self-signed certificate, open Web Config > Network Security > SSL/TLS > Certificate > Update. Enter the Common Name. Choose Certificate Validity (year). Follow Next > OK > Confirm to finish.
If the Epson uses a CA-signed certificate instead, Update is the wrong route. Have the administrator open Network Security in Web Config, select Generate in the CSR section, and download the CSR for the certificate authority. Do not generate another CSR while waiting. Once the CA issues the replacement, use Import to install it, then click Confirm.
For a different model or certificate interface, follow that printer’s certificate instructions. If replacing the certificate does not restore printing on your Mac, recreate its queue next.
Give your Mac a fresh printer queue
After replacing the certificate, open Apple menu > System Settings > Printers & Scanners. Control-click the affected printer and choose Remove Printer. Click Remove Printer again to confirm.
Select Add Printer, Scanner, or Fax. For the standard setup, choose your printer. Click Add.
For Brother’s “Invalid Certificate - Check the printer for errors” message on macOS Tahoe 26, use its alternative setup instead: select IP in the add-printer window. Enter the printer’s IP address or hostname in Address. Choose AirPrint under Protocol. Click Add.
Tip: If the repaired printer remains paused, open Print Center from the Dock and click Resume.
Clear the affected HP certificate on your Mac
A corrupted HP certificate saved on your Mac keeps the credentials error from clearing.
Open Keychain Access using Spotlight. HP recommends this cleanup as an escalation step for its expired-credentials error.
Select Login. Select Certificates. Find the HP certificate containing your printer model’s name.
Control-click that certificate and choose Delete. Limit the deletion to the affected printer certificate.
Retry your print job. Removing the saved Mac certificate does not renew an expired certificate on the printer.
Update HP firmware and check remaining printing problems
Check for a firmware update if certificate replacement and queue cleanup have not restored printing. Firmware updates are a separate maintenance step and do not substitute for certificate renewal.
Enter the printer’s IP address in your browser to open its EWS. Select General > Firmware Update. Enter the printer PIN if prompted. Click Submit.
Select Check for Update. Click Update when an update is offered. Keep the printer connected to power throughout installation.
For HP models with the alternative browser layout, open Printer Update or Manage > Printer Updates instead. Enter the PIN if prompted. Select Check Now. Available updates install automatically in this layout.
For a remaining queue or driver problem, open the HP app on Windows or macOS. Select your printer. Open Diagnose & Fix. Click Start.
Follow the results while leaving the app open. The tool clears stuck queues and resolves spooler issues; on Windows only, it also fixes port mismatches and installs available driver updates. It does not renew printer certificates.
HP retired Print and Scan Doctor on May 27, 2025. Use Diagnose & Fix in the HP app for these printing problems.
Keep resets as a last resort
Choose the reset matching your remaining problem, and expect to set up printers again.
- 1.For a persistent Mac printing problem on macOS Tahoe 26, open Apple menu > System Settings > Printers & Scanners. Control-click a printer or the empty printer list and select Reset Printing System. This removes every printer, completed-job information, and printer presets.
- 2.Add your printers again using Add Printer, Scanner, or Fax, then test printing. Resetting the Mac printing system does not replace an expired printer certificate.
- 3.For an HP printer that still needs a factory reset, open its EWS and follow General > Restore Default Settings > Restore Factory Defaults > Yes. This path applies to HP models with that EWS layout.
- 4.Set up the HP printer again, then retry your document.
Use USB when you need the document now
Connect a USB-capable printer to your Mac with its supported USB cable. Open System Settings > Printers & Scanners.
Select Add Printer, Scanner, or Fax if the USB printer is not already listed. Choose the USB printer. Click Add.
Select the USB printer queue when printing your document. Tip: USB avoids the network certificate path, so repair the expired certificate before returning to that network connection.
Frequently Asked Questions
Should I choose Always Trust for an expired printer certificate?
No. A trust override does not extend a certificate’s expiration date. For a renewed Xerox device certificate, the administrator can download the printer’s Device Root Certificate Authority from its Embedded Web Server and install it in the Mac’s Keychain so the Mac trusts the new certificate.
Does switching to AirPrint always bypass certificate errors?
No. AirPrint and IPP are not guaranteed to avoid TLS. Supported LPD or HP Jetdirect Socket connections offer alternative network-printing paths, but they do not renew the expired certificate.
What if the affected printer belongs to my workplace?
Contact your print administrator. For PaperCut Mobility Print, have the administrator check and renew the server certificate, then recreate the Mac queue using your organization’s setup link or installer. An expired Microsoft Universal Print device certificate requires administrator re-registration.
The certificate error is gone, but an individual print job is still stuck. What next?
In Print Center, select a paused job and click Resume Job. For a failed job, select it and click Delete Job, then submit the document again.