Updating Certificates

Prev Next

DUE TO AN UNFORSESEEN REASON, THE RELEASE OF THE CA AND US1 CERTIFICATES HAS BEEN RESCHEDULED. SEE THE TABLE BELOW FOR THE UPDATED RENEWAL TIMES, AS WELL AS ADDITIONAL INSTRUCTIONS THAT MAY NEED TO BE FOLLOWED.

OneSpan periodically updates and reissues certificates for each region's Sandbox and Production environments, on the specific dates shown in the table below. These updates are essential to ensure the security and integrity of our systems, and they are conducted with careful planning to minimize any potential impact on users. The reissuance of certificates is a routine process that helps maintain the trust and reliability of our services across different regions.

There is no downtime during a certificate renewal. This means that users can continue to access and utilize the Sandbox and Production environments without interruption.

For more information about configuring certificates, see Getting Started with SDKs. This article provides detailed information on how to properly set up and manage your certificates, ensuring that you can take full advantage of the features and functionalities offered by our SDKs.

If you have any questions or concerns, please do not hesitate to contact our Support Team. We also encourage you to visit the  OneSpan Sign Trust Center for regular updates on this matter.

How Does This Impact Me?

If you are not an integrated customer and do not trust any of our certificates, no action is required.

If you have trusted our root certificate as recommended, and the New certificate for download table does not show a new root certificate for you environment, no action is required.

Occasionally intermediates and root certificates are rotated and will need to be downloaded and updated. If this happens the new certificates will be provided in the table below.

If you have trusted leaf/end-entity or intermediate certificate, you must complete the update below to ensure your OneSpan Sign service continues to function normally.

What Do I Need to Do?

To complete this update:

  1. Download the certificate that corresponds to your environment from the New certificate for download column.

  2. If a new certificate is available, but you need a soon-to-expire certificate, download it from the Current certificate for download column.

    The expiring certificate downloads with an -expiring suffix appended to its filename (for example, star.esignlive.com.au.crt.cer-expiring). After downloading it, rename the file to remove the -expiring suffix so it matches the filename listed in the New certificate for download column. Each certificate has its own unique filename — always match the filename shown for that certificate's row, never a filename from another region.

  3. Install the new certificate before the Renewal date listed in the table below.

    In case of one or more OneSpan certificate pinning (leaf, intermediate, root, or any combination), you must install the new certificate in addition to the currently active certificate. Do not replace or remove the existing certificate until after the Renewal Date. Your system must trust both the current and the new certificates until the Renewal date passes.

  4. If necessary, update your system trust store with the new certificate listed in the New certificate for download column below. These are occasionally rotated and will need to be updated. When this happens we will provide the new certificates in the table below.

The New certificate for download column always links to the certificate that is valid as of the Renewal Date. We publish this certificate in advance so you don't have to wait until that exact date to retrieve it. This certificate only becomes active after the Renewal Date is reached.

Region

Current certificate for download

Current certificate expiry date

New certificate for download

Renewal date (Sandbox)

Renewal date (Production)

CA (Canada)

e-signlive.ca

star.e-signlive.ca.crt-expiring

(Sandbox and Production)

Oct 3, 2026

(new certificate expires April 1, 2027)

star.e-signlive.ca.crt

(Sandbox and Production)

GlobalSign Root

GlobalSign GCC

(NEW - Root certificates)

October 1, 2026, 5:00 AM ET

October 1, 2026, 5:00 AM ET

US1

e-signlive.com

star.e-signlive.com.crt.crt-expiring

(Sandbox and Production)

Oct 3, 2026

(new certificate expires April 1, 2027)

star.e-signlive.com.crt.crt

(Sandbox and Production)

GlobalSign Root

GlobalSign GCC

(NEW - Root certificates)

October 1, 2026, 5:00 AM ET

October 1, 2026, 5:00 AM ET

US2 Sandbox

esignlive.com

sandbox.esignlive.com

Feb 10, 2027

US2 Production

esignlive.com

apps.esignlive.com

Feb 10, 2027

EU (European)

esignlive.eu

apps.esignlive.eu

Feb 10, 2027

AU (Australian)

esignlive.com.au

apps.esignlive.com.au

Feb 10, 2027

FedRAMP Sandbox

sandbox-gov.esignlive.com

signer-sandbox-gov.esignlive.com

Dec 9, 2026

FedRAMP Production

gov.esignlive.com

signer-gov.esignlive.com

Dec 9, 2026