MailStore Error ‘The certificate with identifier used to sign the client assertion is expired on application. Reason – The key used is expired’
This warning has happened because the certificate you created when synchronising MailStore with your Microsoft Entra ID has now expired.
To resolve this issue you will need to create a new one within MailStore and upload to your App registration within Microsoft Entra ID
The following guide will take you through these steps.
Creating a new Certificate within MailStore Server
- Log on to MailStore Client as a MailStore Server administrator
- Click on Administrative Tools > Users and Archives > Directory Services
- In the Connection section, click on the button (…) next to the Credentials drop-down list
- In the Credential Manager that appears, select the current credentials configured (most likely called ‘MailStore Server’) and click on edit
- In the Microsoft Entra ID App Credentials dialog, click on the small down arrow on the Certificate line and choose ‘Create certificate

- Once created again click on the same down arrow and select Download Certificate. Save the certificate on your hard drive.
- Confirm your entries by clicking OK.
Publishing Credentials in Microsoft Entra ID
- In the navigation menu (☰), select the option Microsoft Entra ID
- On the next page, select App registrations in the Manage section of the left navigation menu
- Select All Applications. And select the ‘MailStore’ Application you previously configured
- Select Certificates & secrets in the Manage section of the left navigation menu
- You should see your previous expired certificate here. which you can delete once you have uploaded the new certificate
- Click on Upload certificate in the Certificates section. Select the certificate file that you have saved previously and upload it to Microsoft Entra ID by clicking Add
- If uploading has been successful, the certificate's thumbprint as well as its start and expiry dates appear in the certificates list. You can compare the thumbprint and expiry date with those listed in the MailStore Credential Manager to check that you've uploaded the correct certificate