Quick answer
Check three things first: the certificate is installed and still in date, the PEXA Digital Signing extension is active in your browser, and your PEXA profile name exactly matches the name on the certificate. If it's expired, renew or re-issue it (or move to Mobile Signing). If you're stuck before a settlement, call PEXA support on 1300 084 515 straight away.
WHY IT HAPPENS
The certificate, the extension, or the name.
Signing in PEXA relies on a valid digital certificate and a browser extension that lets PEXA talk to it. A "certificate can't be found" or "expired" message almost always comes down to one of a few things: the certificate has lapsed, the signing extension isn't installed or is disabled, a USB signing token isn't connected properly, or the name recorded on your PEXA profile doesn't line up with the name on the certificate — even a missing middle name or a preferred name is enough to cause it. Work through the checks below.
HOW TO FIX IT
Work through these in order.
- Check the certificate hasn't expiredDigital certificates have a fixed lifespan. If yours has lapsed, PEXA can't find a valid one to sign with. Confirm the expiry date — if it's due or overdue, jump to renewing it (step 6) and don't leave it until settlement day.
- Confirm the PEXA Digital Signing extension is installedSigning needs the official PEXA Digital Signing extension for Chrome or Edge. Open your browser's extensions page, make sure it's present and enabled, then reload PEXA. If it's missing, install it from your browser's web store and restart the browser.
- If you use a USB signing token, reconnect itPlug the token directly into the machine (not through a hub), and check its indicator light is on steadily rather than flashing. Then reload PEXA and try the signing prompt again.
- Make your PEXA name match the certificate exactlyThe name on your PEXA profile must match the name on your certificate character for character. If the certificate was issued with (or without) a middle name or a preferred name, update your PEXA profile to match — a mismatch here is a very common cause of "certificate not found".
- Clear the browser and retry the signing promptIf the prompt appears then fails, clear your cache and cookies, allow pop-ups for PEXA so the signing window isn't blocked, and sign in fresh. A stale session can stop the browser from trusting the certificate handshake.
- Renew or re-issue the certificateIf it's expired, renew or re-issue it through PEXA, or obtain a compliant soft certificate from a Gatekeeper-accredited provider such as DigiCert. Many firms are moving to Mobile Signing, which signs from an app on your phone. Note that older PEXA USB tokens and CD-based soft certificates are being phased out, so choose a path that will still be supported.
- Check you're the correct signing userOnly a user who holds a valid certificate and the right role can sign. If the person logged in isn't a set-up signer, PEXA won't offer a certificate to sign with — have the correct authorised signer complete the signing.
- Contact PEXA supportIf it still won't sign — especially with a settlement approaching — call PEXA support on 1300 084 515. They can confirm the state of your certificate and profile from their side, which is faster than guessing under time pressure.
Renewals are a schedule, not an emergency. Certificate expiry, token retirement and profile-name mismatches all catch firms out at the worst possible moment — mid-settlement. A managed IT provider tracks expiry dates, keeps the signing extensions current across every machine, and moves your team to a supported signing method before the old one stops working.