Make sure your root certificates are up to date and not expired.

It is also important to have your Certificate Revocation List (CRL) up to date.