I started seeing this yesterday both with Mac and Windows (ZXPSignCmd 4.1.2). I suspect something changed with digicert.com?
ZXPSignCmd -sign dir file.zxp certificate.p12 password -tsa http://timestamp.digicert.com
Error - the timestamp returned from the chosen TSA could not be verified, so the ZXP created is likely to be rejected by other tools. Please recreate your ZXP with a different trusted TSA.