Computer lessons

What is the password for eToken and Rutoken. Generating a PKI key on JaKarta Standard PIN code Jakarta

We worked for a year. Alcohol was accepted, sales were sent out. And here is UTM stops send requests and receive documents. Speaks: expiration date has expired PKI-certificate.
Unlike a GOST certificate, which costs money, PKI is obtained for free and its duration smooth1 calendar year.

It's easy to get a new certificate! Just follow our instructions.

1. Look for the JaCarta single client icon near the clock and double-click to open it.

2. Open the "PKI" tab. Select the certificate and open it for viewing. If there is no certificate, then we go straight to .

3. Look at the expiration date of the certificate. And, if it is close to the current one, then we move on to .

4. Launch the Internet Explorer browser. You can find it by clicking on the "Start" button.

6. Select the item “Read the conditions and check their compliance.” Next, go to “Start scanning”.

7. If the verification was successful, then enter the PIN code of the hardware key (GOST): 0987654321 and click "Show certificates".

8. Select the certificate that appears.

10. We are looking for our own separate unit (at the checkpoint). Click "Generate key".

11. Check the address: the "Show address" button.

12. If everything right, then enter the PIN (RSA): 11111111 and click "Generate key".

13. Repeat entering the PIN code: 11111111

14. If everything went well, then when viewing the certificate parameters....

15. ... we will see updated data.

Good luck.

Your carrier JaCarta could be blocked if the wrong PIN was entered several times.
To unlock JaCarta follow these instructions:
1. Insert media Jacarta into your computer and run Single JaCarta Client. To do this, click Start → All Programs → Unified JaCarta Client.
2. In the program window that opens, click the button in the lower left corner Switch to administration mode.

3. Go to the desired tab, PKI or GOST respectively:


4. Click the button Unblock user PIN


5.In the window that opens, specify Administrator password.
Default administrator password:

For the PKI part:
Administrator 00000000;

For GOST parts:
Administrator 1234567890;

Attention! Under no circumstances should you be blocked as an administrator. In this case, the device will be completely blocked without the possibility of restoring the key! If you do not know the password, contact technical support for advice.

6. If the PIN code was entered correctly, a window will appear with the message Unlocking completed successfully.

Jacarta has been successfully unlocked.

Description of the problem. For EGAIS two certificates are used: GOST certificate for the legal significance of TTN; RSA certificate to identify the counterparty.

Each certificate is valid for one year from the date of its formation.

The GOST certificate is issued by a certification center, so to renew it, contact the certification center.

The RSA certificate is generated on the EGAIS portal, so you can replace it yourself.

To solve the problem of, you need to clear the PKI section from the old RSA certificate and write a new one there.

Step-by-step instructions on how to renew an RSA certificate

Step 1. Switch to administration mode

In the Start menu, find the JaCarta Unified Client application and open it.

Rice. 1. Single JaCarta client

The program workspace will open.

Rice. 2. Switch to administration mode

The program workspace will re-open. Go to the PKI tab.

Rice. 3. Token information

NOTE: Before proceeding, make sure the PKI section is not locked.

Order a consultation with a specialist on working with EGAIS

Step 2. Cleaning the PKI partition

On the PKI tab in the Application Operations panel, click the Initialize... link.

Rice. 4. Application Operations

To initialize, obtain permission and provide user data:

1. Administrator PIN - default 00000000

2. User PIN - default 11111111

Rice. 5. Initializing the application

After entering the data, click "Run".

A notification will appear stating that the old PKI certificate will be deleted during initialization. Click Continue to complete.

Rice. 6. Deletion warning

Once you have cleared the PKI partition, it is ready to write a new certificate.

Step 3: Write a new certificate

Rice. 11. Enter the PIN code of the hardware key

The system will show your certificate. Click on it to enter the portal.

Rice. 12. Certificate for entering the portal

In the left vertical menu, select “Get key”.

Rice. 13. Obtaining a key

Dots with addresses that are registered in the EGAIS system will appear in the center of the page. Find the one you need and click the “Generate key” button.

The certificate creation process will begin.

To generate a certificate, enter the user's PIN code - the default is 11111111. Click on the "Generate key" button.

Rice. 14. Generating an RSA certificate

In some cases, the operating system will additionally ask you to enter the PKI user PIN code for the partition—the default is 11111111.

Rice. 15. Additional PIN entry

Wait until the RSA certificate is generated.

After successful completion, the following message will appear: “The certificate has been successfully written to the token.”

Rice. 16. Certificate generation

This completes the replacement of the RSA certificate, continue working with EGAIS.

The JaCarta token may be blocked, the error may be CKR_PIN_LOCKED, if you enter the wrong PIN code several times in a row, this can happen even if you did not enter it, because the program in which you process documents remembers the entered PIN code and accesses the key every time.

The default pin code on the new Jakarta carrier is:

  • User PIN code (without spaces): 0987654321
  • Administrator PIN (without spaces): 1234567890
Unblocking JaCarta is done as follows:
  1. Open the management program: JaCarta Unified Client
  2. Open the GOST tab
  3. Then select Unblock user PIN

4. A warning will appear stating that this unlock only resets the error counter. If you changed the standard PIN code and forgot it, then only generating a new qualified electronic signature (CES) at the Certification Center will help in your case.

5. In the window that opens, enter the administrator PIN code 1234567890 in the field. Click Run

6.If everything is done correctly, a window will appear with the message Unlocking successful.

7. Close the program. Now you can try to enter your PIN code again. The standard user PIN code is 0987654321. If you have changed the standard PIN code and do not remember it, then you will have to generate a new qualified electronic signature (CES).