Promsvyazbank does not see etoken jacarta. What to do if the hardware key for egais is not detected? "Unified Jacarta Client" is not installed

I looked for this problem, but it cannot be avoided. The problem only occurs when I try to make an ajax call. The system will return the error Could not verify the provided CSRF token because your session was not found.

Based on Spring MVC and CSRF Integration, I need to enable @EnableWebSecurity to solve this problem if I use Java Config, but if you are using XML, you need to use this:

@RestController public class CsrfController ( @RequestMapping("/csrf") public CsrfToken csrf(CsrfToken token) ( return token; ) )

And I'm not sure how to use the class above.

The question is how to use the above class, if this is really the solution or is there any solution that I can use?

This is my XML security configuration file;

Additionally, I am using a system like CA Siteminder which will validate the user based on header information without a login form.

Hello everyone, today I want to tell you about my three-day battle with the problem that Etoken is not visible in the PKI Client. The story is this: our company is introducing encryption of letters and for this purpose certificates for encrypting and signing letters were issued by our Certification Center (). The certificates were issued on Etoken and they installed fine for everyone, but he refused to see the accountant. Next I will describe the solution to the problem.

The accountant's workplace had a huge amount of special accounting software. There were already 3 root tokens connected to the computer. This is what the PKI management console looked like. We see 3 empty readers, but in the end they are not empty, but as it turns out, they were root tokens that simply could not be detected by the PKI client.

This is what the eToken properties looked like. We see 3 empty devices.

The first thing you need to do is add the number of simultaneously working keys, this is done like this. Right click on Devices and select Manage Reader Devices

and increase the number of hardware readers.

After this action, you need to reboot and the token should be determined. If you are undecided, read on :)

In the event viewer you may find an error like this.

Smart card reader 'Aladin Token JC0' rejected IOCTL GET_STATE: The I/O operation was aborted due to the end of the command stream

This miracle most often pops up for two reasons: the drivers were installed crookedly and the registry needs to be removed and rearranged or edited.

To reinstall, you need to uninstall PKI Client and download PKI Client and then reinstall it. Let me remind you that when installing the Etoken client, all Etokens must be disconnected from the computer. After installation, the token should light up and Windows should install drivers for it and identify it. If you are undecided, try turning off all unnecessary tokens and leaving only that one. If that doesn't help, edit the registry. Open the registry editor. Go to the branch: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Calais

right click on it and select permissions

And set full Creator-Owner rights

Reboot should work. If it doesn’t appear, write to me and we’ll think about it together. This is how the problem that Etoken is not visible in the PKI Client is simply solved.

To work correctly in the EGAIS system, you need to gain access to the organization’s personal account on the official website. Already at this stage, many users encounter serious problems. One of them is that the EGAIS website does not see the key.

Most likely reasons

There may be several reasons for this problem to occur. Most often, the token cannot be found due to technical problems with the computer, lack of drivers or necessary add-ons. How to solve each of these problems?

Invalid media inserted

Many entrepreneurs confuse the jacarta key with an electronic signature for filing declarations with the FSRAR, and try to log into their personal account using the latter. There are several ways to check whether you inserted the correct media.

  • Examine the electronic signature certificate issued by the certification center. It must indicate the serial number of the type JC-xxxxxxxxx and the media type Jacarta PKI/GOST.
  • open Jacarta Unified Client. If the flash card is detected, but the connected tokens are not displayed in the program window, you are probably using the wrong media.

If you haven't purchased egais yet, where can you get jacarta with an electronic signature? Contact the certification center in your region that is authorized to sell CEPs of this type.

The driver for the egais hardware key is not installed

Perhaps you are trying to use egais key, driver which has not yet been installed. When you connect to jacarta for the first time, the main programs are automatically installed. This is a standard procedure for any new flash card and takes from 1 to 5 minutes.

After installation is complete, a notification indicating successful completion appears in the lower right corner.

Do not try to log into your personal account before the drivers appear - your computer has not yet established a connection with the electronic signature at this moment!

"Unified Jacarta Client" is not installed

The program was released by the token developer and is required to be installed. You can download it and other drivers for secure media on the website of the Aladdin - RD token manufacturer.

USB port doesn't work

There are two solutions:

  • Insert the token into another port and start the scan again;
  • check that the USB port is working properly.

To check, connect any other working flash card to USB. If it is also not detected, then the problem is in USB. Contact your organization's technical specialist or repair person.

When the Jacarta media is correctly inserted into the computer, an indicator on its case lights up. Depending on the model, it may be green or orange. If the indicator is off, then the key cannot be found by the egais because it is not connected.

The Rutoken EDS 2.0 add-on is disabled

When you try to log in, a message about the Rutoken web authentication library add-on may appear at the bottom of the browser screen. This software is provided by FSRAR, is safe and is necessary for correct operation of the site. To run, click “allow” in the pop-up window, and then repeat the check again.

How to use the EGAIS hardware key correctly?

So, the first problems are solved, and you have successfully logged into your personal account. How to avoid repetition of such situations? Insert the EPC only for work and do not use it at other times to prevent the media from overheating. Before starting work, always check the indicator - it signals that the token is working correctly.