Plugin for work with state purchases. How to set up CryptoPro for government purchases. Setting up a work place for participation in electronic trading. Installation of CryptoPro CSP

As of March 2, 2018, in the special office of the deputies behind Law No. 44-FZ, when placing records, you may receive a blocking message: “There was a cancellation when placed, try again: “signCadeBES” is not assigned.” through incorrect adjustment of the work environment. To disable the blocking notification when publishing reports, it is recommended to configure the workspace settings according to step 6 of the Instructions for installing and configuring the “CryptoPro UDS Browser plug-in” component, available by request:

In the leaking window in the Internet browser Internet Explorer If you are asked to allow the download, you must allow the launch of the download by clicking on the "Allow" button. If the plugin is working correctly, when you go to the page, an access confirmation window will open. At the access confirmation window, click the “Yes” button.

Instructions for installing and configuring the component “CryptoPro EDS Browser plug-in” (Vityag)

5 Setting up the plug-in “CryptoPro EDS Browser plug-in”

For correct operation of the system in the ЄІІС in the Internet browser “Internet Explorer” with the use of the plug-in “CryptoPro EDS Browser plug-in” it is necessary:

  • Add the address of the Official EIS website to the list of disabled and trusted sites in the browser settings.
  • Try the robot in crazy mode (for Internet Explorer 10 versions and higher).

A detailed description of this is provided in the document “Instructions for setting up a work environment.”

For all browsers, it is necessary to add the address of the Official IIS website to the list of trusted nodes of the CryptoPro UDS Browser plug-in plug-in.

To check that the Official Website of the IEC adds the plug-in to the list of trusted sites, or add it to the trusted sites, open the shortcut “Adjusting CryptoPro UDS Browser plug-in” to the necessary Internet -browser.

For whom to press right button bear the shortcut “Setting up CryptoPro UDS Browser plug-in” and in the context menu select the item “Seek help”, then select the name of the required browser (Malyunok 5).

Malyunok 5. Select Internet browser in point context menu"Help with help"

In your Internet browser window, the page “Setting up CryptoPro EDS Browser Plug-in” (Malyunok 6) will appear.

Malyunok 6. Customization side of the plugin “CryptoPro EDS Browser Plug-in”

In the Internet browser “Internet Explorer” in the merge window, allow the following scripts and ActiveX elements, By clicking on the button “Allow blocked instead” (div. Malyunok 6).

On the page of setting up the plugin in the block “List of trusted nodes”, enter the address of the Official ЄІС website “http://zakupki.gov.ru” in the input field and click on the icon “”.

To save the added nodes, click on the “Save” button (Malyunok 7).

Malyunok 7. The page for customizing the plugin “CryptoPro UDS Browser Plug-in” with adding the address of the Official EIS website to the list of trusted nodes

6 Checking the work of the plug-in “CryptoPro EDS Browser plug-in”

To check the correct operation of the “CryptoPro UDS Browser plug-in” plug-in in your Internet browser, go to the page: https://www.cryptopro.ru/sites/default/files/products/cades/demopage/simple.html.

If the additions do not have installations or adjustments, the page looks like the representations are lower (Malyunok 8).

Malyunok 8. Side of checking the work of the plug-in “CryptoPro EDS Browser plug-in”. plugin unavailable

In the Internet browser “Internet Explorer” in the pop-up window, allow the launch of the plugin by clicking on the “Allow” button (Malyunok 9).

Malyunok 9. Internet browser window “Internet Explorer 10”. The draining window from the proposition allows the cob of the nadbudova

If the plugin is working correctly, when you go to the page, an access confirmation window will open (Malyunok 10).

Malyunok 10. Access confirmation window

In the window, press the “So” button, to click on the action - “No”.

Following the orders on the page, select the signing certificate, enter the data to check the work of the plugin and click on the “Sign” button (as necessary) (Malyunok 11).

Malyunok 11. Side of verification of robots CryptoPro EDS Browser plug-in. Attraction plugin, signature generated successfully

  1. Receive an electronic signature and an electronic signature request at the verification center.
  2. Install a signature and receive an electronic signature on work place.
  3. Set up your browser to work using an electronic signature.

For 44-FZ, auctions are held in electronic form, for 223-FZ and commercial trading - competitions, quotation, asking prices, etc.

Electronic signature and request for electronic signature

To obtain an electronic signature (certificate), you will need a token and an electronic signature.

A token with a USB connector is the most advanced form of electronic signature. The token can be exchanged for a number of signatures. Popular token brands in Russia: Rutoken, eToken and JaCarta.

Request for an electronic signature - this is a security program that can be used to create and verify electronic signature, Encrypt and decrypt information. The most extensive use of electronic signatures is CryptoPro CSP. Yogo vi was taken away at once with a token.

How to get a certificate?

Certificates confirm that SKB Kontur are suitable for all types of purchases, including those under 44-FZ, and for all types of work. To remove it you need:

How to set up a work place?

If you have a SKB Kontur certificate, the setup consists of five stages:

    Verifying that CryptoPro CSP is installed and working correctly

    Checking the settings of your token in the brand name:

    Rutoken
    - eToken
    -JaCarta

    The distribution of the electronic signature must have a support module for the required token, otherwise there will be a problem.

    Verifying the authenticity of electronic signatures

    Certificates with the same term will not be issued. A new electronic signature must be installed on your workspace in order to participate in electronic procedures.

    Verification of certificates accordingly,

    At your workplace, it is your responsibility to install a certificate in accordance with the center where you obtained the key. Otherwise, the error “Certificate of approval is unknown from the confirmation center” or “It is not possible to display the page” may appear.

  1. Checking your browser settings:

    • To participate in the electronic auction on most ETMs, you can only use Internet Explorer.
    • Checking your browser's powers
    • Checking your browser's overheads
      Nayposhirenisha nadbudova - CAPICOM. If there is no such thing, there may be amends. If the approval occurs at the registration stage, then ETM cannot remove the IPN of the recipient from the certificate, or it informs that the recipient does not have any valid certificates. Since the penalty occurs at the stage of entry into special office, Then the Maidan is blocking the post owner’s access.

Installation is simple, technical problems appears remotely. SKB Kontur guarantees the protection of confidential information.

When everything is sorted out

Once your work environment has been settled, register a new electronic signature on the electronic trading platform.

  • If you enter ETM first, you must undergo accreditation.
  • If you are already accredited for ETM, please follow the instructions to register an electronic signature.

In this article, I will look at all installation options and what components need to be installed for correct operation of the State Purchase portal. So what are Derzhzakupivli? This is a portal (website) for organizing web trading (competitions, auctions). To use this portal you will need the following software:

  • CryptoPro- Data encryption software. The license for this software must be purchased by your organization. Paid software. You can download the distribution kit version 3.6 from the official website CryptoPro.
  • token- key for the robot with the portal. Call such keys, they are named, and appear on the account. For example, if it is necessary to sign a document, the token of Ivan Ivanovich Ivanov is inserted and signed under his name.
  • PKIClient- Drivers for robots with USB token. Drivers are available.
  • The root certificate is certified by the center. .
  • Server certificate.
  • Sign plugin for Internet Explorer browser. The plugin is required to sign a document. When you click on the subscribe button, the plugin clicks on the software for binding the token. .
  • Microsoft. NET Framework - Which exact version is not clear. In Windows XP - 2.0, in Windows 7 it is also included in Windows components.
  • Lkomponent- So it’s just necessary for a signature. .
  • vcredist -Libraries are essential for work. for 64 bit Windows versions. for 32 bit.

After installing all components, reinstall and try to log into a special account and sign the required document.

What to do when making a bee: Can't sign data. Error description: The object does not support this power or method?

  1. To begin with, you need to check point by point, the installed components are assigned more. Once everything is installed, we verify that the Lkomponent and the Sign component are installed correctly, as this itself indicates that the signature has been verified.
  2. If you are using the operating system Windows 7 Or better yet, start and find Internet Explorer with the right button under the administrator.
  3. If you have a 64-bit operating system, then run 32-bit Internet Explorer itself.

Respect! The state portal only works in the browser Internet Explorer.

This article described what is most necessary for working on the portal simply and clearly, as in the official instructions, which you can see here - a lot of water and not required information. If this has helped you, please comment your thanks in the comments.

Registration of a new certificate on the Government Procurement Portal.

Log in to a special account using the old certificate or login and password.

If you have forgotten your password, see the explanation at the end of the document.

At the window "Registration data of the customer" in the upper right corner, click on the message "Register a UDS certificate"

In the window, under the "Insert file with new certificates" row, click the message "Look..."


In the "Select file to purchase" window, select the path to the file for the new certificate.


When you go to the file of the new certificate of approval, press the message “Zavantage”.


In the “Correspondent Registration Data” window, if you logged in using a certificate, then press the register button, if you logged in using a password, then enter the password in the “Password” row and repeat the password again in the “Password Confirmation” row register button


If the certificate registration is successful, a notification appears.


Renewing the password on the Government Purchase Portal.

If you have forgotten your password, then you need to press the message “Forgot your password” in the menu for entering the “Special Account”


In the window you need to enter your account username and prompt on the control panel to “enter the operation confirmation..” and click the “Submit password” button.

If the picture is not visible or through the wrong result control nutrition does not recognize, to refresh the window, press the “F5” key on the keyboard.


After completing the operation, you will be sent a sheet with a timely password and instructions to enter the site to the email address you provided when registering as a customer on the site.

18 April 2017 at 23:30

We go to the special account at zakupki.gov.ru without Internet Explorer and others for the sake of the cinnamon when working with CryptoPro

In this note, I will try to find out about the reliable crypto provider CryptoPro for access to the closed part of the official website of the unified information system in the procurement sector (zakupki.gov.ru) and the website of government services (gosuslug i.ru). The cryptoprovider itself has already become a de facto standard for governments, in which format the digital digital signature appears, for example, which is certified by the center (CA) of the Federal Treasury or the CA of the Ministry of Health.

In the future, I’ll tell you about the site zakupki.gov.ru. The special account of this site is only accessible via HTTPS using GOST encryption algorithms. Long time HTTPS via GOST was performed only in Internet Explorer, which relied entirely on the crypto provider. The unraveling came not so long ago, when support for older versions of IE, including IE8, was added to the site zakupki.gov.ru. The trouble is that IE8 - old version This browser is supported in Windows XP, and national installations are usually quite conservative in terms of licensing. With this rank, a large part of the koristuvachs immediately appeared “overboard.”

Fortunately, the CryptoPro company is releasing a special collection Firefox browser under the name CryptoPro Fox (CryptoFox), which supports GOST algorithms and works, of course, only in connection with a reputable crypto provider. There were hours until the development of the compilation completely stopped, but new versions were released regularly. The remaining collection is based on Firefox 45. You can download collections, available versions under Windows, Linux and Apple OS X.

The English version of the browser is available upon request. For this localization, it is necessary to import the package with the transfer of the interface. Please note that the version of the package depends on the version of the browser itself.

After installing the package you need to open it new tab, Type about: config there, and enter general.useragent.locale in the list of parameters and change the value from en-US to ru-RU. After restarting the browser, the interface will be in Russian.

Now you can put the root certificate of the Federal Treasury in the "Trusted Root Certification Centers" folder, and the personal certificate of the employee in the "Specialties" folder, restart the browser and go to the special account zakupki.gov.ru according to 44-FZ.

My work station does not have the latest certificates installed, so I have access to a special security office. However, encryption of communications in any case is carried out by an algorithm of the GOST family.

If you have access to the closed part of the site under 223-FZ, authorization will go through ESIA (or through the site gosuslugi.ru). Here the situation will be easier, since this site has a plugin for Firefox for a long time and is being released by Rostelecom. When you first visit the site, we will be prompted to install the plugin. After installing the plugin, switch to the “Enable first” mode in the CryptoFox settings, otherwise the support services website will NOT display the certificate.

Unfortunately, signing documents on the website zakupki.gov.ru is implemented through a specific sing.cab component, which is a virtual ActiveX technology. Naturally, this component is not available in CryptoPro, so we will look forward to the transition to more advanced technology. Fortunately, the signing of the document is only a small part of what the operator is responsible for during the hour of work on zakupki.gov.ru, so for everyday operations CryptoFox can be completely used.

Sometimes it may be necessary to save a copy of the private key on local computer. It is possible to earn, as the key is created in the CA of meanings as vivantage. The copy is generated using the “Copy” button (as an unsubscribed one) in the interface of the CryptoPro applet


There are two options for saving a key on a local machine - in the "Register" and on a virtual machine to the great disk. In principle, the security of saving the key in both cases is approximately the same, so the choice of key is left to the reader.

For "Register" readers, the keys are stored in the gallery

HKLM\SOFTWARE\Crypto Pro\Settings\Users\\Keys
for koristuvach and in galuzi

HKLM\SOFTWARE\Crypto Pro\Settings\Keys
for the computer in general.

For a 64-bit OS, the steps will be slightly different:

HKLM\SOFTWARE\Wow6432Node\Crypto Pro\Settings\Users\\Keys
і

HKLM\SOFTWARE\Wow6432Node\Crypto Pro\Settings\Keys

When running CryptoPro on a terminal server, the account manager may not have the right to write the key to the target, since the fragments are not in the account manager’s profile. This situation can be corrected by assigning exclusive rights to the files through the Regedit utility.

CryptoPro looks for key containers on disks that contain the “significant” attribute, so that a flash drive or, God forgive me, a floppy disk will be included in the key containers, but a edge drive or a disk forwarded via RDP will not. This allows you to save keys on floppy disk images using the principle of one key - one floppy disk, thereby increasing security. To create a virtual disk drive, you can use the utility

PREPARATION

Before installation, make sure that the user has local administrator rights on the computer and has an anti-virus program running.
Unique vikoristanya key noses ( RuToken, EToken) Until the software installation is completed.
IN operating system Windows 7 all files it is necessary to run as administrator.

1. Checking the availability of installed programs.

Before connecting the key device, check the availability of the driver for Token and CryptoPro programs.

To check the availability of the program, open Start → Control Panel → Programs and Accessories.

In the list installing their programs there may be a presence: CryptoPro CSP:

For the key item in the list of installed programs, the culprits are present drivers:

For eToken:

For Rutoken:


If necessary, install the driver following additional instructions: How to set up Rutoken?

If CryptoPro is not installed, go to the next step

If you are a product of the installations, go to the following:

2. Installation of CryptoPro CSP

Cancel the installation if it is not installed on your computer software product CryptoPro CSP or when changing the program version. To enter a new serial number div. pp. Below - “Activation of CryptoPro CSP programs”.

We are grateful that in 2018 the sale of versions 3.6 and 3.9 was announced due to the transition to GOST R 34.11-2012. It is important to note which version you are licensed for.

  • Download and install the CryptoPro file of the versions specified in the license (3.6, 3.9 or 4.0)

Activation of CryptoPro CSP programs

Without entering the serial number, the CryptoPro program processes the terms (1-3 months after the first installation) and continues its work until there are no entries. serial number software product.

preparation

Prepare a license for CryptoPro CSP. The license looks like it's up to date:

Entering the serial number

Login to the program CryptoPro CSP: (Start → Settings → Control Panel → CryptoPro CSP or Start → Control Panel → CryptoPro CSP)

Select tab underground and press the button introduction of license.

At the window, enter Serial number of CryptoPro(Specified in the license) and click OK.


4. Establishment of a special Certificate

Verifying the presence of the certificate in the container

Before installing a special certificate from ruToken or else eToken it is necessary to verify the presence of the certificate in the container, for which:

run the program CryptoPro CSP: (Start - Settings - Control Panel - CryptoPro CSP or Start - Control Panel - CryptoPro CSP)

Close the tab "Service" and press the button “Look at the certificates in the container”

"Looking Around"


Select the container that needs to be checked for presence in the new certificate and click the button "OK"

After that, in the field "Name of the key container" enter the name of the container, press the button "Dali"


When the “Enter container pin code” window appears, you must enter the carrier pin code.
Pin code for registration: 12345678

How to contact me in advance “The private key container **** has a daily certificate of a private encryption key”, This means that there is a special certificate in the container.


When the window opened “Certificate for review” This means that there is a special certificate in the container and you can install it.

Export of a special certificate

To install a certificate, press the button "Vlastivosti"


at the deposit "Stock" press button "Copy to file..."

"Dali"


To confirm the copy, press the button "Dali"


To confirm the copy, press the button "Dali"


"Look..."


1. Select work table

2. Write a file name For example: “Certificate”


To confirm the copy, press the button "Dali"


To confirm the copy, press the button "Ready"


After that, when Export will appear, click the button successfully "OK"

Installation of a special certificate

Close the tab "Service" and press the button “Install a special certificate...”

At the window, press the button "Looking Around"


  • Select Work table
  • Select savings certificate
  • Press button "Vidkriti">



Press the button on the next window "Looking Around"


  • See your container
  • I press the button "OK"

Press the button on the next window "Looking Around"


  • Select storage "Specialties"
  • I press the button "OK"

Press the button on the next window "Ready"


Certificate installation completed successfully

3. Installation of intermediate and root certificates

automatic installation

Automatic installation of certificates requires additional programs

CertToTrust.exe.

Save the program to your computer and run it. The program will automatically install certificates

Certificates of the Testing Center have been installed

5. Checking the correct installation of certificates

To verify that the certificates are installed correctly, you must:

  • come in Start → Settings → Control Panel → Power View or Start → Control Panel
  • Make sure that the Control Panel is displayed in the Classic view.
  • In the list of programs you can find the label Powerful Review (div. Malyunok)

Go to tab zmist and press the button certificates

View your certificate and click the button Pereglyad


Go to tab certification routes

Your certification plan must have 3 certificates:

  1. Certificate of the root trusted center
  2. Certificate of Interim Trusted Center
  3. Your Certificate

Installation of software and certificates is completely completed

If the certificates trusted by the root authority and the intermediate trusted authority are not displayed, this means that the certificates were installed incorrectly or not installed.
In this case, repeat step 3.

Participation in government purchases, which are carried out in electronic form and are displayed in a single information system It becomes impossible without the presence of an electronic digital signature (hereinafter referred to as EP). At the same time, the presence of the EP from the deputy or the Vikonavian is not seen in addition to the statement: “The state has purchased a certificate of keys for verifying signatures.” Let's try to figure it out.

The main benefits that arise before organizing the process of conducting public procurement in electronic form from the EP regulations are regulated by Article 5 of Federal Law No. 44, dated 5th quarter 2013

Apparently the key ones are:

  • transfer and exchange of electronic documents in the field of public procurement, Submission of applications for participation in them, the selection of negotiations and the signing of contracts is only permitted if it has been signed by an authorized EP;
  • EP keys, And also certificates of keys for verification of signatures are issued by special organizations called certification centers (hereinafter referred to as CA);
  • TC goiters undergo accreditation;
  • Unified benefits regarding the security of certificates and keys, Both in the EIS and in the electronic Maidans, the right to establish a federal body of power regulation in the field of purchasing.

It is impossible not to guess about those who are participating in the state purchase of vikorysts in the EP of goiters:

  • ensure the confidentiality of keys;
  • don't allow abuse of power electronic keys without them by third persons;
  • In case of violation of confidentiality, inform about this CA, which type of certificate is valid for 1 business day;
  • It is important to assume that the security of the key is broken, do not use it to verify the EP.

Features of the EP installation process

Having learned about the nutrition for which it is necessary and what the duties of the Vlasnik EP are, let’s move on to the most important nutrition, and how to learn about it in practice and how to install a certificate for the purchasing power.

In order to fully use the EP in the robot on the official website of the IIS, you need to create a number subsequent actions, Without them, the robots with the key will be impossible.

Actions like this:

  1. customize your browser, From a security point of view, and adding the official government portal to the list of trusted nodes.
  2. Installation of a cryptoprovider.
  3. Installing a certificate.

At first glance, you might think that it is complicated and technically “confusing”, but in practice this is not the case at all. Let's try to transfer to Tsoma.

First stage

Setting up security settings begins when the protocol is enabled in the browser TLS encryption. In the photo below there is a butt pointing, as you can see in the Internet Explorer menu.

After what you need to confirm your security digital signatures Otherwise, to confirm their authenticity, install the server and CA certificate.

What is needed for:

  • import the desktop settings files from the official portal and install the root certificate of the purchasing authority by opening the file with the extension *.cer

Please! Since the certificate type is PKCS # 7, for this installation you need to open the file with the extension *.p7b.

  • Follow the steps similar to those described above to install a server certificate;
  • place all certificates in the folders specified in the Master for importing certificates “Trusted Root Certification Authorities”;
  • add the ЄІІС site to the list of trustees, indicating that it is in the browser’s authorities (the marvelous butt is lower by the smallest).

Other and third stage

With authorization, signature and data electronic document What kind of legal force these signatures will have is established special program, Named as the crypto provider CryptoPro CSP. For which the installation package of programs is launched on the reader’s computer, all necessary fields will be filled in, confirmed by the consent of the licensee and the types of readers are specified, and denials are avoided mani keys.

Z reporting instructions You can find it on the software manufacturer's website. The remaining time is when the certificate is installed in the CryptoPro CSP program.

In order for the government to purchase a root certificate for installations, it is necessary to complete a number of actions:

  • insert the storage device into your computer to save the certificates;
  • Open file with extension *.p7b;
  • standing on required file special certificate select menu item
  • "Export". The butt of the indications on the little one is lower.

  • indicate the place to save the certificate and your name and complete the operation;
  • Install the CryptoPro software and install a special certificate in the “Service” tab, as shown below.

Respect! The system will predict the end of the term of the EP in automatic mode.

What else do you need to know about the EP?

Electronic keys for participation in public procurement are available from the CA only to Vikonavians/postholders. In order to participate in purchases, government officials (government authorities) only issue EP in the centers of the Treasury of the Russian Federation.

The procedure for retrieving keys by participants of the purchase at the offensive center:

  • save your application;
  • submit the necessary package of documents;
  • pay for service;
  • select the ready-made EP kit.

Slide indicate what is in present moment In order to maximize the reliability of their clients, CAs are encouraged to fill out an application online. Why bother with the package of documents?

As a butt, we will transfer documents for participants - entrepreneurs (IP):

  1. Certificate of sovereign registration of IP and IPN;
  2. Statement of registration from the Unified State Register of Individual Entrepreneurs (USRIP), issued no earlier than 30 days ago;
  3. Entry passport;
  4. SNILS;
  5. Power of attorney for withdrawal (if it is not the individual entrepreneur himself who will issue the coupon).

Respect! Term of action EP - 1 rik, after the completion of any track, re-release.