Electronic digital signature (EDS) has long ceased to be the prerogative of desktop computers. Today, entrepreneurs, civil servants and even individuals actively use smartphones to sign documents, participate in tenders or work with government service portals. But if the process of installing a certificate on a PC has been worked out for years, then questions often arise. Why can't I see the certificate from the flash drive on my phone? How to connect Android devices Questions often arise. Why can't I see the certificate from the flash drive on my phone? How to connect Rutoken via OTG? Is it possible to do without additional software?
In this article we will look at three officially supported methods for installing digital signature on Android, including working with external media (eToken, JaCarta), cloud services and built-in OS tools. We will pay special attention to typical errors due to which the system does not recognize the certificate, and ways to eliminate them without contacting technical support.
Important: the procedure depends not only on the phone model, but also on the type of digital signature (qualified/unqualified), as well as on which certification center issued the certificate. If you work with state portals (for example, Government Services or Rosreestr), check whether your phone supports GOST R 34.10-2012 - without this, the signature will not be valid.
1. Preparing your phone: what you need to check before installing the digital signature
Before you begin installation, make sure that your smartphone meets the minimum requirements. Even if you are using a flagship model, some parameters may block work with digital signature.
First, check Android version. A qualified digital signature requires Android 9.0 and higher - earlier versions do not support cryptographic algorithms approved in Russia. You can find out the version in the menu Settings โ About phone โ Android version.
Secondly, if you plan use external media (for example, Rutoken S or eToken), make sure that the phone supports USB OTG. It's easy to check: connect a regular flash drive through the adapter - if it is detected, then OTG works. Some models (especially budget ones) may require additional power via USB hub.
The third prerequisite is the presence of root certificate of the certification authority are most often usedthat issued your digital signature. Without it, the system will not be able to verify the signature. The list of trusted centers in Russia is published Ministry of Telecom and Mass Communications, but in practice, certificates from UC SKB Kontur, Tensor or Kaluga Astral.
- ๐ฑ Android version: 9.0 or later (for a qualified digital signature).
- ๐ OTG support: required for working with external media.
- ๐ CA root certificate: must be installed in the trusted certificate store.
- ๐ถ Internet connection: will be required to download additional modules (for example, CryptoPro CSP).
โ ๏ธ Attention: On some models Huawei and Honor without Google services (HMS), installation problems may occur. CryptoProIn this case, use alternative applications, for example, ViPNet CSP or Signal-COM CSP.
2. Method 1: Installing digital signature from external media (Rutoken, eToken, JaCarta)
This is the most reliable method if you are working c qualified digital signature โsuch a certificate is stored on a secure USB token and cannot be copied. For Android you will need OTG adapter (or cable USB-C โ USB-A) and special software.
First of all, install the application to work with the token. For Rutoken this is the official application Rutoken EDS (available in Google Play), for eToken โ eToken Mobile, for JaCarta โ JaCarta Authenticator. After installation, connect the token to the phone via OTG.
Next follow the instructions:
- Open the token application and wait until the system detects the device.
- Enter the PIN code for the token (by default it is often used
12345678or11111111, but it needs to be changed the first time you connect). - Select a certificate from the list (if there are several of them on the token).
- Click โInstallโ or โExport to the systemโ - the wording depends on the application.
If the certificate is not displayed, check:
- ๐ Is the token connected correctly (try another OTG cable).
- ๐ Is the token software updated (for Rutoken current firmware -
v2.50and higher). - ๐ฑ Is your phone compatible with the token (the list of supported models is on the manufacturer's website).
OTG adapter connected|Official software for the token installed|Token unlocked (PIN entered)|The certificate is visible in the application list-->
โ ๏ธ Attention: Some tokens (for example, Rutoken S) require prior activation on a PC before use on Android. If you see an error when connecting "The device is not initialized", connect the token to the computer and complete the setup via CryptoPro CSP.
3. Method 2: Installing a digital signature via a file (.pfx or .p12 container)
If your certificate is stored in a file (usually with the extension .pfx or .p12), it can be imported directly into the Android storage. This method is suitable for unqualified digital signature or temporary certificates.
To install, follow these steps:
- Copy the certificate file to your phone (for example, via Google Drive or
USB cable). - Open
Settings โ Security โ Advanced โ Encryption and credentials โ Install from storage. - Select the certificate file and enter the password (if it was set during export).
- Specify a name for the certificate (for example,
"EDS for State Services") and click "OK".
After installation, the certificate will appear in the list User CredentialsTo use it to sign documents, you will need an application with EDS support, for example:
- ๐ CryptoARM โfor working with PDF and office files.
- ๐ Kontur.Diadoc โfor electronic document management.
- ๐๏ธ Government services โ for authorization and signing of applications.
If you see an error during import "Invalid file format", check:
- ๐ Are you entering the correct password (case matters!).
- ๐ Is the file damaged (try opening it on a PC).
- ๐ Is the format compatible with Android (some CAs issue certificates in
.cerwhich are not import as a personal key).
If you often work with digital signatures, create a backup copy of the file .pfx in a cloud storage (for example, Yandex.Disk or Google Drive) with two-factor verification enabled. This will protect you from losing the certificate when resetting. phone.
4. Method 3: Cloud digital signature (without a token and files)
Some certification centers offer cloud digital signature certificateswhich do not require a physical medium, and you. only confirm the action via SMS or push notification. This method is convenient for one-time operations, but is not suitable for working with state portalswhere a qualified digital signature is required.
To use cloud EDS:
- Install the official application of your CA (for example, Contour.EDS or Tensor.EDO).
- Log in to the application (you will need a login/password from your personal account on the CA website).
- Generate a certificate in the cloud (usually this is done in the section
"My certificates"). - When signing the document, select the option
"Cloud EDS"and confirm the action.
Advantages of the method:
- โ๏ธ There is no need to buy a token or transfer files.
- ๐ The certificate is automatically renewed (there is no risk of expiration).
- ๐ฑ Works on any Android device, even without OTG.
Disadvantages:
- ๐ซ Not suitable for qualified digital signature (only for unqualified ones).
- ๐ Requires a stable Internet connection.
- ๐ฐ Often paid (tariffs depend on the CA).
| Installation method | EDS type | OTG required | Cost | Complexity |
|---|---|---|---|---|
| External token (Rutoken) | Qualified | Yes | From 1,500 โฝ per token | Average |
File .pfx/.p12 |
Unqualified | No | Free | Low |
| Cloud certificate | Unqualified | No | From 500 โฝ/year | Low |
| CryptoPro CSP + token | Qualified | Yes | From 2,000 โฝ (license + token) | High |
โ ๏ธ Attention: When using a cloud digital signature, make sure that the CA application has a valid security certificate. Check. this is in Settings โ Applications โ [Application name] โ Permissions. If an application requests access to SMS or contacts without explanation, this may be a sign of fraud.
5. Setting up CryptoPro CSP on Android (for a qualified digital signature)
If you work with state portals (for example, Rosreestr, Federal Tax Service or EGAIS), most likely you will need CryptoPro CSP - Russian cryptographic software that supports GOST R 34.10-2012. On Android it works through a separate application CryptoPro EDS Browser plug-in.
The installation consists of several stages:
- Download and install CryptoPro CSP from Google Play (the application is paid, the license cost is from
1,200 โฝ/year). - Connect the token via OTG and wait for it to be detected in the application.
- In the settings CryptoPro select
"Install license"and activate it (the key is sent to your email after purchase). - Restart your phone.
After installation, check the operation of the digital signature:
- Open a browser (recommended Yandex.Browser or Google Chrome).
- Go to the test portal (for example,
https://test.gosuslugi.ru). - Try to sign a test document - if everything is configured correctly, the system will prompt you to select a certificate from the token.
If the signature is not works:
- ๐ Check that the root certificate of your CA is installed in CryptoPro CSP The root certificate of your CA is installed.
- ๐ฑ Update the application to the latest version (the version is current in 2026
5.0.12345and higher). - ๐ Make sure that the certificate on the token has not expired.
What to do if CryptoPro does not see the token?
1. Try another OTG cable (some cheap adapters do not transmit data).
2. Connect the token to the PC and check it through CryptoPro CSP for Windows - if it is not detected there, the problem is in the token itself.
3. data-i="262">on the phone, having previously saved the license key. CryptoPro on your phone, having previously saved the license key.
4. Check if the antivirus is blocking the operation of the token (for example, Dr.Web or Kaspersky).
6. Typical errors and their solutions
Even with the correct installation of digital signature on Android, failures may occur. Here are the most common problems and ways to solve them:
Error: "Certificate is not trusted"
Cause: the system does not have a root certificate from the certification authority.
Solution: Download the root certificate from the website of your CA (usually it is available in the section "Support") and install it manually via Settings โ Security โ Install from storage.
Error: "Unable to sign the document. Key not found"
Cause: the certificate is installed, but the private key is missing (for example, if you imported only .cerfile without .pfx).
Solution: Export the certificate with the key to your PC (via CryptoPro or CrystalCP), then transfer .pfxthe file to your phone and import it again.
Error: "Token not found"
Cause: problems with OTG connection or drivers.
Solution:
- Try another OTG adapter (preferably the original one from the phone manufacturer).
- Connect the token to a charged USB hub (some tokens require additional power).
- Update the token firmware via a PC.
Error: "The application does not support this type of certificate"
Reason: the software used (for example, Contour.Diadoc) does not work with GOST R 10.34-2012.
Solution: Install alternative software that supports Russian encryption standards (for example, ViPNet CSP or Signal-COM).
If you see an error when signing a document on the public services portal, first check that your certificate was issued by an accredited CA. The list of trusted centers can be found on website Ministry of Telecom and Mass Communications in the "Accredited Certification Centers" section.
7. Security: how to protect the digital signature on your phone
Installing an digital signature on a smartphone simplifies the work, but also increases the risks. If the phone is lost or hacked, Fraudsters will be able to sign documents on your behalf. To avoid this, follow the rules:
1. Set up a screen lock
Use PIN code at least 6 characters long or fingerprintAvoid a pattern - it can be easily seen in Android settings. enable the option "Erase data after 10 unsuccessful attempts".
2. Encrypt the certificate storage
If you imported the digital signature from file .pfx, make sure that it is protected with a strong password (at least 12 characters using letters, numbers and special characters). Do not store the password in notes on your phone!
3. Use a separate profile for work
On Android 11 and higher you can create one work profile (via Settings โ Accounts โ Add profile). Install the digital signature only in the work profile and limit access to it.
4. passwords
In the browser and applications, disable saving the password for the certificate. To do this, go to Settings โ Google โ Autofill โ Passwords and delete the saved data for the digital signature.
5. Regularly check the activity of the certificate
In the personal account of your CA, you can view the history of using the digital signature. If you see suspicious actions (for example, signing documents in your absence), immediately revoke the certificate.
- ๐ Password from token: change it once every 3 months.
- ๐ฑ Backup: store a copy of the certificate in an encrypted container (for example, VeraCrypt).
- ๐จ Remote erasure: set up the function
"Find device"from Google to erase data from the phone in case of theft.
โ ๏ธ Attention: Never transfer your token or file .pfx to third parties, even if they claim that they need to โverify the signatureโ has the same legal force as a handwritten signature. documents!
FAQ: Frequently asked questions about digital signature on Android
Is it possible to use one digital signature on a phone and a computer at the same time?
Yes, if the certificate is stored on external token (for example, Rutoken). Simply connect the token to the desired device via USB. If the digital signature is in a file (.pfx), copy it to both devices, but remember that this is less secure.
There are no restrictions for cloud certificates - you can log in to the CA application from any device.
Why when signing a document does the error "Invalid data format" appear?
This error occurs if:
- The document file is damaged (try opening it on a PC).
- You are using the wrong application for signing (for example, you are trying to sign
.docxvia CryptoARM, which only works with.pdfi.xml). - The certificate is not intended for this type of document (for example, digital signature for State Services is not suitable for EGAIS).
Solution: check the file format and compatibility of the certificate with the portal on which you are signing the document.
How to transfer digital signature from one phone to another?
The method depends on the type certificate:
- Token (Rutoken, eToken): just connect it to the new phone via OTG. No additional actions are required.
- File
.pfx: copy it to the new phone (for example, via Google Disk) and import into the certificate store. - Cloud certificate: log in to the CA application on the new device - the data is synchronized automatically.
Important: after transferring, delete the certificate from the old phone, especially if you are selling it or transfer to another person.
Is it possible to sign documents from a phone without the Internet?
Yes, but with reservations:
- If the digital signature is on token, the Internet is not needed - the signature is generated locally.
- If the digital signature is in file
.pfx, connection is also not required. - If you use cloud certificate, the Internet is required - without it, the application will not be able to confirm the signature.
Please note: some portals (for example, Government Services) may require online verification even for local certificates.
What to do, if the EDS has expired?
You cannot renew the certificate - you need to issue a new one. To do this:
- Contact your certification center (usually this can be done through your personal account on their website).
- Pay for the renewal (the cost depends on the type of EDS and CA, on average). from
500 โฝto3 000 โฝ). - Get a new certificate and install it on your phone in the same way as before.
Important: the old certificate is automatically revoked after expiration, so documents signed by it may be invalid.