Mobile device users are often faced with the need to work with documents protected by an electronic signature. A file with the extension .sig on Android cannot be opened using standard system tools, since it is not an independent document, but a container for a cryptographic signature. Many smartphone owners mistakenly believe that this is an image or an archive, trying to run it through a gallery or file manager, which leads to a format error.

In fact, the extension .sig (from English signature) indicates a digital signature file that is inextricably linked with the original document. Without special software that can work with cryptographic algorithms, it is impossible to view the contents of such a file. In the article we will analyze in detail what applications are needed to work with CryptoPro and Federal Tax Service certificates on the mobile platform.

The situation is aggravated by the fact that the Android ecosystem is less focused on working with domestic encryption standards compared to desktop versions of Windows. However, thanks to the development of mobile banking and government services, solutions have emerged that allow you to verify the authenticity of documents directly from your phone. Next, we will look at specific tools and action algorithms.

What is a .sig file and how it works

File .sig is a binary container containing encrypted information about the author of the document, the time of signing and the verification key certificate itself. It does not store text or images, but only confirms that the main file (for example, PDF or XML) has not been changed after approval. On a device, such a file weighs only a few kilobytes.

There are two main types of forming such signatures: attached and detached. In the first case, the signature is embedded inside the document, and a separate file .sig is not created. In the second, a separate file is generated, which should be in the same folder as the original and have an identical name, except for the extension. The .sig file is useless without the original document to which it refers.

To correctly process data on a smartphone, you need to understand the structure of certificates. Often, users receive archives from the tax or banking systems, where files are located .xml.sig or .pdf.sig. An attempt to rename the extension manually will not work, since the internal byte structure will remain encrypted with the GOST cryptographic algorithm.

⚠️ Warning: Never try to open a .sig file in a text editor or notepad. You will only see a set of strange characters, and in rare cases this can damage the file encoding if accidentally saved.

Working with such objects requires having a root certificate from a certification authority installed on the device or application. Without a trusted root certificate, the system will not be able to verify the chain of trust and confirm the legitimacy of the signature. This is an important aspect information securitythat cannot be ignored when working with government data.

The market for mobile solutions for working with electronic signatures in Russia is formed by several key players. The company is the leader CryptoPro, whose products are the de facto standard for interaction with government information systems. A specialized application is available for Android users that allows you to perform basic operations with cryptography.

In addition to commercial solutions, there are free utilities from tax authorities and banks. For example, the Tax Federal Tax Service application has built-in modules for working with data formats used in declarations. However, for universal scanning of arbitrary files, it is better to use specialized software that supports various container formats.

  • 📱 CryptoPro CSP is a powerful cryptographic information protection tool that requires a license for full operation.
  • 🔍 CryptoARM Go is a mobile version of a well-known tool for encrypting and signing files, convenient for quick checks.
  • 🏛️ Federal Tax Service application — allows you to view specific reporting files, but has limited functionality for general tasks.

When choosing a app, you should pay attention to the version of the operating system of your smartphone. Some cryptographic modules require certain security libraries that are only present in recent versions of Android. Old devices may not support the necessary encryption algorithms at the hardware level.

📊 What type of files do you most often receive with the .sig extension?
Tax documents (XML)
Agreements and acts (PDF)
Banking extracts
Other government documents

Instructions for installing CryptoPro on Android

To fully work with signature files, you must install a certified cryptographic information protection tool (CIPF). The installation process on a mobile platform has its own characteristics compared to a PC. First, you will need to download the installation package from the official website of the developer or from the Google Play store, if the version is available there.

After running the installer, the system will ask for permissions to access the key store and file system. This is necessary so that the application can read private key containers if you plan to not only verify but also create new signatures. In your phone's security settings, you may need to allow installation from unknown sources.

☑️ Installation of cryptographic software

Done: 0 / 4

The key step is to import the certificates. You need to add the root certificates of the certification authorities that issued the signature. This is done through the app settings section or through the system menu Settings → Security → Encryption and Credentials. Without this step, signature verification will end with the error “Certificate not found” or “Untrusted issuer.”

⚠️ Attention: The interface of the security settings menu may differ depending on the smartphone model (Samsung, Xiaomi, Huawei). If you do not find the “Encryption” item, use the search in settings.

After installing all components, it is recommended to perform a test scan. Create a simple text file and try to sign it using the installed key. If the process is successful, then the environment is ready to work with incoming files .sigreceived from contractors or government agencies.

How to open and check a file manually

Let's consider the algorithm of actions when receiving a file with a digital signature by email or messenger. First, save the file .sig and the original document (for example, dogovor.pdf) to the same folder on your internal drive. This is critical for the operation of most scanning apps.

Run the installed application, for example CryptoARM Go. From the main menu, select the “Verify Signature” or “Verify Signature” option. Using the file manager inside the application, specify the path to the source document. The app will automatically try to find a signature file with the same name in the same directory.

File path: /storage/emulated/0/Download/Docs/dogovor.pdf

If the automatic search does not work, select the option to manually download the signature file. After processing the cryptographic request, the application will return the result. The “Signature is correct” status means that the document has not been changed and is signed with a valid certificate. The "Error" status may indicate that the key has expired or data integrity has been compromised.

💡

If the application says "Certificate Revoked", check the relevance of the revocation lists (CRLs) in the app settings or contact the sender of the document.

In some cases, you may need to enter the PIN code from the private key container if you are performing a decryption or re-signing operation. For simple verification of visual content, this is usually not required; the presence of public keys in the system is sufficient.

Compatibility table of formats and apps

Not all applications support the same set of algorithms and container formats. Below is a summary table that will help you choose a tool for a specific task. Please note the support for the format CAdES, which is often used in legally significant document flow.

Appendix GOST support Working with PDF License
CryptoPro CSP Full Yes Paid
CryptoARM Go Full Yes Freemium
Tax Federal Tax Service Limited XML only Free
ViPNet CSP Full Yes Paid

As can be seen from the table, for one-time document checks from the tax office, free specialized software may be enough. However, to work with contracts in PDF format and complex chains of certificates, you will need a full version CryptoPro or an equivalent. The choice depends on the frequency and type of your tasks.

💡

For a one-time check of documents from government agencies, free utilities are often sufficient, but for constant document flow, a licensed version of CIPF is required.

Solving common problems and errors

One of the most common problems is the message that the certificate has expired. This happens if the signing key was issued more than a year ago (for individuals) or three years ago (for organizations). In this case, the file .sig is technically sound, but the legal validity of the signature may be in question without confirmation of the status at the time of signing.

Another common error is related to the lack of a trusted root certificate. If you downloaded a file from a new counterparty, its certification authority may not be pre-installed on your system. You must request a chain of certificates from the sender and import them manually into the application storage.

⚠️ Attention: Rules for using electronic signatures and requirements for certificates may change. Always check the current software requirements in your personal account of the tax authority or on the State Services portal.

Users are also faced with the problem of incompatible versions of the signature format. Old files created according to the CMSstandard may not open in new versions of apps targeting CAdES BES. In such cases, using the desktop version of the software or online verification services helps if the confidentiality of the data allows you to upload the file to the cloud.

What to do if the application crashes when opening?

Try clearing the application cache in the Android settings. If this does not help, uninstall and reinstall the latest version of the software, making sure that there is enough free memory on your phone.

Frequently asked questions (FAQ)

Is it possible to rename a .sig file to .pdf to open it?

No, that won't work. The .sig file contains only the cryptographic signature, not the document itself. Renaming will not change the internal data structure and you will get a format error or an empty file.

Is it safe to open such files on someone else's phone?

Viewing the signature is safe as it does not require entering your personal PIN. However, do not save other people's private keys on other people's devices and always delete temporary files after verification.

Why can't a file open on iPhone if it opened on Android?

The iOS ecosystem has stricter restrictions on access to cryptographic functions and the file system. Many Russian CIPFs do not have versions for iOS or require the use of special secure media (tokens) that are not supported by the phone.

Do you need the Internet to verify a .sig file?

For the cryptographic verification procedure itself, the Internet is not required if all root certificates are already loaded into the device. However, to check the certificate revocation status (whether it has been revoked), a network connection is required.