CryptoPro web plugin. Configuring trusted nodes for CryptoPro EDS Browser plug-in

In recent years, most of the document circulation has moved to the field of remote service via the Internet, while paper media are gradually being replaced by electronic virtual counterparts. The most popular is the software product "Crypto Pro", with the help of which the electronic digital signature is confirmed. But for reliability and reliability, it is necessary to check the "CryptoPro EDS Browser plug-in" plug-in and make sure that it is correctly installed on a computer or other electronic device.

Plugin nuances and system requirements

For the normal functioning of all divisions, the question arises of ensuring the necessary level of data protection when signing documents, keeping secrecy and commercial secrets. The solution of problems is achieved by the development of special software products and algorithms that encrypt and decrypt the information included in the document, while simultaneously confirming its authenticity. These programs are certified products and cover certain areas of the information field.

The essence of their work is to process documents online using special extensions for all browsers that support JavaScript. It functions freely on all major operating systems except Android. The plugin allows you to endorse the following types of documents:

  • in electronic format;
  • files that are downloaded from the user's computer;
  • text messages and other types of documentation.

For example, when transferring funds in Internet banking using the "CryptoPro EDS Browser plug-in" check, you can confirm that the operation comes from the account holder with an active key certificate valid at a particular moment. An advanced and conventional electronic CPU is tested with this software. At the same time, there is no need to connect to the Internet when checking, and archival preservation of documentation is provided. An electronic signature can be:

  • attached, that is, added to the documents being signed;
  • separated EP, that is, created separately.

The software product "CryptoPro EDS Browser plug-in" is distributed free of charge and downloaded from the official website. The plug-in is checked on the user's computer.

Installing the software

The installation process is simple. You should go to the official portal cryptopro.ru/products/cades/plugin/get_2_0. Load, specifying where the cadesplugin.exe boot file will be saved. Run the program.

Important! Plugin launch is not available for regular users. You must have administrator rights.

Upon successful completion, a corresponding notification will appear on the monitor screen.

But this message is not a guarantee of correct operation. You will need to carry out additional configuration and verification of the EDS Browser plug-in, depending on the type of browser used. For correct operation, the installed program should be restarted, in some cases with a complete restart of the computer.

Advice! In whatever browser the program is used, it should always be restarted after installation.

Features of the installation process

Given that each browser is slightly different in its work, the plugin is adapted for each environment.

Attention! If errors are detected before starting work and the program does not create objects, then it is necessary to allow launching independently for specific sites or pages that the user often visits.

In cases where the plugin is used on specific pages, you need a corresponding icon that will indicate the possibility of using this extension.

To do this, you need to find the CryptoPro CAdES NPAPI Drowser Plug-in and allow it to be used in automatic mode. This is true for Mozilla Firefox. For Opera and Yandex, the procedure for using the extension is identical.

Find the "Extensions" item in the menu, and load the plugin through it. You can also copy and paste the name of the extension into the corresponding query string. The system will do everything by itself. For the Google Chrome browser, the extension will be found by itself, and the user will have to confirm the installation.

After completing all operations and settings, you must close all windows and tabs, restart the browser.

What if the system "does not detect" the program?

It often happens that when installing a plug-in and then trying to work with an EDS, problems appear. A window pops up offering to install the program. In this case, it is recommended to go to the developers' site in the "Contacts" section to state the essence of the problem and get appropriate recommendations. It is recommended to provide screenshots of all activities. In this case, it will be much easier to identify the problem. If the check is successful, a corresponding notification appears that the plugin has been loaded.

Recommendations for using the software

If you have to reinstall an existing plugin, but not working, then first you need to:

  • remove it and all unnecessary programs through the "Control Panel";
  • clean out the cache memory;
  • download the plugin again and run it with administrator rights;
  • be sure to add all the pages of the "Personal Accounts" to trusted sites.

Thank you very much, Mikhail, we did everything promptly and the main thing is clear to me ... Since we have found a common language. I would like to continue the communication with you in the future. I look forward to fruitful cooperation.

Olesya Mikhailovna - General Director LLC "VKS"

On behalf of the State Unitary Enterprise "Sevastopol Aviation Enterprise" we express our gratitude for the professionalism and efficiency of your company! We wish your company continued prosperity!

Guskova Lilia Ivanovna - manager. SUE "SAP"

Thank you, Mikhail, very much for your help with the design. Very qualified employee +5!

Nadia Shamilevna - entrepreneur IP Anoshkina

On behalf of the company "AKB-Auto" and on my own behalf, I express my gratitude to you and all employees of your company for the productive and high-quality work, sensitive attitude to the client's requirements and efficiency in the execution of the ordered work.

Nasibullina Alfira - Senior Manager"AKB-Auto"

I would like to thank the consultant Mikhail for the excellent work, timely and complete consultations. He is very attentive to the client's problems and questions, prompt solution of the most difficult situations, it would seem to me. It's a pleasure to work with Mikhail !!! Now I will recommend your company to my clients and friends. And the technical support consultants are also very polite, attentive, helped to cope with the complex installation of the key. Thanks!!!

Olga Sevostyanova.

Acquiring a key turned out to be very easy and even enjoyable. Many thanks for the assistance to manager Mikhail. Explains complex and massive things to understand, succinctly, but very clearly. In addition, I called the free hotline and online, together with Mikhail I left a request. I got a key made in 2 working days. In general, I recommend it if you save your time, but at the same time want to have an understanding of what you buy and what you pay for. Thanks.

Levitsky Alexander Konstantinovich Samara

Personal gratitude to the consultant Mikhail Vladimirovich for prompt advice and work on the accelerated receipt of the ES certificate. During the preliminary consultation, the optimal set of individual services is selected. The end result is immediate.

Stoyanova N.L. - Chief Accountant LLC "SITEKRIM"

Thank you for your prompt work and competent help! I was very pleased with the consultation!

Dmitry Fomin

Expert Sistema LLC would like to thank the consultant Mikhail for the prompt work! We wish your company growth and prosperity!

Sukhanova M.S. - AppraiserLLC "Expert System", Volgograd

Thanks to the consultant who introduced himself as Mikhail, for the promptness in working with clients.

Stepan Gennadievich Ponomarev

Many thanks to the consultant Mikhail for his assistance in obtaining an EDS. For operational work and advice on issues arising in the process of registration.

Leonid Nekrasov

The company, represented by its consultant Mikhail, does the impossible! Acceleration of accreditation in less than 1 hour! Payment upon delivery of the service. I thought it couldn't happen. With full responsibility, I can advise you to contact the Center for issuing electronic signatures.

Nowadays, document flow is increasingly moving to monitor screens. Instead of standard paper media, virtual documents come, which do not need to be collected, certified, duplicated and archived. But the use of electronic document management carries one inevitable complexity: the problem of data protection, certification of documents and preservation of privacy. This is where the question arises about the use of special algorithms that perform two functions:

  • protect the data contained in the file;
  • certify an electronic document.

Such algorithms execute special programs that have passed the appropriate certification and are designed to encrypt and decrypt certain information. One of these programs is called Crypto Pro.

What is the crypto pro program for?

Crypto pro company was founded in 2000 and since then occupies one of the leading places in the market of crypto programs and electronic digital signatures. Developers not only implement individual software products, but also offer ready-made utilities that process documents online through special browser extensions. Crypto-Pro EDS Browser plugin can be purchased on the company's website, and its installation is possible on all types of popular browsers.

How to install Crypto-Pro EDS

This plugin can be found on the company's website or at the link: https://www.cryptopro.ru/products/cades/plugin/get_2_0

After the transition, you can see a window where you will be prompted to download and select the location to save the installation file cadesplugin.exe

After downloading to the selected disk, the installed file should be run:

Please note that for ordinary users, it is impossible to launch the installation of the Crypto Pro browser plugin. The process can be activated only with administrator rights. If the user has them, then you can see the following notification on the screen:

The following window will indicate the successful installation of the plugin:

Correct installation does not guarantee correct operation of the plugin. The browser must be restarted, and in the case of Chrome, a complete restart of the computer may be required.

Features of installing browser plugin Crypto Pro

For various browsers, the developers have come up with special add-ons to facilitate the work of the plugin. For example, for later versions of FireFox, there is an add-on that is proposed to be installed immediately after the main part of the process.

Sometimes an error occurs before work, and the plugin is not able to create objects.

This problem can be solved quite simply: you should allow the launch of add-ons separately for certain sites or for all pages visited by the user.

If the plugin is allowed to be used on individual sites, you should go to the desired page and find a separate icon in the search bar indicating the possibility of using the extension:

If the plugin will work with all sites, it should be run from the "Add-ons" option:

In the list of all possible add-ons, we are looking for CryptoPro CAdES NPAPI Browser Plug-in and allow its use in automatic mode:

For Opera browsers and Yandex browsers, the process of using the extension will be identical. In the menu we find the option "Extensions", through do not load the required plugin.

In this article, we will consider how to quickly configure the Yandex browser to work with an electronic signature. The settings below will work if your computer is already configured to work with electronic signatures:

  • installed crypto provider (CryptoPRO CSP or other);
  • the Personal certificate is installed;
  • installed root certificates of the Certification Authority, which issued you an electronic signature.

Attention!This article describes the configuration process ONLY for electronic signatures issued using a cryptographic provider CryptoPRO CSP and for hardware keys (Rutoken EDS, JaCarta GOST, etc.). If your electronic signature was issued using a different encryption provider (for example, Vipnet CSP, Lissi CSP, etc.) further settings may damage your operating system! To configure, contact the organization that issued your electronic signature!

Where can I get Yandex Browser?

You can download the Browser from the official developer page: https://browser.yandex.ru/
We will not describe the download and installation process, it is quite simple and straightforward.

Installing components for working with electronic signature

To work with an electronic signature, you need to install the following components:
  • CryptoPRO CSP;
  • CryptoPRO EDS Browser plugin;
  • Plugin for the e-government system (only needed to work with the website of the State Services and the Unified Information System of Autonomous Systems).

Since January 1, 2019, CryptoPRO CSP version 4.0 and higher is recommended for use, so we recommend using it. ...
Installation of CryptoPRO CSP is quite simple, any user can handle it - run the downloaded file and then follow the installation wizard.

The current version of CryptoPRO EDS Browser plugin can be downloaded from the manufacturer's website via a direct link: https://www.cryptopro.ru/products/cades/plugin/get_2_0
Installation of CryptoPRO EDS Browser plugin is also quite simple - run the downloaded file and follow the installation wizard.

You will also need to install a browser extension, you can install it from the link: https://chrome.google.com/webstore/detail/cryptopro-extension-for-c/. When the page opens, click "Install", after a couple of seconds the extension will be installed.

The e-government plug-in can be downloaded from the download page: https://ds-plugin.gosuslugi.ru/plugin/upload/Index.spr
When you click on the link, the download of the plugin will start automatically. Plugin installation is also simple, no additional configuration is required.
To work in Yandex Browser, you need to install the extension. To install it, you need to open Yandex Browser and open the link https://chrome.google.com/webstore/detail/ifcplugin-extension/ in it and click the "Install" button. After a couple of seconds, the plugin should be installed.

Turn off unnecessary

Along with some programs (for example, Yandex Browser), additional programs may be installed that may interfere with the normal operation of electronic signatures on some sites.

To avoid problems, we recommend removing such programs as Browser manager , Yandex button on the taskbar , Yandex elements for Internet Explorer ... They are removed using standard MS Windows tools - through the Control Panel - Programs and Features.

Enabling signature settings

The settings for working with electronic signatures are enabled through the browser menu. To do this, we will perform the following actions:
Open the browser menu (there is a button with three stripes in the upper right corner of the browser) and select the "Add-ons" item as shown in the picture or in the address bar simply open the browser: // tune page.

In the window that opens with plugins, you need to enable the plugins we need: CryptoPRO EDS and Extension for the Public Services plugin (if necessary).

After enabling the plugins, you must enable the ability to work with a secure TLS connection in accordance with GOST. To do this, go to the browser settings and in the "Network" section, check the "Connect to sites using encryption according to GOST." As indicated in the pictures below.



After enabling these settings, you can start working with an electronic signature on the resource we need without rebooting.

Pay attention! For the secure connection to work correctly, you must turn off the antivirus while working with a signature! This is necessary when working on the FTS website or on the ERUZ website (zakupki.gov.ru). As for the famous Kaspersky antivirus, you have to do it " Output"(shutdown doesn't help)!

Usually setting Yandex Browser it takes our specialists 10-15 minutes to work with an electronic signature. You can contact our paid technical support for help. The cost of setting up an electronic signature in Yandex Browser usually costs 600 rubles!

Cryptographic operations, such as creating an electronic signature or decrypting a file, require access to the user's keys and personal data (for example, to the personal certificate store). When such operations are performed by web applications (using the CryptoPro EDS Browser plug-in), the plug-in asks for the user's permission to access his keys or personal data.

User permission will be requested when activating CryptoPro EDS Browser plug-in objects.

Trusted sites (for example, those on an organization's intranet) can be added to the list of trusted sites. Trusted sites will not ask for user confirmation when opening a certificate store or when performing operations with a user's private key.

Managing the Trusted Sites List on Windows Platforms

To manage the list of trusted websites in the CryptoPro EDS Browser plug-in, the user must run Start -> Crypto-Pro -> EDS settings Browser plug-in... This page is part of the CryptoPro EDS Browser plug-in distribution kit.

A computer or domain administrator can also manage the list of trusted sites for all users through Group Policy. Configuration is carried out in the Group Policy Console in the section Computer Configuration / User Configuration -> Administrative Templates -> Crypto-Pro -> CryptoPro EDS Browser plug-in... The following policies are available to the administrator: Trusted sites list... Determines the addresses of trusted hosts. Websites specified through this policy are considered trusted in addition to those that the user adds independently through the CryptoPro EDS Browser plug-in settings page.

The page is saved for a specific user
HKEY_USERS \ \ Software \ Crypto Pro \ CAdESplugin

The policy saves in the appropriate section for policies:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Crypto-Pro \ CadesPlugin \ TrustedSites

Trusted Site List Management on Unix Platforms

To manage the list of trusted websites in the CryptoPro EDS Browser plug-in on Unix platforms, use the /etc/opt/cprocsp/trusted_sites.html page, which is part of the CryptoPro EDS Browser plug-in distribution kit.

Alternatively, you can use the command to view the list of trusted websites:

/ opt / cprocsp / sbin / / cpconfig -ini "\ local \ Software \ Crypto Pro \ CAdESplugin \ TrustedSites" -view

To add Web sites (for example, http: // mytrustedsite and http: // myothertrustedsite) to the list of trusted sites, you can use the command:

/ opt / cprocsp / sbin / / cpconfig -ini "\ local \ Software \ Crypto Pro \ CAdESplugin" -add multistring "TrustedSites" "http: // mytrustedsite" "http: // myothertrustedsite"

To clear the list of trusted sites, you can use the command:

/ opt / cprocsp / sbin / / cpconfig -ini "\ local \ Software \ Crypto Pro \ CAdESplugin \ TrustedSites" -delparam

Adding sites to the list of trusted sites for all users is available using the command

/ opt / cprocsp / sbin / / cpconfig -ini "\ config \ cades \ trustedsites" -add multistring "TrustedSites" "http://www.cryptopro.ru" "https://www.cryptopro.ru"