Copy the cryptopro key to another medium. How to copy an electronic signature from the registry to a medium? Select from the list by clicking the Browse button

Sometimes situations arise when you need to install a certificate with a key on another computer or make a backup copy of it. When working with USB flash drives, you can make a working copy of the private key using available Windows tools, the main condition is that you have CryptoPro CSP 3.0 installed.

Next, you need to follow the proposed instructions step by step, but it is worth remembering that a copy can only be made through a cryptographic information protection tool (cryptographic information protection tool), otherwise, for example, if you copy through Explorer, you will not be able to run the key on another computer.

Instructions for copying a certificate via CryptoPro CSP

1. Click on the CryptoPro CSP 3.0 shortcut or open it through Start – Control Panel.

2. In the system window, go to the “Equipment” tab and configure readers by selecting from the list of installed readers, then “Add”. Use “All removable drives” and “Registry” if they were not in the list.

4. In the next window that opens, run the “Browse” command to enter a name in the empty field. When choosing a name, first confirm the operation, and then click on the “Next” button. In some cases, when working with a root token, you may need to enter a password (PIN code) - enter the sequence 12345678.

5. Create a name for the container where the data is copied. The keyboard layout can be either Russian or Latin. Spaces are also allowed in the name. After defining the name, click "Done".

6. The system will then ask you to insert a blank key media onto which the container will be copied. Do this and click “OK”.

7. You can set a password for the created copy - this is an optional step, so you can simply click “OK” and leave the field empty. If the copy is made to a root token, then again you need to enter the standard security combination - 12345678.

The copying process will be completed when the system returns to the “Service” tab on the screen.

My new post will be devoted to the Crypto Pro program, it seems to be nothing complicated, but all the time I have problems with this software, either because I have to deal with it once or twice a year or because the software is like that, but in general I decided to make a reminder for myself and for you.

Task: Provide access to the Kontur Extern program on two machines, OK, let's get started.

What we have: One already working key on the SD card.

What you will need: We need any media SD card, USB flash drive can also be uploaded to the registry or you can use the so-called RUtoken. I will install on RUtoken, and you can use any of the options.

Yes, just a small note, if you have a domain computer, it is better to do all this under the administrator account.

And so let's get started

Find the program in the start menu or control panel,

Let's launch the program.

Go to the tab Service and press the button Copy.

You will be required to enter a password of any 8 characters. Enter the password and press Further.

In the next window, we need to set the name of the container (I always use the one that is convenient for me; we have 2 organizations and I use the name-01 and 02 markings; you can also use the organization’s TIN for separation.) and then click the button Finish.

Here you will once again need to enter the password for the new container, make the same one and click OK.

In the next dialog box, you need to select the media where to copy our container, I select RUtoken and you need to select the media where you are going to install the container.

Once you have chosen, click the button Further. Then Finish.

That's basically it, the key has been copied. All that remains is to install it for a specific user.

There are two options here:

Option 1.

Go to CryptoPro again, open the service tab and click on the button View the certificates in the container.

In the dialog box that opens, open the container we need and click the button OK. then press the button Further.

In the next window, click the U button become, if it is not there, press button C troops.

In the window that opens, click the U button install a certificate. The certificate import wizard will open where you need to click Further.

In the window that opens, you need to leave everything as it is and click Further.

If the certificate is installed successfully you should see the following dialog box.

Option 2.

Installation via the menu install a personal certificate.

To install the certificate, we need the certificate file itself (a file with the extension .cer) it is located on the media where we copied it, in my case it is rutokin.

And so, open CryptoPro again and go to the tab Service and press the button Install a personal certificate.

In the window that opens, find this certificate by clicking on the button Review.

In the next dialog box, check the box next to Find container automatically, after which the program will automatically find the container you need. Then click the button Further.

Then a window may appear asking you to select the storage location for the certificate; you need to select Private and click the button OK.

Then a dialog box may appear where you need to click a button Yes.

Then wait for a message about successful installation.

Then you need to remove your device to which the container with keys refers and insert it back, after the device is found you can try.

If you have any questions because there may be various changes in different versions of CryptoPro, please leave your comments, I will always be happy to help you.

Copying the private key container is a mandatory action when reinstalling the SBS on another computer. You can also copy the certificate if you want to create a spare digital signature key.

Copying a private key container to a flash drive, floppy disk or token is a rather complicated process to avoid errors it is important to strictly follow our instructions.

CryptoPro: certificate copying

Step 1. Opening the CryptoPro program

To open the program follow this path:

Click menu Start, then go to ProgramsCryptoProCryptoPro CSP and enable the tab Service.

In an open window Service click the button Copy container.

Rice. 1.

Step 2: Copy the private key container

After pressing the button Copy container, the system will display the window Copying the private key container.


Rice. 2

In the open window you need to fill in the field Key container name.

Step 3. Entering the key container

There are 3 ways to fill out the field Key container name:

    Manual input

    Select from the list by clicking the Browse button

    Search by digital signature certificate

In addition to filling out the Key container name field, you must fill in the remaining search options:

  • - the switch is set to position User or Computer, depending on what storage the container is located in;
  • Select CSP to search for key containers - the required crypto provider (CSP) is selected from the proposed list.


Once all fields are filled in, click the button Further.

If a password is set for access to the private key, the system will ask you to enter it. Enter your password and click the button OK.

Step 4. Entering a new key container

The system will display the window again Copying a private key container, in which you need to enter the name of the new key container and set the switch The name entered specifies the key container to position User or Computer, depending on in which storage you want to place the copied container.

After entering, click the button Ready.

Step 5: Select media for the copied container

A window will appear on your screen in which you need to select the media for the copied container.

Insert the media (token, flash drive, floppy disk) into the reader and press the button OK.

Step 6. Set a password

The system will display a window for setting a password to access the private key.

Enter your password, confirm it, and check the box if necessary Remember your password.

If this box is checked, the password will be saved in a special storage on the local computer, and when accessing the private key, the password will be automatically read from this storage rather than entered by the user.


After entering the required data, click the button OK. The CryptoPro CSP cryptographic information protection tool will copy the private key container.

If you still have questions, you can order a consultation with a specialist.

To perform any actions on the digital signature, copy the digital signature, delete or install it, you need the CryptoPro program installed on your computer.

  1. In order to copy the digital signature, you need to go to Start-All Programs-CryptoPro and run the CryptoPro CSP file.
  2. Next, go to the Service tab.

  1. Click on the “Browse” button.

  1. Select the required container and click “OK”.

Note:

In the image above, you can see the presence of two columns: On the left is the “Reader” column and on the right is the “Container Name” column. This information will help you decide which digital signature to copy.

The inscription “Register” in the reader column means that the digital signature is on the computer. Otherwise, the digital signature is located on some medium (flash drive, floppy disk or secure media). In the case shown in the image, there are three digital signatures recorded on the computer and one signature recorded on Rutoken.

You can understand which certificate you need to copy by looking at the “Container Name”. The “container name” is made up of the serial number, the date of issue of the certificate and the name of the organization.

In the case we are considering, we choose the digital signature located on the protected Rutoken media.

  1. Select and copy the container name, click “next”.

  1. Paste the container name copied in step 5 into the “Key container name” field, add any few characters or spaces and click the “Finish” button.

  1. Next, we need to select the location where we want to copy the digital signature. This could be a computer, flash drive or secure media. And click ok.

Note:

In the case we are considering, we copy the digital signature to a flash drive by selecting its name in the list of devices. If you need to copy your digital signature to your computer, you should select “Register” from the list of devices.

  1. Next, the system will ask you to create a password for the container. If you do not want to create a password, then leave the fields blank, as shown in the image. And just click “OK”.

This completes the digital signature copying.

If a flash drive or floppy disk is used for work, copying can be done using Windows (this method is suitable for versions of CryptoPro CSP no lower than 3.0). The folder with the private key (and the certificate file, if any) must be placed in the root of the flash drive (floppy disk). It is recommended not to change the folder name when copying.

The private key folder should contain 6 files with the extension .key. Below is an example of the contents of such a folder.

Container copying can also be done using the CryptoPro CSP crypto provider. To do this you need to follow these steps:

1. Select Start / Control Panel / CryptoPro CSP.

2. Go to the Tools tab and click on the Copy button. (see Fig. 1).

Rice. 1. “CryptoPro CSP Properties” window

3. In the window Copying a private key container press the button Review(see Fig. 2).

Rice. 2. Copying the private key container

4. Select a container from the list, click on the button OK, then Further.

Rice. 3. Key container name

6. In the “Insert and select media to store the private key container” window, you must select the media on which the new container will be placed (see Figure 4).

Rice. 4. Selecting a blank key media

7. You will be prompted to set a password for the new container. Setting a password is optional, you can leave the field blank and click on the button OK(see Fig. 5).

Rice. 5. Setting a password for the container

If copying to media Rutoken, the message will sound different (see Fig. 6)

Rice. 6. Pin code for container

Please note: if you lose your password/pin code, using the container will become impossible.

8. After copying is completed, the system will return to the tab Service in the window CryptoPro CSP. Copying is complete. If you plan to use a new key container to work in the Kontur-Extern system, you must install a personal certificate (see How to install a personal certificate?).

For bulk copying, download and run the Certfix utility.

Publications on the topic