Blog

A blog on QES and electronic signatures under DSTU

DSTU standards · August 7, 2026

Kupyna (DSTU 7564:2014): what this hash function is and why it replaces GOST 34.311-95

Kupyna (DSTU 7564:2014) is the modern Ukrainian hash function replacing GOST 34.311-95. How it works, why it beats its predecessor, and how to enable it when signing with a QES.

Read →

For developers · August 7, 2026

Signing in with a QES: how to authenticate website users with an electronic signature

QES-based sign-in on your website: a one-time challenge, signing in the widget, and server-side cryptographic verification. Your backend gets a verified identity — full name, RNOKPP, EDRPOU.

Read →

QES basics · August 7, 2026

Long-term electronic signatures: keeping a signature verifiable 10 years from now

Long-term validation (LTV): how a TSP timestamp and OCSP data keep a QES verifiable years later. The CAdES-XL and PAdES-B-LTA levels, with code for your website.

Read →

For developers · August 7, 2026

QES in PDF: how to sign a PDF document with the PAdES standard

How to sign a PDF with a qualified electronic signature using the PAdES standard: signature levels, the signature embedded inside the file, and a key that never leaves the browser. A guide with code.

Read →

QES basics · August 7, 2026

QES, digital signature, and advanced electronic signature: the differences and which one is legally binding

QES, digital signature, and advanced electronic signature: what is the difference? Which signature is equivalent to a handwritten one, how an advanced signature differs from a QES technically and legally, and how to tell them apart programmatically.

Read →

For developers · August 7, 2026

Multiple signers on one document: how to implement multi-signing

Multi-signing in DSTUcrypt: how to add a second signature to a document with the coSign method, what the flow looks like in your app, and how to check every signer via verify.

Read →

Security · August 7, 2026

The dangers of pure-JS cryptography: timing attacks, the one-time k, and key recovery from signatures

JS cryptography security: how timing attacks and a repeated one-time k let attackers recover the private key from signatures — and why a WASM build of a native core is safer.

Read →

For developers · August 7, 2026

Verifying an electronic signature on your website: cryptography, the trust chain, OCSP, and timestamps

Verifying an electronic signature online: four validation levels — cryptography, the chain of trust, OCSP/CRL, and timestamps. How to verify a .p7s signature on your website.

Read →

For developers · August 7, 2026

QES key files: PKCS#12/PFX, JKS, PKCS#8, and Key-6.dat — how to support them all

A file-based digital signature/QES key comes in PKCS#12/PFX, JKS, PKCS#8, and Key-6.dat formats. We explain how they differ and how to support all of them with a single widget on your website.

Read →

QES basics · August 7, 2026

Electronic signature formats: CAdES, PAdES, XAdES, ASiC — which one to choose

CAdES, PAdES, XAdES, and ASiC: how electronic signature formats differ, what .p7s and the ASiC container are, what levels exist, and which format to pick for your task.

Read →

Security · August 7, 2026

Why the private key must never leave the browser: the architecture of client-side cryptography

Electronic signature security starts with the key. Why a QES key must never be sent to the server, why XSS is dangerous, and how iframe origin isolation protects the key.

Read →

For developers · August 7, 2026

How to add QES to your website in 10 minutes: an iframe widget with no backend and no cryptography

How to add QES to your website in 10 minutes: one SDK import, an electronic signature widget in a modal, and a ready-made signature delivered to your backend. No cryptography on the server.

Read →

For business · August 7, 2026

How to choose a QES solution for your website: a checklist for business

How to choose a QES solution for your business: a 7-question checklist — where the key is processed, DSTU standards, signature formats, cost, and speed of implementation.

Read →

DSTU standards · August 7, 2026

How to sign a document with a QES using the Kupyna hash in the browser: a practical guide

How to sign a document with a QES using the Kupyna hash (DSTU 7564) in the browser: a step-by-step guide, sign() code with digest:'kupyna-256', the CAdES, PAdES, and XAdES formats, and verification.

Read →

For developers · August 7, 2026

XML signatures (XAdES) with DSTU 4145 keys: for reporting and B2B exchange

XAdES — XML signing under DSTU: Ukrainian DSTU 4145 keys with GOST 34.311 and Kupyna-256 hashes, the B-T/B-LT/B-LTA levels. For reporting and B2B exchange. A guide with code.

Read →