Tools
Sign a file — QES under DSTU
Choose a file and sign it with a qualified electronic signature — with a file key, via Diia.Signature, or with Smart ID from PrivatBank. The key and password are entered in an isolated window and never leave your browser — neither to our server nor anywhere else. With cloud methods, only the document's digest is sent to the provider.
File to sign
Format: CAdES-XL
long-term, with timestamp · GOST 34.311 hash
Not a single byte of your key leaves your browser
The default is CAdES-XL (a long-term format with a timestamp and full validation data) with the GOST 34.311 hash — this pair is accepted by the Diia / central CA (CZO) government validators. Kupyna (DSTU 7564) can be selected manually, but it is not yet accepted by government validators, and it downgrades long-term levels to C.
Keys: PKCS#12/PFX, JKS, PKCS#8, IIT Key-6.dat. The signing key is picked from the container automatically based on keyUsage.
The signing window has a "Remember key" checkbox — the key file is stored in your browser so you don't have to pick it every time; the password is still entered for every signature and is never stored anywhere.
Need to check an existing signature? Verify a signature →