Security
Signing with a USB token or smart card: what it is and why the key never leaves it
A signing token is a small device that holds your private key and refuses to hand it over. It signs things for you instead. A web page cannot talk to one directly, so a small app on your computer passes the request to the token, which asks for your PIN before it signs.
In the Digital Signature tool, the certificate section has two tabs: "Certificate file" and "USB token / smart card". This page is about the second one.
What a token looks like
You have probably met one if a government office or bank issued your digital ID. It is usually:
- a small USB stick that plugs into your computer (often called a DSC token),
- or a smart card you put into a reader,
- or a national eID card.
It came with a PIN, and possibly with a warning that too many wrong PINs will lock it.
Why it is safer than a file
A .pfx file is still a file. It can be copied to a memory stick, attached to an email, or picked up by anything that gets onto your computer. The password helps, but a copy is a copy.
A token is built so the key physically cannot be exported. There is no "save as" for it. Someone who wants to sign as you needs the actual device in their hand *and* your PIN.
That is why banks, courts and tax offices in many countries insist on tokens for anything official.
The everyday version
A .pfx file is like having a copy of your signature that you keep in a locked drawer. Useful, but copies can be made.
A token is like a rubber stamp locked in a safe that only opens for you. You never take the stamp out. You put the paper in the slot, enter your code, and the safe stamps it and hands it back.
Why a web page needs help
Browsers deliberately cannot reach devices plugged into your computer. That is a good rule. You would not want any website able to poke at your hardware.
So there is a small Windows app, KovaPDF Signer, that runs on your own computer and listens only to programs on that computer. The web page asks it; it asks the token; the token asks you.
What happens when you sign
Step by step, this is the actual sequence:
- You choose your certificate from the list the app found on your computer.
- You press Sign document. The server prepares everything and works out a short fingerprint of what is being signed.
- That fingerprint: and nothing else: goes to KovaPDF Signer on your machine.
- The app shows you what you are about to sign and asks you to confirm.
- Your token asks for its PIN, and signs the fingerprint inside the device.
- The signed result goes back, and the server finishes building the signed PDF.
The private key never moves. The document never goes to the app. Only a fingerprint travels in each direction.
Setting it up
Two things must be in place:
- Your token's own driver, from whoever supplied it: ePass2003, ProxKey, SafeNet eToken, your eID card software and so on. Without it, Windows cannot see the certificate at all, and neither can anything else.
- KovaPDF Signer, the small Windows app that lets the page reach the token.
If either is missing, the panel tells you which one and what to do.
Things that commonly go wrong
"KovaPDF Signer is not running." Start it from the Start menu, then press *Check again*.
"No signing certificate was found." The token is not plugged in, or its driver is not installed. Plug it in, install the driver, check again.
"Your token rejected the PIN." Type it again carefully. Too many wrong attempts will lock the token, and only your token's own software can unlock it.
Nothing happens in Safari. Safari refuses to let a secure web page talk to apps on your computer, so it can never reach the token. Use Chrome, Edge or Firefox.
"Your token cannot sign with this hash algorithm." Some older tokens support only one. Set Hash algorithm back to *Automatic* under Advanced: see hash algorithms explained.
Everything else works the same
Once the certificate source is sorted, every other option behaves identically: the trusted timestamp, long-term validation, certifying, the visible stamp, all of it. The only difference is where the key lives.
Common questions
What is a USB signing token?
A small device holding your private key and certificate. It performs signatures inside itself after you enter a PIN, and it will not hand the key over to your computer.
Why can't the website use my token directly?
Browsers block web pages from reaching devices plugged into your computer. A small local app, KovaPDF Signer, passes the request to the token on the page's behalf.
Does my document get sent to my computer's signer app?
No. Only a short fingerprint of what is being signed is sent to it, and only the signature comes back. The document itself never goes through the app.
Is a token safer than a .pfx file?
Yes. A file can be copied; a token's key cannot be exported. Anyone wanting to sign as you would need the physical device and your PIN.
My token is not showing up. What should I check?
Install the token's own driver first, plug the device in, make sure KovaPDF Signer is running, and use Chrome, Edge or Firefox rather than Safari.
What if I enter the wrong PIN too many times?
The token locks itself. Only the token's own software from its supplier can unlock it. No website can.