The main signs of Rutoken devices connection are indicated in Table 1.
Table 1
Device name | Property |
Token, Bluetooth Token, Token with Type-C, Token with NFC | the indicator lights up on the device |
Smart Card | an indicator lights up on the smart card reader |
During operations with the Rutoken device, do not disconnect it from the computer in any case. This may lead to an error. |
The Rutoken Control Panel is a software tool designed to service Rutoken devices in Microsoft Windows operating systems. The Rutoken Control Panel is installed in the system when installing the "Rutoken Drivers for Windows" kit.
Types of users in the Rutoken Control Panel:
The User's PIN code is a password that is used to access the main functions of the Rutoken device.
The default User PIN is 12345678.
The Administrator's PIN code is a password that is used to access the administrative functions of the Rutoken device.
The default Administrator PIN is 87654321.
To connect the token, insert it into the USB port of the computer. If the token is connected correctly, then an indicator will light up on it.
A smart card reader is used to connect the smart card to the computer.
Both an empty reader and a reader with an inserted smart card can be connected to the USB port of the computer.
To connect a smart card to a computer:
Connecting a Rutoken with a Type-C connector to a computer
A Rutoken with a Type-C connector connects to a computer that has a special USB Type-C port. On some computers, this port is designated as Thunderbolt 3 (USB-C).
If the token is connected correctly, then an indicator will light up on it.
There are several ways to launch the Rutoken Control Panel:
Use the left mouse button to double-click on the Control panel icon located on the desktop of the computer.
For Windows 10:
For Windows 7:
For Windows XP:
If several Rutoken devices are connected to the computer at the same time, then before starting work, you need to select the device with which operations will be performed.
To select a device:
To check the correctness of the device selection:
To view information about the Rutoken device:
The description of the information about the Rutoken device presented in the control panel is given in Table 2.
Table 2
Field | Description |
Name | Personalized device label |
Model | General name of the device |
System name | The name used to designate the device in other applications |
ID | Unique digital device identifier |
Version | Rutoken device firmware version and status flags |
Shared memory (bytes) | The total amount of memory of the selected device |
Free memory (bytes) | The amount of device memory (available to the user) |
The User's PIN code can be changed | The policy selected to change the User's PIN on the device |
Using UTF-8 in PIN codes | The ability to safely use сyrillic characters when setting a PIN code |
CryptoPro FKC Support | The device supports working with CryptoPro Rutoken CSP via a secure FKC channel |
Microsoft Base Smart Card Crypto Provider | The device supports working with a standard cryptography provider for smart cards from Microsoft |
The device is connected via RDP | Is the device connected via the RDP protocol |
To view the version of the installed kit "Rutoken Drivers for Windows":
After entering an incorrect User's PIN code several times in a row, the Rutoken device is blocked. Only the Administrator of the Rutoken device can unlock it. |
To enter the User's PIN code:
Crypto provider is a dynamically connected library that implements cryptographic functions with a standardized interface.
Each cryptographic provider can have their own sets of algorithms and their own requirements for the format of keys and certificates.
To select the crypto provider used by default for the Rutoken device:
You should not use Microsoft crypto provider to generate key pairs if you are not sure about the security of your computer. |
To select a cryptographic provider to generate RSA key pairs:
You can set the settings for the PIN code in the Rutoken Control Panel. The list of settings is specified in Table 3.
Table 3
Setting | Result of setting selection |
Remember the PIN code from the app... | The PIN code is entered once when using the Rutoken device for the first time in the application |
Offer to change the PIN code every time... | Every time after entering the PIN code, a message is displayed on the screen with a suggestion to change the PIN code (if the user has not changed the default PIN code) |
Encoding the PIN code in UTF-8... | The PIN code can consist of Cyrillic characters |
The Remember PIN-code setting allows you to reduce the number of PIN-code entries in applications due to their short-term storage by the crypto provider in encrypted memory. Do not use this setting if you are not sure about the security of the computer.
The Encoding the PIN code in UTF-8 setting allows you to safely use PIN codes containing cyrillic characters.
To select the settings for the PIN code:
By default, the User's PIN code set for the Rutoken device is 12345678. For security reasons, before using the Rutoken device for the first time, it is recommended to change the default PIN code.
The recommended length of the PIN code is 6-10 characters. Using a short PIN (1-5 characters) significantly reduces the level of security, and a long PIN (more than 10 characters) can lead to an increase in the number of errors when entering it.
Access to the certificates stored on the device is possible only after specifying the PIN code. If the PIN code has been changed, then it must be remembered. |
To change the PIN code:
In order to distinguish Rutoken devices from each other, you should set a name for each device. It will not always be displayed in third-party applications.
It is recommended to specify the first and last name of the owner of the device or a short name of the scope of the device use.
To specify the Rutoken device name:
After entering the wrong Administrator PIN code several times in a row, the device is blocked. The Administrator's PIN code cannot be unlocked. If the Administrator's PIN code is blocked, it is necessary to format the Rutoken device, but all data stored on it will be permanently deleted. |
To enter the Administrator's PIN code:
By default, the Administrator PIN code set for the Rutoken device is 87654321. For security reasons, it is recommended to change the default PIN code before using the Rutoken device for the first time.
The recommended length of the PIN code is 6-10 characters. Using a short PIN (1-5 characters) significantly reduces the level of security, and a long PIN (more than 10 characters) can lead to an increase in the number of errors when entering it.
To change the Administrator's PIN code:
The Administrator can change the User's PIN code only if the "User and Administrator" ("Administrator") PIN change policy was selected when formatting the device.
To view the current PIN change policy, open the Rutoken device details.
The recommended length of the PIN code is 6-10 characters. Using a short PIN (1-5 characters) significantly reduces the level of security, and a long PIN (more than 10 characters) can lead to an increase in the number of errors when entering it.
To change the User's PIN code:
The User's PIN code is blocked if the user has entered it with an error several times in a row. The User's PIN code can only be unlocked by the administrator.
After the User's PIN code is unlocked, the counter of failed authentication attempts will take its original value (set when formatting the Rutoken device).
After unlocking, the User's PIN code will not change. The Administrator can set a new User PIN code only when formatting the Rutoken device.
In order to unlock the User's PIN code:
During the formatting of the device, all objects created on it will be deleted. Only those objects that have been stored in protected memory (for Rutoken EDS Flash) will remain. Also, when formatting, new PIN values are set or default values are selected. If the user has exhausted all attempts to enter the Administrator's PIN code, then it is possible to return the device to the factory-fresh state. For such formatting, the Administrator's PIN code is not required. When returning the Rutoken EDS Flash device to the factory-fresh state, the contents of the Flash memory will also be cleared, and the information recorded in it will be permanently deleted.
When formatting a Rutoken device, all data on it, including keys and certificates, will be permanently deleted. |
During the formatting process, do not disconnect the Rutoken device from the computer, as this may lead to its breakdown. |
To start the Rutoken device formatting process:
To specify the name of the Rutoken device when formatting specify a new device name in the Token name field.
Depending on the policy selected when formatting the Rutoken device, the User's PIN code may be changed:
In order to understand which policy to choose, follow the link "Which policy should I choose?" (located in the section the user's PIN code can be changed).
To change the policy in the section the user's PIN code can be changed, set the switch to the desired position.
In order to set a new PIN code of the User (Administrator), which will be available only after the formatting process is completed:
The recommended length of the PIN code is 6-10 characters. Using a short PIN (1-5 characters) significantly reduces the level of security, and a long PIN (more than 10 characters) can lead to an increase in the number of errors when entering it.
In order to set the minimum length of the PIN code of the User (Administrator), select the desired value in the corresponding section in the drop-down list Minimum PIN code length.
To increase the security level, you should change the original value. The recommended number of attempts to enter the PIN code is 5 times. A small number of attempts (1-4 times) can lead to accidental PIN code blocking, a large number (more than 5 times) - will reduce the level of information security.
In order to set the maximum number of attempts to enter the PIN code of the User (Administrator), select the desired value in the corresponding section in the drop-down list Attempts to enter the PIN code.
PIN quality policies allow you to increase the level of PIN security.
In the Rutoken Control Panel, all PIN codes are divided into three categories by quality:
There is a choice of policies that will be taken into account when assessing the quality of the PIN.
The following policies are used to control the quality of the PIN code:
When installing the "Rutoken Drivers for Windows" kit, the policy settings are set by default.
By default, all previously specified PIN quality policies are selected.
By default, a password is considered "weak" if its length is less than one character.
PIN quality policies can be changed in the Rutoken Control Panel by a user with operating system administrator rights or a domain administrator.
Each new PIN must comply with the selected quality policies.
PIN quality policies are set in the Rutoken Control Panel for a specific computer.
In order to select the policies that will be taken into account when assessing the security level of the PIN: