PROCEDURE FOR APPLYING DSC FROM NICCA Download DSC application form fromhttps://nicca.nic.in. Fill in each and every column in the DSC application form correctly and carefully in block letters. Columns marked with asterisk (*) are mandatory fields and skipping any of these fields can result in getting the application rejected. Eg. Class of certificate, Name, email id, date of Superannuation etc. Paste a recent passport size photograph in the space provided. The applicant has to sign, write place & date in the space provided in all the three pages of the application form. Attach attested Xerox copy of any one document mentioned in column 10 of the DSC application. If the applicant is interested to include PAN in his/her DSC, an attested copy of PAN card may also be attached. The filled in application endorsed by the Head of the Department. The applicant has to get the sign and official stamp of his/her HoD in pages 2 & 3. After completing the above formalities, the application has to be verified and signed by SIO/NIC Coordinator. To send the application to NIC Mumbai, it may be forwarded to : State Informatics Officer National Informatics Centre, 11th floor, New Administrative Building, Madam Cama Road Mumbai 32 for signature of SIO/NIC co-ordinator in pages 2 & 3 along with a covering letter addressed to State Informatics Officer. The Applicant must download the Digital Signature Certificate in the USB Token within 90 days from the Date of Application, failing which a fresh application must be submitted.
Alert on Processing DSC application. After processing the application by NICCA, each applicant will get an email alert in his/her email id mentioned in the DSC application showing that their application is processed and the user-id is XXXX Once the user-id is created, the applicant has to collect the USB crypto token and user-id details from the RA office, Mumbai. The same can be received by post also, but the applicant may have to bear with the postal delay if any. For Class III Certificates, it is mandatory that the applicant has to appear personally with proper identity proof at the RA office, Mumbai and collect token and user-id details. In case of class III users, RA office can help them in enrolment and downloading DSC. Enrollment and Downloading procedure of DSC Please ensure that Latest Java Runtime Environment (JRE) is available on the PC. It can be downloaded from http://java.com Install device driver of token. Ensure that the token is not plugged while installing the token drivers. The drivers can be downloaded from http://nicca.nic.inby going to the download page To download Ex: a) Click on Option 11 to download Moserbaer Token / card reader Driver. b) Click on Option 15 to download Gemalto token Driver.
Enrollment and Downloading procedure of DSC -Cont Download Certificate Chain fromhttp://nicca.nic.in. Out of the 5 certificates available in the menu, install only 3 as follows: 1. CCA India location Trusted Root. 2. NICCA Certificate 3. NIC Sub CA (Note: Above b & c can be installed in default location by double clicking on it.). Restart system after driver installation. You may use Windows 7 & Internet Explorer 8 or 9 while applying for DSC online. Do the following settings in the browser before applying online for the certificate. Go to Tools ->Internet options -> security Click Custom Level and set security level as Medium Enable all Active X settings) Sign-in Certificate will be directly downloaded into the USB Token. But Encryption certificate has to be saved on the PC (ex. Desktop) and then using the Token Admin Tool, you have to import the Certificate into the token. Each DSC is issued for two years or retirement date of the applicant whichever is earlier. Please follow the download and backup procedure for the signing and encryption certificate
Fee Structure : For Latest fee structure, please visit the website http://nicca.nic.in, click on view DSC Fee Structure link. Certificate Fee Structure(for all classes: Class-I, Class-II & Class-III) Type ofsubscribers Smart Card Smart Card Individual/ personal Certificate S.Card Proc. Reader Charge Total # USB etoken USB Token/iKey Individual/ personal Certificate Proc. Total Charge Soft Token SSL Server/ Device Cert. (Proc. charge) Renewal (Proc.Charge) Government 227/- 489/- - 716/- 555/- - 555/- - - PSUs & Autonomous/ Statutory Bodies Validity Renewal 227/- 489/- 200/- 916/- 555/- 200/- 755/- 200/- 200/- Two years (Conditions apply) On expiry of certificate, processing charge shall be applicable as above to renew/create the certificate on the same media. All other formalities shall be same as for a new DSC applicant, including submission of fresh DSC Application form and fees as applicable.
Installation of USB Token (Gemalto): Follow these steps to install appropriate drivers. Install JRE 6 or above (https://164.100.20.211/jre-6u29-windowsi586.exe) Download the driver for Gemalto token from the below link The CD contains installation instruction. Go to the Drivers 32 and 62 bit (Windows). http://nicca.nic.in/html/datakey.html Click on Gemalto Token Windows Driver Download [.zip format] (for all Windows - 32/64 bit OS) 1. Browser Settings Active-X controls need to be enabled in your internet browser. In order to ensure this, please Do the following: Open a browser window Go to Tools >> Internet Option >> security Click Custom Level and set security level as Medium Enable all Active-X controls 2. Download and Install Certificate Chain: Per-requisite: Windows-XP SP-3, Windows Vista SP-2 To download and install certificate chain follow these steps. Open the Browser and go to http://nicca.nic.in Bring your mouse to Repository and Click Certificate Chain (CCA, NICCA and NIC Sub-CA Certs) Click on Download (Left Hand Side Window Pane) and Click Download certificate Chain (.Zip format). Save this file on Desktop or your desired location.
Unzip this file with Winzip or WinRAR. This will display number of files. Right click on chain.p7b ( This includes CCA India 2011, NICCA 2011, and NIC Sub-CA for NIC 2011) and click install certificate. This will install certificate chain. Or you can install each certificate separately. CCA India 2011 certificate must be installed under Trusted Root Certificate only. 3. Initialise Smart Card / USB Token Initialising the Smart Card/USB Token: Insert you smart card in Reader or plug in USB Token in the system Run SC-SED Click on Select Card and then choose Gemplus USB key Smart Card Reader 0. A new window will appear. In this new window enter the following information A new pop up will appear, click Ok. Enter Name, Department, and Organization. Enter PIN: 0000 or as desired by you and confirm the same These will initialize your token in few seconds 4. Enrolment Instruction Generating Key Pair When you enroll for a digital certificate, cryptographic keys are generated and stored on your smart Card USB Token. It won t be visible in the Card. Open the Browser and go to http://nicca.nic.in or http://164.100.20.211 Click member login and login with User-id / Password issued by NIC Certifying Authority Insert your smart card in the Card Reader or USB Token in USB port of your system. Click Enroll OR Step-1 for generating your Digital Certificate Key Pairs. (An Electronic From will appear, which is self-explanatory. You are required to fill in Your details mentioned in digital Signature Certificates Request From and submitted to NICCA ) Certificate Class: It is fixed at the time of User-id creation.
Certificate Type: Select Signing Certificate or as desired or as suggested/ instructed by Certifying Authority Do you have a Certificate request already generated? Click No Fill in the seven mandatory fields under Contents of your Digital Certificate Cryptographic Service Provider: select Microsoft Base Smart Card Crypto Provider. Do not scroll down the page with mouse wheel; it changes the select option. To avoid this move arrow away from selected option and click left mouse-button once. Check all entries ones again and Click Generate Request. (A Confirmatory message will be display on your computer screen. Read it and Click Ok). At this time you will be prompted to enter Pass Phrase/PIN of the smart card/usb Token.) Enter Passphrase / PIN of the smart card/usb Token. Your Digital Certificate key pair will be generated on smart card. A request Number will also be generated and displayed on your computer screen. Please note it down for further follow up. No need to go to Step-2. Go to Step-3 OR Step-4 to view the status of your DSC Request or simply click view Status on the top of the page. Similarly apply for Encryption Certificate by clicking on Enroll and selecting Encryption certificate from drop down list. Once RA administrator and CA Administrators process the certificate request, your Digital certificate, Encryption Certificate will be generated and Authentication PIN will be sent on your email address.
Installation of USB Token (Moserbaer): Follow these steps to install appropriate Drivers. The CD contains installation instruction. Go to the \Drivers 32 and 64 bit (Windows). There are two.exe files - (i)safesign-iclient-3.0.45x32.rar and (ii) SafeSign-IClient-3.0.45x64.rar. One is for 32 bit operating System and other for 64 bit operating system. Install appropriate SafeSign-Identity-client as per your operating system. The installation procedure is in Quick Reference Guide available on the CD. 1. Browser Settings Active-X controls need to be enabled in your Internet browser. In order to ensure this, please follow the following: Open a browser window Go to Tools >> Internet Options >> Security Click 'Custom Level' and set security level as Medium and enable all Active-XControls 2. Download and Install Certificate Chain: Pre-requisite: Windows-XP SP-3, Windows Vista SP-2 or above To download and install certificate chain follow these steps. Open the Browser and go to https://nicca.nic.in Bring your mouse to Repository and Click Certificate Chain (CCA, NICCA and NIC Sub-CA Certs) Click on Download (Left Hand Side Window pane) and Click Download certificate Chain (.zip format). Save this file on Desktop or your desired location.
Unzip this file with Winzip or WinRAR. This will display a number of files. Right click on chain.p7b (This Includes CCA India 2011, NICCA 2011 and NIC Sub-CA for NIC 2011) and click install certificate. This will install the certificate chain. Or you can install each certificate separately. CCA India 2011 certificate must be installed under Trusted Root Certificates only. 3. Initialise Smart Card / USB Token Initialising the Smart Card / USB Token: Insert your Smart card in Reader or plug in USB Token in the system. Run Token Management Utility Click on Token and then click Initialise Token A new window will appear. In the new window enter the following information Enter PUK: 0000 (four times zero) and confirm the same. Keep PUK as "0000" only Enter PIN: 1234 or as desired by you and confirm the same This will initialise your token in 90 seconds approximately 4. Enrolment Instructions - Generating Key Pair When you enrol for a digital certificate, cryptographic keys are generated and stored on your Smart Card/USB Token. For generating the Key Pair on Smart Card/USB Token select the appropriate CSP - (SafeSign Standard-I Cryptographic Service Provider) Open the Browser and go to https://nicca.nic.in Click Member Login and login with User-id / Password issued by NIC Certifying Authority Insert your smart card in the Card Reader or USB Token in USB port of your system. Click EnrollOR Step-1 for generating your Digital Certificate key pairs. (An Electronic Form will appear, which is self-explanatory. You are required to fill in Your details as mentioned in Digital Signature Certificate Request Form and submitted to NICCA) Certificate Class: It is fixed at the time of User-id creation. Certificate Type: Select Signing Certificate or as desired or as suggested / instructed by Certifying Authority
Do you have a certificate request already generated? Click No Fill in the seven mandatory fields under "Contents of your Digital Certificate" Cryptographic Service Provider: Select SafeSign Standard-I Cryptographic Service Provider. Do not Scroll down the page with mouse wheel; it changes the selected option. To avoid this move arrow away from selected option and click left mouse-button once. Check all entries once again and Click Generate Request. (A confirmatory message will be displayed on your computer screen. Read it and Click OK). At this time you will be prompted to enter Passphrase/PIN of the smart card/usb Token.) Enter Passphrase / PIN of the smart card/usb Token. Your Digital Certificate key pair will be generated on smart card. A request Number will also be generated and displayed on your computer screen. Please note it down for further follow up. No need to go to Step-2. Go to Step-3 OR Step-4 to view the status of your DSC Request or simply click View Status on the top of the page. Once RA administrator and CA Administrators process the certificate request, your Digital certificate will be generated and authentication PIN will be sent to you on your email address. 5. Downloading Digital Certificate on Smart Card/USB Token Open the Browser and go to https://nicca.nic.in Click Member Login and login with User-id / Password issued by NIC Certifying Authority Click on View Status - This will show the status of your DSC request. If the certificate has been generated a link will be provided on the DSC request number. Click on DSC Request Number Enter Authentication PIN (Ten Digit Alphabetic code - all CAPITAL LETTERS) and click on Download. Your certificate will be downloaded on the smart card/usb Token. 6. Importing Encryption Certificate to Smart Card / USB Token:
Encryption Certificate is downloaded as file with extension.p12. This file must be uploaded to the Smart Card / USB Token. Take a backup of this file and store it securely for future needs. Run Token Management Utility Click on Digital ID and click Import Digital ID Select the Encryption Certificate file (.p12) Enter Digital ID Password. Digital ID password is your Encryption certificate request number Enter PIN of Smart Card / USB Token and click OK This will import encryption certificate on the Smart Card / USB token in 25 seconds approximately. NOTE: Until your certificate is generated and downloaded successfully, you will not be able to access these keys for use or for backup purposes. It is therefore extremely important to ensure the following until your certificate is downloaded successfully: For Smart Card / USB Token Users follow the steps till downloading. Do not format your machine Do not re-install or upgrade your internet browser If the above conditions are not met, your keys will be lost permanently and you will not be able to download your certificate. In such cases, the only option is to apply for a fresh certificate. Your digital certificate is related to the cryptographic keys stored on your machine (or Smart Card / USB Token, as applicable). Hence, it's necessary for you to download the certificate onto the same machine (or Smart Card / USB Token, as applicable) from where you enrolled for the certificate. INITIALIZING THE TOKENS WILL REMOVE ALL YOUR CERTIFICATES