RUKKENZH
Ask AI
SectionsVAT & e-invoices (ESF)
How to configure the ЭЦП to avoid loading the key with every ЭСФ issuance
Article language:🇷🇺 RU🇰🇿 KK🇬🇧 EN🇨🇳 ZH

How to configure the ЭЦП to avoid loading the key with every ЭСФ issuance

СТ
Сапа Т.И. — 1C and accounting expert, practising trainer

To prevent the system from requesting the digital signature (EDS) key every time you issue an electronic invoice, you need to link the key to a user in the settings once — then the program will use it automatically throughout the session, without re-fetching it. This is a standard technique for bulk issuance of ESF: you set up the "user — key" pairing once, and further work proceeds without stopping to select and confirm the key.

Why linking the key to a user is needed

When issuing an ESF, each document must be signed with an electronic digital signature. If the key is not assigned to a user, the program asks you to specify the path to the key file (for example, to a GOST container) and enter the password for every operation. During high-volume work — dozens and hundreds of invoices a day — this significantly slows down the process and increases the risk of errors (selecting the wrong key, extra clicks). Linking the key solves this problem: the signature is applied automatically.

How to do it

Go to the General settingsElectronic invoiceUsers section. There, click Create user and link the required EDS key to them.

After this setup, the key will be assigned to the user, and during subsequent ESF issuances the system will not request it again every time.

Step-by-step procedure

  1. Make sure you have a valid EDS key (container file) and know its password.
  2. Open General settingsElectronic invoiceUsers.
  3. Click Create user.
  4. Specify the user (the employee on whose behalf the ESF will be issued) and link the required EDS key to them.
  5. Save the setting.
  6. Check the result — issue one test or real ESF and make sure the key is applied without a repeated request.

What to consider during work

  • The signer's role. The key you link must correspond to a person authorized to sign ESF on behalf of the organization (the head, an accountant, or another authorized employee). Verify that the key data (IIN/BIN) matches your organization's details.
  • Several users. If invoices are issued by different employees, you can create a separate user for each and link the corresponding key. Then the system will use the key of whoever performs the operation.
  • One session. Automatic substitution works within the current work session. After restarting the program or logging in again, the setting is preserved, but the key password may be requested again — this depends on the password storage parameters.
  • Updating the key. The validity period of the EDS certificate is limited. When a new key is issued (for example, after expiration or a change of the head), the link must be updated — replace the old key with the new one in the user settings.

Check before bulk issuance

Before starting a stream of ESF, it is useful to make sure the pairing is configured correctly and the signature passes on the IS ESF side. To do this:

  • Issue one document and track its status in the IS ESF office — it should successfully accept the signature.
  • Make sure the signer's details in the document correspond to the linked key.
  • Check that the key is not expired: if the certificate has expired, the system will produce an error when sending, and the auto-substitution setting will not help.

Common mistakes

  • The wrong key is linked. An individual's key is attached to the user instead of the organization's key (or vice versa), causing the ESF to be rejected. Check which container exactly is selected.
  • The certificate validity period has expired. Auto-substitution works, but the document does not pass when sent. The sign is a signature error or rejection on the IS ESF side. The key needs to be updated.
  • The key file was moved or renamed. If the container was in a specific folder and it was moved, the program will not find the key by the saved path. Restore the path or link the key again.
  • The setting was made for the wrong user. The key is assigned to one employee, but another one is doing the issuance — the system requests the key again. Create a user and a link for each person who issues ESF.
  • Change of responsible person. When the head or accountant changes, the old key remains in the settings — be sure to replace it with the current one.

What to check

  • The setup is done in General settings → Electronic invoice → Users, the key is linked to the required user.
  • The key details (BIN/IIN) match the data of the organization and the signer.
  • The EDS certificate is valid, the period has not expired.
  • The path to the key container file is up to date (the file has not been moved or deleted).
  • When issuing a test ESF, the key is applied automatically, and the document is successfully accepted by IS ESF.
  • A separate user with a linked key is created for each employee who issues invoices.

After proper setup, everyday ESF issuance proceeds without stopping to select a key — the program applies the signature automatically, and the accountant only needs to monitor the certificate's validity and the correctness of the signer's details.

Read also

Sources

🔎 ESF system — is the outage on the government side or yours? Check whether it works right now: independent automated checks, 90-day history.
Was this article helpful?
💼 Need help with 1C or accounting? Слава КВЦ — many years of 1C practice in Kazakhstan. Explore the annotated Tax Code of RK 2026 or ask in the BuhGPT chat — answers in seconds.