Root certificates

NCA (RSA) pki_rsa
NCA (GOST) pki_gost
RCA (RSA) root_rsa
RCA (GOST) root_gost

certificate revocation list

NCA (RSA) CRL Delta CRL
NCA (GOST) CRL Delta CRL

You want to reissue the EDS? Jump to Site >>

Вопрос-Ответ

Frequently Asked Questions

  • What is NCA RK?

    National Certification Authority, Republic of Kazakhstan is intended for providing individuals and legal entities in the Republic of Kazakhstan with digital signature facilities. To that effect, NCA RK provides issuance of registration certificates (certificate). Certificates are issued for free.

  • What basic legal acts govern the activities of NCA RK?

    Law of the Republic of Kazakhstan No. 370-II of January 7, 2003 “On e-Document and Digital Signature”; Standard for the public service: “Issuance and Revocation of Certificate by National Certification Authority, Republic of Kazakhstan approved with Resolution by Government of the Republic of Kazakhstan No.1241 of September 25, 2012.

  • What is a certificate?

    A hard-copy document or an e-document issued by Certification Authority to certify the digital signature’s compliance with requirements determined by Law of the Republic of Kazakhstan No. 370-II of January 7, 2003 “On e-Document and Digital Signature”.

  • What types of certificates does NCA RK issue?

    1) Digital signature certificate: a certificate intended to identify the person signing the e-document.
    2) Authentication certificate: a certificate intended to identify the person going through the procedure of accessing (authentication) a web resource or an IS.
    3) SSL certificate: a certificate intended to be used by a web resource or by an IS to enable the authentication procedure.

  • To whom and how many certificates does NCA RK issue?

    1) Upon one application from an individual, two certificates are issued at a time (for digital signature and for authentication).
    2) Upon one application from a legal entity, two certificates are issued at a time (for digital signature and for authentication).
    3) Upon one application from an e-NOTARY user, two certificates are issued at a time (for digital signature and for authentication).
    4) Upon one application from a TREASURY IS user, two certificates are issued at a time (for digital signature and for authentication).
    5) Upon one application from an individual for issuance of SSL, one SSL certificate is issued at a time.
    6) Upon one application from a legal entity for issuance of SSL, one SSL certificate is issued at a time.
    7) Upon one application from a foreign state national (an individual), two certificates are issued at a time (for digital signature and for authentication).
    8) Upon one application from a foreign state national (a legal entity), two certificates are issued at a time (for digital signature and for authentication).

  • What validity period do NCA RK certificates have?

    Validity period of all certificates issued by NCA RK is 1 year after the date of issue. Upon expiry of this period, certificates of NCA RK are invalid. The period of 1 year is established with a view to ensuring the robustness of cryptographic keys and restricting the time of possibility for intruders to figure them out, as well as to keeping actuality and optimal size of the certificates revocation list.

  • What is digital signature?

    Digital signature refers to a set of electronic digital characters generated by digital signature facilities and confirming authenticity of an e-document, its ownership and integrity of its content. Digital signature is equivalent to a signatory’s handwritten signature and involves equal legal consequences when fulfilling the terms according to Law of the Republic of Kazakhstan No. 370-II of January 7, 2003 “On e-Document and Digital Signature”. Once you are issued the digital signature certificate, you can sign e-documents using the private key that corresponds to such certificate. Your signature on the e-document will be verified against the respective certificate attached to it.

  • What are private and public keys?

    Private key is used to generate digital signature. To verify a digital signature, the public key is used that corresponds to the private key applied at computing the digital signature. Subject to usage of robust digital signature algorithm, no one can forge digital signature. NCA RK may not issue a certificate if an applicant does not have his/her private and public keys. Therefore, to generate them, NCA RK provides applicants with cryptographic information security facilities certified in the Republic of Kazakhstan (CISF, Cryptoprovider). To date, this has been implemented in the application submission procedure for obtainment of certificates at www.pki.gov.kz using Java. That is, once an applicant submits application for obtainment of certificate on the pki.gov.kz website, the generation of private and public keys takes place on his hardware (i.e. PC or a key information media). Upon identifying the applicant in CSC, NCA RK issues the respective certificate based on his/her public key.

  • On what hardware may the keys and certificates be stored?

    An applicant, when submitting application for certificate on pki.gov.kz website, may choose between the following hardware as a storage place:
    1. Your computer: in this case, the keys and certificates will be stored on hard disc or file systems of other personal computer’s devices as files protected with PIN code. The advantage of such storage place is that these files can be easily used, while its disadvantage is that there is a possibility of unauthorized copying of such files.
    2. Kaztoken: in this case, keys and certificates will be stored on external media named Kaztoken protected by PIN code. The advantage of such storage place is that private keys can not be copied, while the disadvantage is that the media must be purchased for money.
    3. ID card: when choosing this method, the keys and certificates will be stored on ID cards of citizens of the Republic of Kazakhstan with electronic media. The advantage of such storage place is that private keys can not be copied, while the disadvantage is that there is the need to purchase card-reader for money.
    4. KorganS: is this method is chosen, the keys and certificates will be stored on external protected media, KorganS. The advantage of such storage place is that private keys can not be copied, while the disadvantage is that the media must be purchased for money.

  • Where can I use digital signature?

    Using digital signature, any citizen of Kazakhstan may, first of all, use public e-services on the e-Government portal (www.egov.kz) and via public access points that are available in akimats, CSCs, and National Pension Payment Centers throughout Kazakhstan. Digital signature may also be used in other information systems integrated with NCA RK.

  • Where is IIN (Individual Identification Number) in ID card?

    In ID cards of a new standard (with electronic media), IIN is on the front side in the right bottom corner. In ID cards of previous standard, IIN is on the reverse side in the top left corner above the barcode, or on the front side, under the date of birth.

  • What shall I do if there is no IIN on my ID card?

    If your ID card is an old-standard one and has no IIN, you need to apply to citizen service center at your place of residence to obtain IIN or to change the ID card.

  • How can an NCA RK certificate be revoked?

    1. To recall the registration certificate on their own, without going to the Registration Center (CSC), you need to go to the personal account and produce a review, according to the instructions. To recall registration certificates through the PSC, you will need to provide the approved documents in the Registration Center (CSC).

  • I have lost my private key, what shall I do?

    To implement revocation of registration certificates, you must provide the documents approved in the Registration Center (CSC).

  • How shall I check the status of my application for certificate issue?

    You need to choose a site pki.gov.kz section "status submitted» (https://nca.pki.gov.kz/service/pkiorder/status/index.xhtml), enter the application number you received and click on the button " Search ". When the status of the application - "were issued registration certificates (certificates) of the application", you can set your registration certificates (certificates) by storage of private keys and clicking on "Download certificate".

  • Passed the necessary documents for registration certificates in the PSC, but the status of the application are still "new".

    CHS operator when receiving the documents from the user should immediately verify their correctness or to report a reasoned response to the refusal to provide services. If after delivery of documents within 1 working day, the status of your application has not changed, please contact the PSC, to clarify the circumstances. If the application is filed by employees of a legal entity, the confirmation of this application must be the first head of a legal entity, then it is necessary to apply to the PSC for further confirmation of this application.

  • I would like my information system/website operate the NCA RK keys and certificates. How shall I fulfill such integration?

    Please access the “To Developers” section at http://pki.gov.kz/index.php/ru/razrabotchikam. All questions related to integrating with NCA RK please email to This email address is being protected from spambots. You need JavaScript enabled to view it.

  • While submitting application, the system replies that the code from the picture is entered incorrectly. What should be done?

    In such case, you need to clear the cache of the browser you use and update the page. If such error occurs again, you should make a screen-shot of it and apply to service desk 14-14 or email This email address is being protected from spambots. You need JavaScript enabled to view it. .

  • An error occurred when re-issuing the certificate via “personal office”?

    Very likely, you tried to sign the application using the wrong type of certificate. You must use the digital signature certificate (subject to the keys and certificates being stored on the PC, the file name for individuals starts with RSA, and for legal entities - with GOST). If such error occurs again, you should make a screen-shot of it and apply to service desk 14-14 or email This email address is being protected from spambots. You need JavaScript enabled to view it.

  • What is Smart Card Reader and where can it be purchased?

    Smart Card Reader is a device for reading the smart cards. It is used by NCA RK for recording and usage of keys and certificates on ID card of a citizen of the Republic of Kazakhstan supplied with electronic media. National Certification Authority of the Republic of Kazakhstan publishes the list of Smart Card Reader models that have passed through testing for compatibility with the new-standard ID cards (those with electronic media). To purchase this device, you may contact: 4 Tarkhan st., office 211, tel.: +7(7172) 293713; +7(7172) 293715; 18 Nemirovitch-Danchenko st., tel.: +7(727) 247 97 34; +7 (727) 354 94 72. Also, Smart Card Reader can be bought in major computer stores.

  • What does PAP mean?

    Public Access Point is intended for citizens to access the e-Government services for obtainment of informational and electronic services.

  • Is it possible for a legal entity to obtain digital signature certificate of NCA RK on ID card?

    The issue of registration certificates with electronic identity card made only for individuals.

  • There are problems with accessing or signing the documents on e-Procurement portal, salyk, and other information systems.

    NCA RK can only help you in the event of problems with certificates as such. Where everything is OK with certificates, you need first of all to apply to service desk of those systems or portals where you have problems. You may check the certificates (issued after May 1, 2012) of National Certification Authority, Republic of Kazakhstan in your “personal office” on the pki.gov.kz website using the respective User Guide, or through obtaining a public service on the egov portal, e.g. a certificate of residential address.

  • You applied for digital signature and submitted the documents to CSC. Your application’s status is: Denied by Registration Authority. What shall the Call Centre operator and user do in such case?

    CHS operator in obtaining the documents from the user should immediately inform the motivated answer about refusal in providing service. If, after submission of documents the status of your application is denied registration by the Centre, it is necessary to ascertain the reasons for appeal to the PSC in which the documents have been handed over.

  • Since what age are the digital signature certificates to be issued?

    Currently, pursuant to the opinion provided by lawyers, the digital signature certificates are issued by NCA RK to persons upon the attainment of the age of 16.

  • How to work with a protected bearer KAZTOKEN?

    pngKAZTOKEN – personal device, which is a hardware implementation of the Kazakhstan standard of digital signature, formed into a usb-stick. In order to obtain registration certificates NCA RK on media protected information KAZTOKEN, when applying under "Storage Location" you need to select «KAZTOKEN» For more information on this carrier obraschatsya recommend the following link kaztoken.kz.

  • The protected vehicle eToken

    png eToken – a private means of authentication and data storage hardware supports work with digital certificates and digital signature (the signature). eToken configured as a USB-key. eToken supports and integrates with all major systems and applications using smart card technology and PKI (Public Key Infrastructure). In order to obtain registration certificates NCA RK on support secure eToken information when applying under "Storage Location" you need to select "eToken" For more information on this carrier obraschatsya recommend the following link.

  • Re-issue electronic signature through a personal user account, in excess of 10 registration certificates.

    At the moment, there is a limitation in the form of 10 requests per month for an extension of the registration certificates NCA RK, via personal cabinet. What it is due to the technical capabilities of the software. Due to data limitations, we recommend that you carry out the extension of the registration certificates in advance.

  • Clearing Mozilla Firefox browser's cache

    To clear the browser cache on Mozilla Firefox, open the "Browser's Main Menu", select the submenu "History" - "Clear Recent History". Or use hot keys Ctrl + Shift + Del. In the opened window, click "Clear history visits", select the period of "All" time. Exhibitor, tick the desired - "the history of visits," "files cooce (Cookies)," "clear the cache", "active sessions", "Settings sites." Then click "Clear Now." In different browsers, the button names and menu location may vary slightly.

  • Clearing cache in Google Chrome

    To clear the cache in Google Chrome, open the main menu, select the “History” submenu - Clear Recent History. Or use hot keys: Ctrl + Shift + Del. In the opened window, click “Clear Recent History”, select the time range to clear “Everything”. Select the necessary checkboxes – “Browsing & Download History”, “Cookies”, “Cache”, “Active Logins”, “Site Preferences”. Then click “Clear Now”. Depending on the browser version the button names and menu locations may vary slightly.

  • Clearing cache in Opera

    To clear the cache in Opera, open the main menu, select the “History” submenu - Clear Recent History. Or use hot keys: Ctrl + H. In the opened window, click “Clear Recent History”, select the time range to clear “Everything”. Select the necessary checkboxes – “Browsing & Download History”, “Cookies”, “Cache”, “Active Logins”, “Site Preferences”. Then click “Clear Now”. Depending on the browser version the button names and menu locations may vary slightly.

  • Clearing cache in Internet Explorer

    To clear the cache in Internet Explorer, open the main browser menu "Tools", select the menu "Options". In the "General" tab in the "Istoiya viewing" click "Delete." Or use hot keys Ctrl + Shift + Del. Select the necessary checkboxes – “Browsing & Download History”, “Cookies”, “Cache”, “Active Logins”, “Site Preferences”. Then click “Clear Now”. Depending on the browser version the button names and menu locations may vary slightly.

  • Clearing cache in Java

    Clearing the Java cache To clear your cache Java, follow these steps: Open the Start (Start)> Control Panel (Control Panel). Double-click the Java icon in the Control Panel. This will display Control Panel Java. Click Settings (Settings), located in the section Temporary Internet Files (Temporary Internet Files). This will open a dialog box Temporary Files Settings (Settings temporary files). Click Delete Files (delete files). The dialog box Delete Temporary Files Settings (Delete temporary files). Click OK in the Delete Temporary Files (delete temporary files). After clearing the cache, redo your actions on the site pki.gov.kz.

FaLang translation system by Faboba