Signing your filing with your DSC
Signing your filing with your DSC
Customs will not accept a Sea Cargo Manifest declaration that is not digitally signed. This page is about how signing works in practice: what signs, what it needs on your computer, what you will be asked, and what to do when it does not work.
The short version, as of 13 September 2026: you sign inside the app. Press Sign & upload on a finished filing, and the scmtr DSC Signer — a small program installed once on your Windows computer — asks your DSC token for a signature and the platform sends the signed filing to ICEGATE. Your token asks for its PIN exactly as it does anywhere else; nothing about the filing leaves your browser before it is signed. The Signer is a free download from the app's download page, and the app offers it the moment it finds it missing.
Until 12 September 2026 the route was different: the platform handed you the file and you signed it on ICEGATE's own portal. That route still exists for anyone who cannot install software — see Do I have to install anything? below — but it is no longer the button on the filing.
Why does a filing need a digital signature at all?
ICEGATE ties every filing back to a registered filer. The signature is what proves the declaration came from you rather than from someone quoting your ICEGATE ID, and it is checked against the Digital Signature Certificate registered against your ICEGATE account.
The practical consequence: the certificate that signs must be the one registered with ICEGATE for the organisation filing. A signature from a valid but unregistered DSC is a rejection.
What do I need before I can sign?
Three things, two of which most filers already have:
- A Class 3 Digital Signature Certificate, on a USB token, issued by a CCA-India-licensed
Certifying Authority — eMudhra, (n)Code, Capricorn, Sify, Verasys and others. This is the same
token you use on ICEGATE's own portal. If you file today, you have one.Its driver installed, so Windows can see the certificate. Again, if the token works on
ICEGATE's portal, this is already done.The scmtr DSC Signer, installed once. It is what lets a web page reach your token. The
filing page tells you when it is not there and offers the download; How do I install it on
Windows? below says what to expect.
How do I sign a filing?
With Sign & upload, the button on the filing once it is complete:
- Your certificate is chosen. If exactly one usable DSC is present it is used and named on
screen. If there are several, you are asked which — see Why is it asking me which certificate
to use? below.You confirm what is going. A Send this to ICEGATE? screen names the filing — the reporting
event, job number and date, port, vessel, VCN, how many master and house bills and containers,
and the certificate that will sign — and says so if the file deletes a declaration or is only a
test. Nothing has been signed or sent yet. Send to ICEGATE stays greyed out until you tick
I have checked these details; the cursor starts on Cancel — don't send, so pressing Enter
backs out, and a double-click on Sign & upload cannot reach the Send button. Cancel leaves the
filing exactly as it was.The filing is frozen. Its exact bytes are fixed, so what you reviewed is what gets signed.Your token asks for your PIN. This is your token's own dialog, not the platform's.The signed filing is submitted to ICEGATE, and the platform checks the signature against the
frozen bytes before sending — a filing whose signature does not verify is stopped here rather
than by customs hours later.The acknowledgement arrives against the filing as usual.
The same confirmation stands in front of every upload to ICEGATE: a shipping line's SAM or SDM signed here; a CSN batch, asked once for the sitting before the first filing is signed and naming the batch, how many CSNs it holds, their master B/Ls and the certificate that will sign them (stop the batch at any time — nothing is sent twice); and a file signed somewhere else and uploaded — which used to go the moment it was chosen, and is now read first so the screen can say what it will file. The platform refuses any upload that did not come through it, so nothing reaches customs by an accidental press.
Before any of that, the platform compares your entries against ICEGATE's own arrival manifest and pauses you on a disagreement. A manifest that is simply not there yet is silent.
What is the scmtr DSC Signer?
A web page cannot reach a USB token on its own — browsers deliberately have no access to smart cards. Every Indian portal that signs in the browser solves this the same way: a small program runs on your computer and the page asks it to sign.
The scmtr DSC Signer is ours. It runs quietly in the background, and when a filing needs signing it asks your token, which prompts you for your PIN exactly as it does anywhere else.
Three things it deliberately does not do:
It never sees your declaration. The platform sends it only a short mathematical fingerprint of the frozen filing — 32 bytes — not the consignee, the bill of lading, or anything else on it.
It never sees your private key. The key stays on the token; the token does the signing.
It signs for this platform's own website and for nothing else. The list of sites it will
answer is built into the program — scmtr.io and www.scmtr.io — and any other page asking it
to sign is refused outright.
Earlier builds asked you instead: the first time a site wanted a signature, a dialog named the site and you allowed or blocked it. That was removed, because it was weaker than it looked. A prompt asking "allow this site to use your Digital Signature Certificate?" is exactly the shape a phishing page wants, on a lookalike domain where the honest expectation is that most people click Allow — and once allowed, a site signed silently for ever afterwards, so it did nothing at all against the realistic case of a page that is already trusted. A fixed list is not something you can be talked out of. If you are running the Signer and it refuses to sign, you have not blocked anything and there is nothing to un-block — see the troubleshooting section below.
How do I install it on Windows?
Download the installer for your machine — Intel/AMD unless you know you have a Windows-on-ARM device — and run it. What to expect:
- Windows may warn you the first time. "Windows protected your PC", with the button hidden
behind More info → Run anyway. The installer is code-signed, by TAGQA Pty Ltd, the
company that operates SCMTR.io — so check that the dialog names that publisher before you click
through. The warning appears because Windows builds reputation for a signing certificate from
the number of clean installs it has seen, and this one is new; see Will Windows warn me?.It needs no administrator rights. The Signer installs under your own user profile and
touches nothing machine-wide, which is why it does not need IT to approve the install — though
your IT department may still want to read the download page first, and it is written for them.The installer asks nothing. It has no directory to choose and no options; a progress bar,
then done. The Signer starts as soon as it finishes. The file in your Downloads folder is
only the installer — the Signer itself is installed under your user profile
(
%LocalAppData%\Programs\scmtr DSC Signer), so you may delete the download afterwards and
signing keeps working. If deleting it did stop signing, you were running a build from before
1.0.0, which was a bare program with no installer: run the current installer once.Nothing visible will happen when it starts — no window, no message. It sits in the
notification area (the system tray) with the scmtr mark; right-click that icon to see its
version and port, open its log file, or quit it.It starts with Windows from then on, and restarts itself if it stops unexpectedly. You do
not have to launch it before filing. If that is not what you are seeing, the next answer but
one is yours — versions before 1.1.1 arranged this less reliably than they were meant to.Plug in your DSC token, with its driver installed. On Windows the Signer reads your
certificate from the Windows certificate store, so there is no file to choose and no password
to type into the Signer itself.To confirm it is running, open http://127.0.0.1:13913/health in any browser. A short block of text that includes a version means yes; a connection error means it is not running — start it from the Start menu (scmtr DSC Signer).
You can check what you downloaded against the published checksums with PowerShell:
Get-FileHash $HOME\Downloads\scmtr-dsc-signer-1.1.1-win-x64.exe -Algorithm SHA256Do I have to start the Signer every time I restart my computer?
No. It is meant to start by itself when you sign in to Windows, and from version 1.1.1 it checks that this is actually set up every time it runs, and sets it up again if something has removed it.
If you are starting it by hand after every restart — or worse, installing it again, which some filers were doing — one of these is why:
- You are on a version before 1.1.1. Those installers tried to register a Windows scheduled
task that, on any computer where you are not an administrator, Windows refused: the task was
written in a way that asked to run for every user of the machine, which only an administrator
may set up. Nothing said so. The installer's simpler fallback still started the Signer at
sign-in, so most filers never noticed — until something removed that fallback too (see below),
at which point nothing started it at all. Installing 1.1.1 over the top fixes it; there is
nothing to uninstall.Antivirus or a "PC cleaner" removed the startup entry. Both do this to startup entries as a
matter of routine. 1.1.1 puts it back by itself the next time the Signer runs, so starting it
once from the Start menu is enough to repair it.You switched it off, usually while chasing a slow start-up: Task Manager → Startup apps
→ scmtr DSC Signer. The Signer will not turn itself back on — that is your setting, not
ours — so turn it back on there.Your IT department's policy forbids it. On a locked-down desktop neither the scheduled task
nor the startup entry may be allowed. The 1.1.1 installer says so on its last screen rather than
finishing silently, and your administrator has to permit one of them.
To see which of these it is, the Signer will tell you. In a Command Prompt:
"%LocalAppData%\Programs\scmtr DSC Signer\scmtr-sign.exe" -autostart-statusIt prints one line — Starts at sign-in: yes, or NO with the reason — and exits without
disturbing the copy that is running. The same line is in the tray icon's right-click menu. If it
says anything but yes, send us that line and we can tell you exactly what to do.
The app also watches for this. Since 23 September 2026, if the Signer tells the app it will not start again after a restart, the filing form says so in a small banner while you are filing — when it costs nothing — rather than leaving you to find out the morning it has gone. The banner never blocks anything; the filing you are working on is unaffected.
The app says my Signer is out of date — how do I update it?
Download the current installer from the download page and run it over the top. That is the whole update: the installer recognises the existing install, closes the running copy, replaces it and starts the new one. There is nothing to uninstall first, and nothing about your filing changes.
The app refuses to sign with a Signer older than the version it was built against, and says so with both numbers — "version 0.1.0, but signing here needs 1.0.0 or newer" — rather than letting an old build fail later in a way nobody can read. The floor only moves when an older Signer genuinely cannot be trusted to produce a correct filing, not on every release.
Will Windows warn me when I install it?
Possibly, the first time — and if it does, read the name on the dialog. The installer and the program inside it are signed by TAGQA Pty Ltd, the company that operates SCMTR.io and is named as your counterparty in the Terms, with a timestamp so the signature stays valid after the certificate itself expires. That is the publisher to expect wherever Windows names one, rather than "SCMTR"; a dialog that says Unknown publisher is not our installer.
Signing does not make the SmartScreen prompt disappear on day one. Windows carries a signing certificate's reputation forward across releases, and only stops prompting once a certificate has accumulated enough clean installs — which for a tool used by a few hundred filers takes a while. What signing bought immediately is that Windows 11's Smart App Control no longer blocks the file outright, and managed desktops that hide "Run anyway" can run it at all. Verify the checksum and the publisher name; do not wait for the warning to disappear.
I am on a Mac — is it different?
Yes, and macOS support is mainly there for testing rather than day-to-day filing.
The easiest route is one line in Terminal, which fetches the right build for your Mac, checks it against the published checksums, and installs it:
curl -fsSL https://downloads.scmtr.io/install-mac.sh | shIt is a short script; you can open that URL and read it first, or download and run it separately if you would rather not pipe anything into a shell.
Why not just double-click the download? Because macOS tags anything downloaded by a browser,
the unarchiver passes that tag to the program it extracts, and Gatekeeper then refuses to run an
unsigned program at all — "Apple could not verify 'scmtr-sign' is free of malware…". That message
is about the tag, not about the program: the Windows code-signing certificate signs Windows
programs only, and the macOS build is unsigned. Installing with the command above avoids the
problem entirely, because curl sets no such tag.
If you have already hit it, clear the tag once:
xattr -d com.apple.quarantine ~/Downloads/scmtr-signOn recent macOS the old right-click → Open shortcut no longer bypasses this; the command above, or System Settings → Privacy & Security → Open Anyway, are the routes that work.
The second difference: a Mac has no Windows certificate store, so the signer reads your DSC from a
PKCS#12 (.p12) file rather than from a USB token. If you file on Windows — as almost all filers
do — none of this applies: download, run, done.
Do I have to install anything if I would rather not?
To sign inside the app, yes — a web page cannot reach your token without it. If you cannot install software on your work machine, the route that needs nothing installed is still there: when Sign & upload finds no Signer on the computer, the dialog that offers the download also offers Sign on ICEGATE. That downloads the frozen filing, you sign it on ICEGATE's own file-signing page with your DSC token, and you upload the signed file back to the same filing; the platform checks it is byte-for-byte the file it issued and that the signature verifies before anything is submitted.
One thing to watch on that route, because you are handling the file yourself between download and
upload: leave its name alone. ICEGATE reads the filing's details out of the file name and
rejects anything that does not match the expected seven parts — including a name your browser has
quietly turned into … (1).json by downloading it twice. See Filename convention in
Every reference number, who issues it, and when.
Why is it asking me which certificate to use?
Because more than one usable Digital Signature Certificate was found on the computer — commonly a colleague's token left plugged in, a renewed DSC sitting alongside the one it replaced, or a personal certificate next to the business one.
The platform will not guess. Signing with the wrong certificate produces a filing that looks perfect and is rejected by customs hours later, so you are asked — with each certificate's holder name, organisation, issuing authority, validity dates, serial number and thumbprint shown.
Pick the one registered with ICEGATE for the organisation this filing is for. If one of them belongs to the person named as the filing's authorised representative, it is marked The filing's authorized representative — a label to help you find it, nothing more. Where two entries share a name, work down that list: the issuer separates a personal certificate from the organisation's, the dates separate a renewed certificate from the one it replaced, and the serial number and thumbprint separate two renewals from the same authority that agree on everything else. Those last two are also what ICEGATE support asks you to read out, so they are shown in a monospaced font, a character at a time.
With only one usable certificate there is no question to ask, so none is asked — but you are still told whose it is. While your token is being asked for its PIN, a Signing as line on the screen names the holder, the organisation, the expiry and the thumbprint of the certificate about to sign. Your token's own PIN dialog belongs to Windows and names neither the filing nor the certificate, so if a colleague's token is plugged into the same machine, that line is where you find out before customs does.
What is the authorised representative PAN — must it be the person whose DSC signs?
authReprsntvCd, labelled Authorized representative PAN, is what ICEGATE's message guide calls
the PAN of authorised person: the person authorised to file for the submitter. It does not have
to be the person whose DSC signs the filing, and it can be your organisation's own PAN.
Customs has accepted filings both ways. Proprietors file with their own PAN as both submitter and representative. Companies we have seen name either the person who files — with the company's PAN as the submitter — or the company's own PAN in both places, and a signed filing whose representative was the company's PAN, signed with an employee's DSC, is on customs' own record as accepted. So nothing in the platform warns when the two differ.
Where it comes from. Settings › Filing profile › Authorized representative PAN holds your organisation's default, and every new filing starts with it. Leave it blank and the PAN in your submitter code is used. You can change it on any filing — under Filed by in the guided steps, or Authorized person in the full form. Before 15 September 2026 the platform copied the submitter code into it and did not let you change it; nothing about filings made that way needs correcting.
What does have to match is the consolidator PAN, which is a different field on each bill:
ICEGATE's error 158 requires it to be the submitter's PAN. The platform fills it from your
submitter code — and only if your submitter code is not a PAN at all, from the representative.
My DSC was renewed or replaced — why does filing fail now, and what do I do?
A renewed DSC is a new certificate, even for the same person from the same authority. ICEGATE's FAQ is explicit that the DSC used to sign a file must be the one registered for your ICEGATE ID, so until the new certificate is registered there, ICEGATE answers a filing signed with it by e-mail: "DSC validation failed … Please use a valid DSC". Nothing in the filing itself is wrong.
- Register the new certificate on your ICEGATE ID. This is done on ICEGATE, not here. We have
not documented ICEGATE's own steps for it; if the portal's profile pages do not make it obvious,
the ICEGATE Helpdesk can tell you.Sign the filing again with the new certificate and send it with a new control number — the
failed transmission was received, so its number is used.Retire the old certificate from the computer if it is still there, so it is not picked by
mistake. Until then the certificate picker lists both, with their dates.
The file checks below help you tell: signed in, a file signed with a certificate your organisation has never had an accepted filing with — especially a new one for the same person — is flagged, and Compare with the DSC on this computer shows whether your token holds a newer certificate than the one that signed.
Which certificates will it offer me?
Only ones that could actually sign a filing. A certificate is left out when it:
- has no private key available (it is a copy of somebody's public certificate, not a token)is expired, or not yet validis marked for encryption only, so it cannot signdoes not look like a CCA-India Digital Signature Certificate
You are told which of these applied. The Signer works out a reason for every certificate it leaves out and the platform shows it — "ASHA RAO — this certificate is expired or not yet valid", against that name — both in the picker, underneath the certificates you can choose from, and in the message you get when nothing at all can sign. So the three problems that used to produce one sentence now produce three different ones, because they need three different things done: plug the token in, renew the certificate, or check it is a CCA-India DSC rather than some other certificate that happens to be installed.
Signer versions before 1.1.0 wrongly left out Care4Sign certificates as not looking like a CCA-India DSC. If yours is a Care4Sign DSC and it is refused for that reason, install the current Signer over the old one — the app does not prompt for this update, because older Signers still sign every other certificate correctly. From 1.1.0 the Signer also confirms each certificate's chain to CCA India, as well as recognising the authority's name.
If nothing is listed at all — no usable certificates and nothing refused either — then the computer has no DSC on it as far as Windows is concerned, and the usual cause is simply that the token is not plugged in.
Nothing happens when I press Sign & upload
Work through these in order.
- Did your browser ask whether scmtr.io may access other apps and services on this device?
Chrome asks that the first time the platform reaches for the Signer, and the answer is
Allow — the question is about the Signer, which runs on this computer, and nothing else. If
it was blocked, the platform says so rather than reporting the Signer missing: click the icon
at the left of the address bar, open Site settings, set Local network access to Allow, and
reload. If you closed the question without answering, the platform says that too — press
Check again and choose Allow when it reappears. Firefox and Safari do not ask.Is the scmtr DSC Signer installed and running? If it is not, the platform says so: a dialog
offers the download for your machine and a Check again button — install it, then press that
rather than beginning the filing over. If it is installed, look for the scmtr icon in the
notification area, or open http://127.0.0.1:13913/health; a connection error means it is not
running, and the Start menu entry scmtr DSC Signer starts it.Is it current? The platform refuses a Signer older than it needs and names both versions.
Run the current installer over the old one — see The app says my Signer is out of date.Are you on the real address? The Signer answers
scmtr.io and www.scmtr.io and refuses
every other address, so a preview link, a staging address, or a bookmark to an old domain is
refused however good your token is. There is no dialog and nothing to allow — if this is the
problem the platform says which address it was refused for, and that address is the answer.
Go to https://scmtr.io and open the filing there.Is your token plugged in? If it was inserted after the Signer started, it is still found —
the certificate list is read fresh each time.Does the same token sign on ICEGATE's own portal? If it does not, the problem is the token
or its driver, not this filing.Why did the digital signature disappear from my filing?
Because you changed the filing. A digital signature covers the exact content it was made over — change any field afterwards and the old signature is a signature over something that no longer exists. The moment you edit a signed draft, the app removes the stale signature and says so on screen. Nothing is lost: sign the current content again when you file. The same applies to a signed file you import — the import gives it a new transmission identity, so the old signature could never verify and is not carried in.
How do I check my DSC, or whether a signed file's signature is valid?
Drop a _DECSigned file on SCMTR JSON upload (signed in), or on the free check at
https://scmtr.io/check with no account, and a Digital signature (DSC) panel lists every check
it ran — the ones that pass included, and the ones it could not run marked not checked. When
ICEGATE has said "DSC validation failed" and nothing else, that list rules out the causes a file
can show and flags the one that looks likely; it cannot see which DSC ICEGATE has registered, which
only ICEGATE knows.
Nothing needs installing for any of these. The panel names the certificate as ICEGATE support would ask for it — holder, organisation, issuing authority, validity, class, serial number and thumbprint — says whether its holder is the person named as the filing's authorised representative (information only: customs accepts filings either way), and then checks:
| Check | What it looks at | When it is red or amber |
|---|---|---|
| The signature matches the file's exact contents | The signature, verified over every byte, the way customs verifies it | Red when it does not verify — with what happened where the file shows it: line endings changed by an editor, content added after the signature block, or a file signed by a general-purpose signing tool instead of a JSON filing utility (each of these is proven by re-verifying the undone change), or characters that are no longer valid text, which points to a file re-saved in another encoding |
| The certificate is in date | Its validity dates | Red when expired or not yet valid. Amber from 30 days before it expires, because a renewed DSC has to be registered on your ICEGATE ID before it can file, and urgently in its last three days |
| This DSC has signed a filing customs accepted (signed in only) | Your organisation's accepted filings sent with Sign & upload — a filing signed on ICEGATE's portal keeps no signature here to compare | Amber for a new certificate — especially a new one for someone whose earlier DSC signed accepted filings, which is what an unregistered renewal looks like. Not checked when your organisation has no such filings, and on the free check |
| Not revoked | The certifying authority's own revocation service (OCSP), answer signature verified | Amber when the authority says it was revoked, with the date and reason |
| Chains to CCA India | Each authority's certificate, fetched and verified up to the CCA India 2022 root | Amber when the chain leads somewhere else, or the published issuer did not sign it |
| A Class 3 certificate | The CCA class policy in the certificate | Amber when it is not Class 3 |
| A signing certificate, not an encryption one | Its key usage | Amber for an encryption certificate — tokens often hold one of each under the same name |
| Issued by an authority in India | The issuer | Amber for a self-signed, test or foreign certificate |
| An RSA key of 2048 bits or more | The key | Amber below 2048 bits or for a non-RSA key |
| The signature block is where the utility writes it | The digSign block's position and layout | Amber for a file signed twice, missing or extra fields, a wrapped certificate, or a re-formatted block — ICEGATE's "signature tag is misplaced" |
A file that begins with an invisible byte-order mark gets one more amber line: ICEGATE's signing utility never writes one, so the file was opened and re-saved after it was made.
Red means customs refuses it; amber means fix it before you send. Red is kept for what customs is known to refuse — a signature that does not verify, a certificate out of date. The rest are amber because no acknowledgement we hold proves ICEGATE refuses for them, however likely.
The revocation and chain checks ask the certifying authority, so they appear a moment after the rest. If an authority does not answer in time — or is not one whose addresses we know yet — they say not checked, which says nothing about the DSC; drop the file again to retry. Only the certificate is sent to our server for them, and the only addresses contacted are CCA India's and the certifying authorities' own. The free check does not keep the file, unless you press the button to continue with it after signing in, which holds it for 30 minutes.
Can I compare a signed file with the DSC on my computer?
Yes, on the same panel: Compare with the DSC on this computer. It uses the scmtr DSC Signer, so the Signer must be installed and running (the panel offers the download when it is not). It is never run on its own — press the button when you want it. Nothing from the file leaves your browser; the Signer is only asked which certificates it holds. It tells you:
- whether the token plugged in here signed this file. If it did, every check above passed, and
ICEGATE still says "DSC validation failed", the likeliest cause left is that this certificate is
not the one registered on your ICEGATE ID.whether the token holds a renewed certificate for the same person that the file was not
signed with, or the other way round — and which of the two is newer, so you know which one
ICEGATE needs registered and which to sign with.that none of the certificates here signed it, when it was signed somewhere else.which certificate, if any, belongs to the filing's authorised representative, marked in the
list with each certificate's expiry, and the Signer's reason for any certificate it cannot sign
with.
It says the signature does not match the filing
The signature covers the exact text of the declaration as it was when it was frozen. If the declaration changed after that — a field edited in another tab, or a file signed earlier and reused — the signature no longer matches, and the platform refuses it rather than sending customs something you did not review.
Start a fresh Sign & upload. On the Sign-on-ICEGATE route, download the file again before signing; do not re-sign an older download.
It says my certificate is not valid today
The DSC has expired, or has not started. Customs rejects a filing signed with an expired certificate, so the platform stops it first. Renew the certificate with your Certifying Authority, register the new one with ICEGATE, and sign again.
Registering it with ICEGATE is not an optional last step. The certificate you sign with must be the same one registered against your ICEGATE ID — a perfectly valid, in-date DSC that ICEGATE does not have on file is rejected exactly like an expired one, with ICEGATE emailing you a bare "DSC Failed". This is the usual explanation when signing suddenly starts failing and nothing about the filing has changed: the certificate was renewed or replaced, and the registration was never updated to match.
ICEGATE says "DSC validation failed" — what does it check?
The message arrives by e-mail, worded like "DSC validation failed for control no. …, filing date …, Receiver ID …, message ID SACHM22 … Please use a valid DSC", or from the Open API as the bare "Digital Signature (DSC) validation failed." It is customs' own verification of the signature block failing, and ICEGATE has published what it means and what to do, in two documents:
- Its 2025 FAQ on SCMTR registration and filing (Q20, "DSC Failed"): the DSC details are
invalid, expired or incorrect; or the details are valid but the signature tag is misplaced
in the file; and the DSC used to sign the file must be the one used for ICEGATE
registration. Re-file with valid, correct DSC data.Its 2022 message-filing FAQ, on why an acknowledgement never comes: use the DSC that was
registered at ICEGATE; use the correct signing utility for JSON — ICEGATE's own, not a
general-purpose signer; do not open the file after it has been signed; send it from the
same computer that signed it; and if there is an error, open a fresh file, correct it, sign
it and send it without opening it again.
Start by dropping the signed file you sent on SCMTR JSON upload, or on https://scmtr.io/check. Its Digital signature (DSC) panel checks the causes below that a file can show and flags the likely one (see How do I check my DSC, or whether a signed file's signature is valid?). If you still have the DSC token, press Compare with the DSC on this computer too. Read against a real failure, the causes fall into these groups, in the order worth checking:
- The certificate is not the registered one. The most common. A renewed or replaced DSC that
was never re-registered against the ICEGATE ID fails exactly like an expired one. The panel's
history check flags a new certificate — and says so plainly when it is a renewal for someone
whose earlier DSC signed accepted filings — and the token comparison shows whether your token
holds a newer certificate than the one that signed — see My DSC was renewed or replaced above.
ICEGATE's general FAQ adds the class it wants: a Class 3 certificate.The file changed after signing. Opening a signed JSON in an editor that re-saves it, a
download that became
… (1).json, or a re-sign of an older copy all break the match between
signature and bytes. The panel proves this and, where the file shows it, names the change —
line endings, a text encoding, content added after the signature.The certificate itself. Expired, revoked by its authority, an encryption certificate picked
instead of the signing one from the same token, not Class 3, or not issued under CCA India.The signature block is in the wrong place or the wrong shape — "tag misplaced" in
ICEGATE's words. The digSign block has to sit where the MIG puts it, with the signature,
certificate and signer version fields as ICEGATE's utility writes them, once.Not a cause: the authorised representative PAN. A filing whose representative is someone other than the DSC holder — or the company's own PAN — is accepted; see What is the authorised representative PAN? above.
The one thing none of the published causes includes is the filing's content. A DSC failure is not a rejection of the declaration, and nothing inside the cargo data needs to change. Sign a fresh copy of the same file correctly and send it again — with a new control number, since the first transmission was received.
I cancelled the PIN dialog — what state is my filing in?
Nothing was sent, and nothing was filed. Press Sign & upload again when you are ready; the same frozen version is reused rather than a second one being created, as long as the filing has not changed in between.
Is my filing data sent anywhere while signing?
No. The declaration stays between your browser and the platform. What goes to the Signer on your computer is a 32-byte fingerprint of the frozen filing and nothing else — it cannot be turned back into the declaration, and the Signer has no network access to anywhere but your own machine.
Your private key never leaves your token, and the platform never holds it.
Still stuck on this?
The assistant answers from this exact page and the rest of our reference material, and names the documents behind every answer.
Have the file? Check it free — no sign-in
General information only — not legal or customs-compliance advice, and it may not reflect the most current ICEGATE/CBIC requirements. Verify against the official sources, or a licensed customs broker, before filing.