Customs & Clearance
IGCR Clearance SVB Registration ICEGATE Registration AD Code Registration MOOWR Scheme Importer of Record (IOR)Codes, DSC & Setup
IEC Registration IEC Renewal DGFT Digital Signature Class 3 DSC Export Promotion Bank A/c Foreign Company SetupEPR (CPCB)
EPR Plastic Waste EPR E-Waste EPR Battery WasteCertifications & Licenses
BIS Certification WPC Certificate FSSAI Export License Certificate of Origin View all services →
ICEGATE PKI is the client side component that lets the customs portal see the Digital Signature Certificate in your USB token. It runs on your own machine, not on icegate.gov.in. When it is missing, blocked by the browser or installed the wrong way, signing fails and Bill of Entry filing, Shipping Bill submission, e-Sanchit uploads and DSC registration all stop with it.
This guide covers the install sequence, the browser settings most guides leave out, and what each error means. If the certificate still will not register, our ICEGATE registration process service handles it end to end.
PKI stands for Public Key Infrastructure. On ICEGATE it means something narrower: a small Java based service on your laptop that bridges your browser, your DSC token and the portal. Signing happens locally, and ICEGATE PKI is what lets the browser reach the private key on your token.
The component and the Common Signer Utility are one download, not two. On icegate.gov.in go to Services, then Digital Signature Certificate, then Common Signer Utility. The link labelled Download Signer utility delivers PKIComponent.zip, which installs nCodePKIComponent.
| Requirement | Detail |
| DSC | Class 3 signing certificate from a CA licensed under CCA India. Encryption only certificates fail validation |
| Name match | Holder must be the authorised signatory on the ICEGATE profile |
| Java | Java 1.8 only, 32 or 64 bit. No other version is supported |
| Windows account | Local administrator rights, with read and write permission |
| Token drivers | ePass, ProxKey, mToken, WatchData or whichever your CA issued |
| Browser | Chrome, Edge or Firefox |
Java is the row people get wrong. Being applet free is why the component runs outside Internet Explorer, but it is still a Java application. If more than one version is installed, remove the rest and keep only 1.8. No certificate yet? Start with a Class 3 DSC.
Plug it in first and confirm the token software sees it.
Use the Common Signer Utility page on icegate.gov.in or filesign.icegate.gov.in. Third party installers circulate widely and some carry adware.
A PKIComponent.zip smaller than 100 MB means the bundled Java payload is missing. Install Java 1.8 manually first, or the component will not start.
Right click the ZIP, choose Extract All, and extract locally rather than to a network drive.
Double click the installer. Do not right click and choose Run as administrator. Your account needs administrator rights, but running the setup elevated is the most common cause of an ICEGATE PKI component that installs and then refuses to connect.
Choose 32 bit or 64 bit to match your operating system, not your browser.
The component starts automatically and an icon appears in the Windows system tray. No icon means the install did not complete. Reinstall before testing anything else.
The component listens on your own machine at https://localhost:13591, and on http://localhost:12951 in some builds. Browsers block that by default, producing a connection error even when the install is perfect. Open the address first. If it loads, ICEGATE PKI is running and the fault lies elsewhere.
| Browser | Setting to change |
| Chrome | chrome://flags/#allow-insecure-localhost, enable it, restart Chrome |
| Edge | edge://flags/#block-insecure-private-network-requests, set to Disabled |
| Firefox | Open https://localhost:13591 and add a security exception |

Installing the component does not authorise you to file. Log in, open My Profile or Services then Digital Signature, select Register DSC, pick the certificate, enter the token PIN and submit.
No documents are needed, but consistency is essential. The registered email and mobile must match GSTN and, for importers and exporters, DGFT records. Unsure which identifier goes where? See ICEGATE ID vs IEC. DGFT side signing needs a separate DGFT digital signature. When a certificate expires, register the replacement the same way. There is no grace period.
| Error | Cause | Fix |
| PKI component not found | Not installed, not running, or installed with Run as administrator | Confirm the tray icon, reinstall without elevating the setup |
| Error connecting to PKI component | Browser blocking localhost, or antivirus intercepting the request | Apply the browser settings above, then whitelist the component |
| Still not connecting after reinstall | Stale certificate configuration | Exit from the tray icon, run installCert.bat as administrator from the install folder, then run_32.bat or run_64.bat |
| DSC not detected | Token drivers missing, or a USB hub in the way | Install CA drivers, plug directly into the machine, try another port |
| Long delay after selecting the certificate | CRL check timing out | Check the CRL URL in the certificate opens and is not blocked by a proxy |
| Works on one machine, not another | The component is per machine, not per account | Install on every workstation used for signing |
When the component rejects a certificate it shows a list of checks marked true or false. Each false has one meaning.
| Check reading false | What it means |
| Date validation | Certificate expired, or the system clock is wrong |
| Has private key | You picked an installed .cer file, not the certificate on the token |
| Certificate chain installed | Root and intermediate certificates missing from the machine |
| CA validation | Issuing CA is not licensed under CCA India |
| Class validation | Wrong DSC class for the portal |
| Is signing allowed | You are signing with an encryption certificate |
| CRL validation | Certificate revoked, or the CRL URL is unreachable |
ICEGATE PKI is software on your own machine, and that single fact explains almost every error users hit. Install it with Java 1.8 present, without elevating the setup, confirm the tray icon, unblock localhost, and register a valid Class 3 signing certificate. When something breaks, check localhost:13591 first, then the validation screen.
If the certificate still will not register, the details usually conflict with your PAN, GSTN or DGFT records.
JPARKS INDIA resolves exactly that and has supported 500+ importers and exporters since 2018. Write to [email protected] or start with our ICEGATE registration process service.
In practice, yes. The Download Signer utility link delivers PKIComponent.zip, which installs the component. There is no separate download.
Yes. Java 1.8 is required and no other version is supported. Being applet free is why it works in Chrome and Edge, but it is still a Java application.
No. Your account needs administrator rights, but do not right click and choose Run as administrator. That causes connection failures afterwards.
Either it is not running, or the browser is blocking localhost. Check the tray icon, then open https://localhost:13591.
Yes. It is machine specific, not account specific.
GST uses emSigner. ICEGATE uses its own PKI component. One certificate can be valid on both while only one utility is installed.
The ICEGATE helpdesk on 1800-3010-1000 or [email protected], available 24×7. Have your ICEGATE ID, component version and exact error text ready.
Need this handled for you?
Tell us where you are stuck. We usually reply the same business day.
5.0 ★ · 126 Google reviews · Since 1990
EXCELLENT Based on 126 reviews Posted on Google Vandana BajajTrustindex verifies that the original source of the review is Google. Very prompt and reliable service by Rahul Kolge and his team. Exceptional and happy experience.Posted on Google Supriya ShetyeTrustindex verifies that the original source of the review is Google. Had a really good experience with JParks India. Rahul sir helped me a lot with my import work and were always active and responsive. Whatever documents or guidance was needed, they handled everything smoothly and explained things clearly. Felt stress-free throughout the process. Very helpful team, definitely recommend them if you’re doing import or export.Posted on Google dipali sakpalTrustindex verifies that the original source of the review is Google. Very nice people, get the work done in a very short time.Posted on Google Satish BajajTrustindex verifies that the original source of the review is Google. Excellent & Prompt services in all Import Export matters. Great to work with youPosted on Google Bajaj VCPLTrustindex verifies that the original source of the review is Google. It was a great experience having work with you.Posted on Google Satish BajajTrustindex verifies that the original source of the review is Google. "Outstanding professiona services, efficient, and gets things done incredibly fast. Highly recommended for anyone needing reliable and prompt assistancePosted on Google Nishat fatimaTrustindex verifies that the original source of the review is Google. excellent servicePosted on Google farhan sayedTrustindex verifies that the original source of the review is Google. JParks Team is Super helpful! Thanks to Rahul and team!Posted on Google Sadik InamdarTrustindex verifies that the original source of the review is Google. Good and personal service for import export codePosted on Google MaheshwarTrustindex verifies that the original source of the review is Google. Had a really good experience with JParks India. Rahul sir helped me a lot with my import work and were always active and responsive. Whatever documents or guidance was needed, they handled everything smoothly and explained things clearly. Felt stress-free throughout the process. Very helpful team, definitely recommend them if you’re doing import or export.Verified by TrustindexTrustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more
We use cookies to run this site, measure traffic, and track our ads. Essential cookies are always on. Accept all, reject non-essential, or set your preferences.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
Google reCAPTCHA helps protect websites from spam and abuse by verifying user interactions through challenges.
Google Tag Manager simplifies the management of marketing tags on your website without code changes.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a web analytics service that tracks and reports website traffic. It collects anonymized data on how visitors use the site to help us understand and improve performance.
Service URL: policies.google.com (opens in a new window)
Marketing cookies are used to follow visitors to websites. The intention is to show ads that are relevant and engaging to the individual user.
Google Ads is an advertising service used to deliver and measure ads, including conversion tracking for our campaigns.
Service URL: policies.google.com (opens in a new window)
Google Maps is a web mapping service providing satellite imagery, real-time navigation, and location-based information.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and .
Free consultation
Talk to an EXIM expert
Tell us what you are stuck with. We usually reply the same business day.
Prefer WhatsApp? Chat with us instead
5.0 ★ rating · 126 Google reviews · EXIM specialists since 1990 · Your details stay private