# Signing error "cryptographic error"

**URL:** https://www.finalbuilder.com/forums/t/signing-error-cryptographic-error/7591
**Category:** Discussions
**Created:** [December 18, 2024, 6:37pm UTC](https://www.finalbuilder.com/forums/t/signing-error-cryptographic-error/7591 "2024-12-18T18:37:31Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![OMonien](https://www.finalbuilder.com/forums/user_avatar/www.finalbuilder.com/omonien/32/2504_2.png) [@OMonien](https://www.finalbuilder.com/forums/u/OMonien)
#### Post date: [December 18, 2024, 6:37pm UTC](https://www.finalbuilder.com/forums/t/signing-error-cryptographic-error/7591/1 "2024-12-18T18:37:31Z")

</div>

I am getting the following error. Any ideas where to start digging?

 ![Bildschirmfoto 2024-12-18 um 19.35.19](https://www.finalbuilder.com/forums/uploads/default/original/2X/7/7e8b0f27abadc3721543c7692a4d67849c8543a4.png)

---

<div class="post-metadata">

### Author: ![OMonien](https://www.finalbuilder.com/forums/user_avatar/www.finalbuilder.com/omonien/32/2504_2.png) [@OMonien](https://www.finalbuilder.com/forums/u/OMonien)
#### Post date: [December 18, 2024, 6:40pm UTC](https://www.finalbuilder.com/forums/t/signing-error-cryptographic-error/7591/2 "2024-12-18T18:40:18Z")

</div>

The mentioned certificate was imported from Windows Cert Store, has a private key and the signing algorithm of the cert is “sha256RSA”

---

<div class="post-metadata">

### Author: ![Sparky](https://www.finalbuilder.com/forums/user_avatar/www.finalbuilder.com/sparky/32/10_2.png) [@Sparky](https://www.finalbuilder.com/forums/u/Sparky)
#### Post date: [December 18, 2024, 11:53pm UTC](https://www.finalbuilder.com/forums/t/signing-error-cryptographic-error/7591/3 "2024-12-18T23:53:14Z")

</div>

Hi Olaf,

Could you confirm which certificate store the certificate is located in? Is it located in a user store or system store?

Our initial thought was that this may be a permissions issue but, from the error message, we can see that Signotaur already has the private key. The error occurs while signing the digest.

One possibility is that your certificate provider requires a different signature padding scheme than the one currently being used. To help us investigate further, could you run the following command to retrieve detailed information about your certificate?

```auto
certutil -v -store storename

```

Please send the output to us, either via a direct message here, or by email to support at [finalbuilder.com](http://finalbuilder.com).

---

<div class="post-metadata">

### Author: ![OMonien](https://www.finalbuilder.com/forums/user_avatar/www.finalbuilder.com/omonien/32/2504_2.png) [@OMonien](https://www.finalbuilder.com/forums/u/OMonien)
#### Post date: [December 19, 2024, 11:52am UTC](https://www.finalbuilder.com/forums/t/signing-error-cryptographic-error/7591/4 "2024-12-19T11:52:42Z")

</div>

Thanks for your help, as already communicated via email, I found the error.

The certificate originates from a SafeNet token, which was then imported to the Windows store.

Signotaur detected and selected that certificate in the store, but cannot access the private key, which remains on the token.

As stated in the docs, you have to access the certificate via „Library“ - which I missed. It now works and signs perfectly.

> **[Signotaur - Add Certificate from Library (PKCS#11)](https://docs.finalbuilder.com/sn/1.0/server/admin/certificates/library.html)**
>
> Add Certificate from Library (PKCS#11)
