Which token, which certificate, which portal.
Five DSC token families are recognised and driven directly, and a software certificate (PFX/P12) can be used where the law and the destination allow it. This page states the difference — including the cases where no software certificate will do.
The five families, and the driver each one uses.
There is no separate driver to install for Flash Turbo Signer. The application loads the PKCS#11 library your token vendor already installed when the DSC was issued — the same library your browser and Adobe use.
-
Watchdata ProxKey
SignatureP11.dll· slot 16385 -
Feitian ePass & Hypersecu
eps2003csp11v2.dll· slot 1 -
M-Token CryptoID
CryptoIDA_pkcs11.dll· slot 0 -
SafeNet eToken
eTPKCS11.dll -
InnaIT Key DSC
Precision InnaIT ·
InnaITPKCS11Driver.dll - Adobe Acrobat Reader Opens, displays and verifies the signed PDF
Brand names and logos belong to their owners and are used here only to state which drivers and readers this application works with. Flash Turbo Signer is an independent product — not affiliated with, endorsed by or sponsored by any token vendor or by Adobe.
How detection resolves a token.
Auto-detection is the default, but every brand can also be named explicitly — useful in a script where you want the run to fail loudly rather than guess. These are the aliases the CLI accepts and the library each one maps to.
| Alias | Resolves to | PKCS#11 library |
|---|---|---|
watchdata, proxkey |
Watchdata ProxKey | SignatureP11.dll |
feitian, epass |
Feitian ePass (also EnterSafe and Hypersecu) | eps2003csp11v2.dll |
mtoken, cryptoid, cryptoida |
M-Token CryptoID | CryptoIDA_pkcs11.dll |
safenet, gemalto |
SafeNet eToken | eTPKCS11.dll |
| (auto-detect) | InnaIT Key DSC (Precision InnaIT) | InnaITPKCS11Driver.dll |
Auto-detection scans the known installation folders and these library names:
WDPKCS.dll, SignatureP11.dll,
eps2003csp11v2.dll, CryptoIDA_pkcs11.dll,
eTPKCS11.dll, eToken.dll and
InnaITPKCS11Driver.dll. If a token presents a PKCS#11 interface under a
name that is not on the list, unplug and re-plug the token and use
flash-signer tokens to see what was found.
Token or PFX/P12? The destination decides.
Flash Turbo Signer can sign with either. Which one you must use is not a product question — it is set by the portal or the counterparty that has to accept the signed document.
Where a USB token is required — and where it isn't
- Signing a PDF yourself — an invoice, agreement, letter, report or drawing: Flash Turbo Signer signs it on this machine, either with your DSC USB token or with a PFX/P12 software certificate if that is what you hold.
- Filing on a government or enterprise portal — Income Tax e-filing, MCA21, the GST portal, EPFO, GeM, and state RERA and tender portals — those portals sign through the USB token plugged into your computer. The majority of them do not accept a PFX/P12 file, and the Aadhaar-OTP based eSign route is not accepted for DSC filing either, so a hardware token is mandatory there.
- Portal signing stays on the portal. Flash Turbo Signer produces the signed PDF before you upload it; it does not log in to a portal or replace the portal's own signing step. If you already sign in Acrobat with the token plugged in, the driver is installed — there is nothing extra to set up here.
Rule of thumb: keep the USB token for anything that has to be signed on a portal, and use Flash Turbo Signer for the documents you sign and send.
Using a PFX/P12 file
- Choose “Sign with PFX/P12” instead of a token
- Point at the
.pfx/.p12file and enter its password - Expired certificates are refused with a clear message, not a silent failure
- The resulting signature is the same PAdES signature a token would produce
Using a DSC USB token
- Insert the token; brand and library are detected automatically
- Pick the signing certificate if the token carries more than one
- The private key never leaves the token — the PIN authorises it in place
- Required for portal filing and for tender submissions
Verification that works with the network unplugged.
A signature is only useful if the person receiving it can check it. Nothing here requires an upload, an account or a connection to a vendor service.
In the application
The Verify and Integrity tabs report whether the signature covers the whole document, whether the file changed after signing, the signer's certificate, its issuer and its expiry — and the timestamp, when one was embedded.
In Adobe Acrobat Reader
Acrobat displays the signature panel for a PAdES signature and validates it when it trusts the signer's chain. Indian chains — CCA India into Capricorn, eMudhra, SafeScrypt, (n)Code and others — are normally trusted already.
Offline trust store
Thirty certificates ship in the trust store: 28 Indian roots and sub-CAs, plus the GlobalSign and FreeTSA roots used for trusted timestamps.
If Acrobat reports “Signature Not Verified”, treat it as a trust question before a signature question. Install your DSC provider's root certificate into the Windows Certificate Store, and read the signature panel rather than the banner — some older readers do not support PAdES at all and will never show it as valid. The full explanation is in the FAQ.
Built on a mature signing core, shipped as one file.
No bespoke cryptography. Flash Turbo Signer assembles well-audited libraries under a desktop shell, pins every version, and gates each change behind the same test suite — so behaviour is reproducible across machines.
| Layer | Technology (pinned in 4.2) | What it does here |
|---|---|---|
| Desktop UI | PySide6 6.11.1 (Qt 6) | Native Windows application shell and the drag-to-place signature canvas. |
| PDF signing | pyHanko 0.35.1 | Builds the CMS signature and writes it with an incremental save, so the original bytes are preserved. |
| Chain validation | pyhanko-certvalidator 0.31.1 | Validates the signer's chain against the bundled Indian CA trust store while offline. |
| Token interface | python-pkcs11 0.9.4 | Loads the vendor PKCS#11 library for each token brand and drives the on-token private key. |
| Cryptography | cryptography 49.0.0, asn1crypto, oscrypto | SHA-256 digests, certificate parsing and RFC 3161 timestamp requests. |
| PDF engine | PyMuPDF 1.28.0 | Renders page previews and locates the text anchors used for automatic placement. |
| Stamp rendering | ReportLab 5.0.0, Pillow 12.3.0 | Draws crisp vector stamps with the per-style fonts, border and accent colours. |
| Configuration | PyYAML 6.0.3 | Reads and writes signing profiles, presets and appearance settings — never the PIN. |
| Runtime health | psutil 7.2.2 | Checks driver and process state so token errors surface as clear messages. |
| Packaging | PyInstaller 6.21.0, Inno Setup 6 | Produces the one-file FlashTurboSigner.exe and the standard Windows installer. |
| Quality gate | pytest 9.1.1, Ruff 0.15.20 | 1,892 automated tests collected, plus lint and format checks run on every change. |
Layered, engine-based architecture
Security, signing, appearance, placement, workflow, batch, classification, configuration and logging are separate engines behind facades. Qt code stays in the UI layer, so the signing core is exercised headlessly by the test suite.
Offline trust store, by design
Thirty certificates ship in the trust store: 28 Indian roots and sub-CAs — CCA India, eMudhra, Capricorn, SafeScrypt, (n)Code, IDRBT, PantaSign, Verasys and emSign — plus the GlobalSign and FreeTSA roots used for trusted timestamps, so a document can be validated with the network cable unplugged.
No telemetry, no phone-home
The application does not report usage, does not upload documents and does not need an account. The only optional outbound request in the whole product is the RFC 3161 timestamp you explicitly enable.
Bring your token. That is the whole setup.
If the token already signs anything on this machine — a portal, a browser or Adobe — Flash Turbo Signer will use the same driver without further work.
- Five DSC token families detected automatically
- PFX/P12 supported where the destination allows it
- Windows 10 and 11