Installing AppStra Setu

AppStra Setu is a small application that runs on your own computer. It is what lets AppStra use the Digital Signature Certificate (DSC) on your USB token.

Your private key never leaves the token, and your PIN is never sent to AppStra. Setu asks for your PIN in its own window, on your machine, and the signature is produced inside the token itself.

What you need

  • Your Class-3 DSC USB token
  • The computer you will be signing from
  • The token software from the Certifying Authority that issued your DSC — some brands need it, some do not. See Token software below.
  • About ten minutes, once

Step 1 — Install AppStra Setu

Download the version for your computer using the buttons above, then:

On a Mac

  1. Open the downloaded .dmg file.

  2. Drag AppStra Setu onto the Applications folder.

  3. Open your Applications folder, right-click AppStra Setu and choose Open. Then click Open again in the box that appears.

    Use right-click → Open the first time. Double-clicking will show "AppStra Setu cannot be opened because the developer cannot be verified". That message appears because the app is not yet registered with Apple. Right-click → Open tells macOS you trust it, and you will not be asked again.

  4. A small icon appears in your menu bar, at the top-right of the screen. That is AppStra Setu. It has no window and no Dock icon by design.

On Windows

  1. Run the downloaded .exe installer.
  2. Windows may show "Windows protected your PC". Click More info, then Run anyway. This appears because the installer is not yet registered with Microsoft.
  3. Follow the installer. Leave "Start automatically when I sign in" ticked.
  4. An icon appears in your system tray, next to the clock.

On Linux

  1. Extract the downloaded .tar.gz.
  2. Run ./install.sh from the extracted folder.
  3. AppStra Setu then appears in your application menu.

Step 2 — Add the browser extension

Chrome does not allow a website to talk to an application on your computer directly. The AppStra Setu Connector extension is the permitted bridge, and AppStra will not be able to reach your token without it.

Install it from the Chrome Web Store, then reload AppStra.

Step 3 — Plug in your token

Plug the USB token in. Click the AppStra Setu icon and choose Open Status Window.

  • Ready to sign, with the name on your certificate — you are done. Skip to Signing a trade call.
  • Your token is plugged in, but this computer cannot read it — your brand needs its own software. Read the next section.

Token software

AppStra Setu includes software that can read many tokens on its own. It cannot read every brand, because some manufacturers use their own format and only their own software can open it. That software is theirs to give out, not ours, so we cannot include it — but the Certifying Authority that issued your DSC publishes it, free, for exactly this reason.

This is a one-time install. Once done, you never think about it again.

Your tokenExtra software
Watchdata ProxKeyRequired. Tested on real hardware — AppStra Setu cannot read this token without the ProxKey software. Install it before you try to sign.
eMudhra / ePass2003Probably not needed, but we have not tested this brand yet. Try Step 3 first; install the software only if the status window asks for it.
TrustKeyNot tested yet. Try Step 3 first; install the software only if the status window asks for it.
SafeNet eTokenNot tested yet. Try Step 3 first; install the software only if the status window asks for it.
Any other brandTry Step 3 first. The status window will tell you, by name, if it needs something.

Not sure which brand you have? The AppStra Setu status window names it for you, and so does the token's own packaging.

Getting the software

Ask the Certifying Authority that issued your DSC — eMudhra, PantaSign, Capricorn, VSign, IDSign and the others all publish their token drivers as a free download, usually under a "Downloads", "Drivers" or "Support" heading. Pick the one for your token brand and your operating system.

The AppStra Setu status window also offers a Search the web button that fills in your brand and operating system for you.

Download it only from your Certifying Authority or the token manufacturer. Token drivers from anywhere else are not worth the risk — this software talks directly to the device holding your signing key.

After installing, unplug the token, plug it back in, and choose Re-check in the status window.

Signing a trade call

  1. Write the call in AppStra as usual.
  2. Choose Sign on DSC token.
  3. AppStra checks that Setu is running and your token is plugged in.
  4. AppStra Setu asks for your token PIN in its own window. Type it there.
  5. The call is signed and published. Your signature is embedded in the rationale PDF, so the file opens as signed in any PDF reader.

Your PIN is remembered for a few minutes so signing several documents does not ask repeatedly, then it is forgotten automatically. You can forget it immediately with Lock Token in the menu.

If something does not work

What you seeWhat to do
AppStra cannot find SetuCheck the icon is in your menu bar or system tray. Start AppStra Setu if it is not.
"No token plugged in"Unplug the token and plug it in again, then choose Re-check.
"Your token is plugged in, but this computer cannot read it"Your brand needs its own software. See Token software above. The message names your brand.
Installed the software and it still cannot be readChoose Reload token software in the status window — Setu only looks for token software when it starts, so it will not notice a fresh install on its own.
PIN not acceptedCheck the PIN. Tokens lock after a few wrong attempts — contact your CA if that happens.

Still stuck? Write to support@zerostic.com with a screenshot of the AppStra Setu status window. It lists every place Setu looked for token software, which is usually enough to answer the question straight away.