NICDSign Client Inspector / Enterprise Edition / read-only

Certificate Reader & System Diagnostics

A complete, read-only snapshot of your machine, browser, network, and NICDSign signer service — everything you or your IT desk need to confirm a DSC token is ready to sign, without ever touching a document or a private key.

IDLE
0.0s elapsed 0/10 checks
[ awaiting first run ]
0%
Readiness
0/10
Checks Passed
0.0s
Total Duration
Completed At
Everything here is read-only, by design
This inspector never uploads a document and never triggers a signature. It only calls the diagnostic and listing endpoints your local NICDSign client already exposes — isInitialized, initialize (PIN prompt only if the token store needs unlocking), and listCertificates. All hardware, storage, battery, and permission checks below use standard read-only browser APIs — nothing is installed, and nothing is sent anywhere except localhost and, if you choose to run them, the optional public-IP lookup and internet speed test.
SYSTEM
OS & hardware
BROWSER
Client environment
NETWORK
Connection state
SIGNER :8020
HTTPS endpoint
SIGNER :8019
HTTP endpoint
CERTIFICATE
Token contents

Digital Signature Readiness

Plain-Language Signing Diagnosis

The four things that actually block a DSC signature, stated accurately from the live checks above — not guessed. This updates automatically after every diagnostic run and after each certificate read.

NICDSign Service
Waiting for the connectivity probe to run…
DSC Token / Store Status
Waiting for the connectivity probe to run…
Java / Browser Plugin Relevance
Waiting for diagnostic run…
Browser & Network Configuration
Waiting for the connectivity probe to run…

Problem Detection

All Errors Found

Every failure, warning, and unreachable check collected from the checks above, in one place — this list also feeds the voice assistant (Malayalam, English, or Hindi).

! Errors & Warnings
Run the diagnostic to collect errors.

Environment

System, Browser & Platform

Everything the browser can tell you about the machine NICDSign is running on, including deep Windows build details where your browser supports it.

01 System

Exact OS name and version (using Client Hints on Chromium browsers to correctly tell Windows 10 apart from 11), true CPU architecture, cores, and memory — helps rule out platform-specific signer issues.

02 Browser

Correctly identified browser name, version, and rendering engine (Edge/Opera/Brave/Samsung Internet are told apart from Chrome), plus language and security flags — useful when a signer call behaves differently across browsers.

03 Windows / Platform Details

High-entropy Client Hints (Chromium browsers only) — exact Windows release, CPU architecture, and bitness, useful for matching 32-bit vs 64-bit NICDSign installers.

04 Display & Locale

Screen, timezone, and locale details — included in the exported report for support and audit purposes.

Hardware & Capabilities

Graphics, Storage, Power & Permissions

Deeper machine capability checks that occasionally explain why a signer applet, PDF preview, or token driver misbehaves on a specific device.

05 Graphics / GPU
06 Storage
07 Power / Battery
08 Permissions Snapshot

Current permission state only — this does not trigger any browser prompt. "prompt" means the browser hasn't been asked yet.

Network

Connectivity & Internet Speed

Connection quality estimates plus an on-demand download speed and latency test, useful when a signing session is timing out over a slow link.

09 Network
Speed test downloads a temporary file from Cloudflare's public test endpoint to estimate throughput and latency. It's a client-side estimate, not a certified measurement — for precise figures, use your ISP's tool or speedtest.net.

Signer & Certificates

NICDSign Service & Token Contents

Live connectivity to the local NICDSign signer, the raw service response on each port, and everything readable from the connected DSC token.

10 Certificate Reader (NICDSign)
Uses only the read-only calls from the official client: isInitializedinitialize (only if the store needs it — this may prompt for the token PIN once) → listCertificates. Nothing here signs, stamps, or sends any document to the token. Base URL matches the official client exactly: http://localhost:8019/signer (HTTP) or https://localhost:8020/signer (HTTPS).
Use the trust-page button once if HTTPS reads fail with a certificate error.
Port connectivity probe (no certificate read) — hits isInitialized only, to confirm the signer service is reachable on each port.
Manual Request Tester (read-only endpoints)
All requests are POST with Content-Type: application/json, sent to http(s)://localhost:<port>/signer<path> — matching the official client. Response will appear here.
11 NICDSign Service Detail (raw)

The exact JSON fields returned by isInitialized on each port during the last diagnostic run — useful for spotting a signer version mismatch or an unexpected field your IT team asked about.

Why this tool exists

Verify before you sign

Confirm the NICDSign service, token driver, and browser are all correctly wired up before starting a real signing session on a government or enterprise e-filing portal — no more discovering a broken setup mid-transaction.

Nothing leaves your machine

Every call in this tool talks to localhost only, except the IP lookup and speed test you trigger manually. No document, PIN, or private key material is ever transmitted anywhere.

Bring your own evidence

Export a timestamped, shareable PDF diagnostic report to attach to a support ticket or IT helpdesk request — no screenshots or manual transcription needed.

  • Included: system, browser, platform, display, GPU, storage, power, network, signer, certificates
  • Excluded: private keys, PINs, signed documents

Help

Troubleshooting & FAQ

Both signer ports show fail — what do I check first?
Confirm the NICDSign desktop client or service is actually running on your machine — it must be started separately from this browser tab. If it's running and :8020 still fails, your browser may not yet trust its self-signed certificate; click Open /check trust page once and accept the warning, then re-run the diagnostic.
Why does reading certificates sometimes ask for my token PIN?
If the token store isn't already unlocked, the client calls initialize once, which the NICDSign service itself may use to prompt for your PIN. This tool never sees, stores, or transmits that PIN — the prompt comes from the signer client, not from this page.
What does the Windows / Platform card actually detect?
It uses the browser's Client Hints API to report your real Windows release, CPU architecture (x86/ARM), and bitness (32/64-bit) — far more reliable than parsing the User-Agent string. It only works in Chromium-based browsers (Chrome, Edge, Brave); Firefox and Safari will show a fallback message.
Is the public IP lookup or speed test required?
No. Both are entirely optional and only run when you click their buttons. IP lookup calls ipify; the speed test calls Cloudflare's public test endpoint. Neither is required for reading certificates.
A certificate shows "EXPIRING" or "EXPIRED" — what now?
Renew or re-issue the certificate with your Certifying Authority before relying on it for signing — most portals will reject an expired DSC outright, and many flag certificates expiring within 30 days for early renewal.

Knowledge base

SPARK, BIMS & NICDSign Troubleshooting (searchable)

ശബ്ദ സഹായി
Checking for a local voice on this device…
🛡️

Category

WHAT TO DO
    Sound & Language Settings
    One language speaks at a time — no mixing between languages.
    Language
    മലയാളം
    English
    हिन्दी
    Voice
    ♀ Female
    ♂ Male
    Sound
    Auto-announce results after scan
    On
    Off
    Keep listening after each answer
    On
    Off
    Live AI answers (Sarvam AI + web search)
    On
    Off