Troubleshooting
"Error connecting to PKI component" or "No PKI Applet Found" are the most common errors ICEGATE users hit when trying to sign Bills of Entry or Shipping Bills. Here's why it happens and how to fix it.
ICEGATE relies on a local PKI component (a small utility running on your computer) to communicate between your browser, your DSC token, and the ICEGATE website. The error appears when that local component isn't installed, isn't running, or your browser is blocking it from communicating on localhost.
Work through these in order, most cases are resolved by the first two or three steps.
Download the correct PKI component (32-bit or 64-bit, matching your system) from the ICEGATE utilities section, right-click the installer and choose Run as Administrator.
Confirm your USB token's drivers (Proxkey, InnaIT, HypSecu, etc.) are installed and up to date, the PKI component depends on the OS detecting your token correctly.
Fully close and reopen your browser after installing the PKI component. If the error persists, restart your computer as well.
ICEGATE's signing tools historically work best in Internet Explorer/Edge in IE mode, though the newer web-based signer utility supports Chrome, Edge and Firefox, use whichever your specific ICEGATE flow recommends.
Right-click your browser shortcut and choose Run as Administrator before logging into ICEGATE and attempting to sign again.
If you have multiple DSC-related utilities installed (from different CAs or portals), they can conflict trying to use the same local port. Try closing other signing utilities before using ICEGATE.
PKI component errors can be fiddly to diagnose remotely without seeing your screen, we're happy to help troubleshoot directly.
ICEGATE requires encrypted submission for customs documents, so you need a Combo (Signing + Encryption) DSC, a Signing-only certificate will not register successfully.
Not usually, the PKI component error is a local software/driver issue, separate from your certificate's validity. Check your certificate expiry separately if signing still fails after fixing this.
Browsers can't directly access your USB token's private key for security reasons, the local PKI component acts as a secure bridge between your browser, the token, and the ICEGATE website.