What to do if you see “Error reading certificate, error code 136,009”

Have you encountered an incomprehensible error “Reading certificate, code 136 009” when logging into your online bank or government services website? Don't panic. This problem occurs quite often and indicates that your browser or operating system cannot properly verify the site's digital security certificate.

Noracora WWNoracora WW

Most often, the cause lies not in your actions, but in the device settings or the certificate itself. It could be an outdated date and time on your computer, a conflict with your antivirus software, or simply an outdated list of trusted certification authorities in the system.

In this article, we will look at several simple and effective ways to help you fix this error yourself. We will start with the simplest and quickest solutions that help in most cases, and gradually move on to more complex ones.

Method 1: Checking and restoring the file structure

Noracora WWNoracora WW

One of the main causes of error 136 009 is a violation of the structure of the files required for correct certificate reading. When the structure of directories and files is violated, the system cannot find the necessary components, which leads to an error when reading the certificate. A thorough check of all the necessary folders and files will quickly determine what is missing or damaged.

First, open the folder where the certificate files are stored. This is usually a flash drive or a special section on your computer's hard drive. Carefully examine the contents of this folder, paying particular attention to the presence and integrity of key elements.

Check for the following required folders:

  • cert — this folder contains all the necessary information about the certificate, including data about its issuance, expiration date, and owner.
  • keys — this directory contains the program responsible for activating keys and ensuring proper interaction with the cryptographic provider.

After checking the folders, make sure that all the necessary files are present in the root directory. The absence of even one of them can lead to error 136 009:

  • kek.opq — a file containing the encrypted key encryption key (KEK) required to protect the container.
  • mk.db3 and masks.db3 — database files that store parameters and masks for cryptographic operations.
  • request.pem — a certificate request file in PEM format used when updating or obtaining a new certificate.
  • rand.opg — a file containing data for generating random numbers required for cryptographic operations.

Pay special attention to file extensions. Even minor deviations in the name or extension can cause the system to fail to recognize the file and return a certificate reading error. Make sure that all extensions match the required ones exactly.

If during the verification process you find that any files or folders are missing or show signs of damage, you will need to completely reinstall the banking tool or certificate. To do this, contact the official source from which you originally obtained the certificate and request a new copy of the necessary files.

After restoring the file structure, be sure to restart your computer so that all changes take effect and the system correctly recognizes the updated files. After restarting, try logging into the system again using your certificate.

Method 2: Updating program components

Italojewerly WWItalojewerly WW

Outdated or incorrectly installed program components are often the cause of error 136 009. When the version of CryptoPRO does not meet the current requirements or the necessary additional modules are missing, the system cannot work correctly with certificates. Updating all components will help eliminate incompatibilities and ensure stable operation of cryptographic functions.

  1. Check the version of the installed CryptoPRO CSP. To do this, click the button “Start”, find and select the application “CryptoPRO CSP” to run.
  2. After launching the program, find and open the tab “General”. This tab displays information about the current product version and license expiration date.
  3. Visit the manufacturer's official website at www.cryptopro.ru/downloads. Find the latest version of CryptoPRO CSP in the list of available programs and download the installation file.
  4. Run the downloaded installation file and follow the instructions of the installation wizard. When updating, it is usually not necessary to re-enter the license key, as it is stored in the system.
  5. Additionally, download and install the latest versions of ActiveX and Java components. These components are necessary for the correct operation of certificates in the browser and can be downloaded from the official websites of the developers.
  6. See also:

    Installing ActiveX in Windows

    Updating Java in Windows

After installing all components, be sure to restart your computer. This is necessary to fully apply all changes to the system.

Method 3: Reassigning the cryptographic provider

ChicMe WWChicMe WW

Incorrect cryptographic provider settings are a common cause of error 136 009. A cryptographic provider is a software module that implements cryptographic functions and enables working with certificates. When the system uses an unsuitable or incorrectly configured cryptographic provider, errors occur when reading certificates and performing cryptographic operations.

Reassigning the cryptographic provider allows you to specify to the system which module should be used to work with your certificates, and the correct choice ensures proper interaction between the electronic key (token) and the software, which is critical for successful authorization in secure systems.

  1. If you are using a Rutoken token, run the program “Rutoken Control Panel”. If you are using a different device, open the CryptoPRO CSP settings through the menu “Start”.
  2. After launching the program, find and open the tab “Settings” or “Crypto Providers”. This tab contains the main parameters for working with cryptographic functions. In the tab that opens, find the section “Crypto Provider Settings”. In this section, click on the button “Settings” or “Configure” depending on your software version.
  3. In the list of available cryptographic providers that appears, select the appropriate option. It is recommended to select “CryptoPRO CSP” instead of “Microsoft Base Smart Card Crypto Provider”, which may cause compatibility issues.
  4. After selecting the desired crypto provider, click the button “OK” to save the changes you have made. The system will apply the new crypto provider settings.

Method 4: Reinstalling the certificate

Italojewerly WWItalojewerly WW

If the certificate was installed incorrectly or its files are damaged, reinstalling it can effectively solve the problem with error 136 009. Incorrect installation often occurs due to failures during the initial installation process, conflicts between programs, or access rights issues. As a result, the system cannot read the certificate data correctly, which leads to errors when attempting to use it.

  1. Find the menu on your computer “Start” and open it. Find it in the list of programs “CryptoPRO CSP” and run this program. If CryptoPRO is not displayed in the menu “Start”, you can also find it through “Control Panel”.
  2. After launching the CryptoPRO CSP program, find the tab at the top of the window “Service”. Section, click on this tab to open a list of available features and tools.
  3. In the tab that opens “Service” find and press the button “Install personal certificate”. This feature allows you to reinstall your certificate on the system.
  4. The program will open a new certificate installation wizard window. In this window, click the “Overview” to search for the certificate file on your computer. Certificate files usually have the extension “.cer” or “.p7b”.
  5. After selecting the certificate file, check the box next to the option “Find container automatically”. This option will allow the system to automatically detect and associate the certificate with the corresponding private key. Continue to follow the installation wizard instructions, selecting the default settings at each step. Do not change the suggested settings unless you have specific requirements for installing the certificate.
  6. After the installation is complete, close all CryptoPRO CSP program windows. Now restart the application in which error 136 009 previously occurred and check if the problem has been resolved.

Method 5: Checking and updating drivers for the key media

nubia Many GEOsHomestyler WW

If you are using an external key storage device, such as a token or smart card, error 136 009 is often associated with incorrect device driver operation. Drivers are special programs that enable interaction between the operating system and hardware devices. Outdated or damaged drivers cannot ensure the correct operation of the key storage device, which leads to errors when reading the certificate.

  1. Press the keys simultaneously Win + X on the keyboard. In the menu that appears, find and select the item “Device Manager”.
  2. In the window that opens “Device Manager” find and expand the sections “Smart Cards”, “USB devices” and “Other devices”. Your certificate storage devices may be located in these sections.
  3. Carefully review the list of devices in each section. Pay special attention to devices marked with a yellow exclamation mark — this indicates driver problems.
  4. If you find a device with an error, right-click on it. In the context menu that appears, select “Update Driver”. This will launch the driver update wizard.
  5. In the driver update wizard window, select the option “Find drivers on this computer”. On the next screen, select “Select a driver from the list of already installed drivers”.
  6. If you are using a Rootoken token, select from the list of drivers “Smart Card Filter”. Click the “Next” button to continue installing the driver.
  7. If the automatic driver search did not yield any results, open your web browser and visit the official website of your token or smart card manufacturer. Find the section “Support” or “Drivers”, download the latest version of the drivers for your device model.

Method 6: Checking certificate integrity and exporting/importing

Geekbuying WWGeekbuying WW

Damage to the certificate file can cause error 136 009. Checking the integrity of the certificate and reinstalling it through export and import operations allows you to detect and fix problems with certificate files. Incorrect parameters or damage to the internal structure of the certificate may prevent the system from interpreting it correctly.

  1. Press the key combination Win + R on the keyboard. In the dialog box that opens, “Run” enter the command certmgr.msc and press the Enter. This command opens the Windows Certificate Manager.
  2. In the certificate manager that appears, find and expand the section “Personal” field on the left side of the window. Then go to the “Certificates”. Subsection. The right side of the window will display a list of all your personal certificates.
  3. Find your certificate with which you are having problems in the list. Right-click on it and select “Properties” in the context menu. Alternatively, simply double-click on the certificate.
  4. In the certificate properties window that opens, check the information about its status. Make sure that the certificate is valid (not expired) and has not been revoked. Pay attention to the “Valid from” and “Valid until”.
  5. If the certificate is marked as problematic or invalid, you will need to export it. Close the properties window, right-click on the certificate and select “All tasks”, then ‘Export’.
  6. The certificate export wizard will start. Follow its instructions, selecting the format “DER” for X.509 certificates or “PKCS #7” for certificates with a trust chain, depending on your system requirements.
  7. Specify the file name and location where the exported certificate will be saved. Complete the export process by clicking “Finish”.
  8. After successful export, delete the problematic certificate from the store. To do this, right-click on it and select “Delete” in the context menu. Confirm the deletion.
  9. Now import the previously exported certificate. In the certificate manager, right-click on the section “Personal” and select “All Tasks”, and then “Import”.
  10. Follow the instructions in the import wizard, specifying the path to the exported certificate file. Make sure the certificate is placed in the storage “Personal”.
  11. After completing the operation, close the certificate manager and restart the application in which error 136 009 occurs.

Method 7: Restarting CryptoPRO and Windows cryptography services

ChicMe WWChicMe WW

Temporary failures in cryptography services often cause error 136 009. These services are responsible for performing cryptographic operations and providing access to certificates. When they malfunction, various errors occur when reading certificates and performing secure operations. Restarting the services allows you to restore their normal operation without having to reinstall the software. This is a simple and effective way to fix temporary failures, which often helps to solve the problem with error 136 009.

  1. Press the key combination Win + R on the keyboard. In the window “Run” enter the command services.msc and press the Enter. This command opens the Windows Services management window.
  2. In the window that opens “Services” find the following services in the list that are responsible for working with cryptography and certificates: “Cryptographic Services” (Cryptographic Services), “CryptoPRO CSP Service”, “CryptoPRO Revocation Provider Service” (if installed).
  3. To restart the first service — “Cryptographic Services” — right-click on it. In the context menu that appears, select “Restart”. Wait for the service to restart completely. Similarly, restart “CryptoPRO CSP Service”. If the list contains “CryptoPRO Revocation Provider Service”, also restart it.
  4. If restarting the services did not solve the problem, check the startup type of each service. Right-click on the service, select “Properties” and make sure that in the field “Startup type” value set ‘Automatically’. If another option is selected, change it and click “Apply”.
  5. After changing the startup type of the services, restart your computer to apply all changes.

If you encounter the error “certificate reading, code 136 009” while working with the website or program, the problem is most likely with the secure connection between your device and the server. This may be due to outdated or corrupted security data on your computer, incorrect date and time settings, antivirus malfunctions, or a temporary glitch on the website's end. Most often, the error can be fixed with simple steps — check that the date and time are set correctly, restart your internet connection, clear your browser cache, or try opening the page in a different browser. If that doesn't help, temporarily disable your antivirus or firewall to check if they are blocking the connection. The problem can usually be solved quickly and without any special knowledge.

Method 8: Checking Russian security certificates

Ticombo - Global Event Tickets Many GEOsTicombo - Global Event Tickets Many GEOs

After the sanctions were imposed, many online services switched to using Russian security certificates. The absence of such certificates in the system can cause error 136 009 when attempting to access protected resources. Certificates from certification authorities are necessary to verify the authenticity of websites and establish a secure connection.

Installing and configuring Russian security certificates has become a particularly pressing task for users working with government information systems, banking services, and other secure resources. Without properly installed root certificates, the system will not be able to establish a trusted connection.

  1. Press the key combination Win + R on your keyboard. In “Run” enter the command certmgr.msc and press Enter. You will be taken to the familiar certificate management window.
  2. In the certificate manager that opens, find and expand the section “Trusted root certification authorities” on the left side of the window. Then select the subsection “Certificates”.
  3. Review the list of certificates on the right side of the window and make sure that it contains certificates from the Russian Ministry of Digital Development, Communications and Mass Media or the National Certification Authority (NCA). These certificates are required to work with Russian secure resources.
  4. If the necessary certificates are missing, open your web browser and visit the official website of Gosuslugi in the relevant section at www.gosuslugi.ru/crt.
  5. Download the necessary root certificates to your computer. They are usually provided in .cer or .crt format. You can also obtain certificates from the website of the organization you work with (e.g., a bank or government portal).
  6. After downloading the certificates, double-click on each of them to open the installation window. In the window that opens, click the “Install Certificate”.
  7. The certificate import wizard will start. On the first screen, select “Current user” and click “Next”. On the next screen, select “Place all certificates in the following store”.
  8. Press the button “Overview” and in the window that opens, select “Trusted root certification authorities”. Click “OK”, and then “Next” and “Ready” to complete the certificate installation.
  9. Repeat the procedure for all downloaded certificates. After installing all certificates, restart your computer and browser, then try to log in again to the system where error 136 009 occurred.

Method 9: Update your browser and check your settings

Redmagic WWRedmagic WW

An outdated browser version or incorrect security settings can cause error 136 009 when working with secure sites. Modern browsers are constantly being updated, including new security mechanisms and fixing vulnerabilities. Using an outdated version can lead to compatibility issues with cryptographic functions.

  1. Update your browser to the latest available version. For more details about this process for different web browsers, read another article on our website.
  2. Check your browser's security settings. Open your browser settings and find the section related to security and privacy. In Chrome, this is the section “Privacy and security”, in Firefox — “Privacy and security”.
  3. Make sure that Russian certification authorities' certificates are not blocked in your security settings. In some browsers, you may need to disable the option “Warn about unsafe sites” or add exceptions for specific sites.
  4. Check your TLS/SSL settings. In the advanced security settings, find the section related to TLS and SSL protocols. Make sure that all versions of the protocols are enabled, including TLS 1.2 and TLS 1.3.
  5. More details:

    Configure SSL in Yandex Browser

    Enable TLS protocol in Yandex Browser.

  6. Install the CryptoPRO EDS Browser plug-in extension from the manufacturer's official website. This extension provides support for Russian cryptographic algorithms and works with electronic signatures in the browser.
  7. More details: Enabling the CryptoPro EDS plugin in Yandex Browser

  8. After installing the CryptoPRO EDS Browser plug-in extension, restart your browser and check its performance with secure sites.
  9. If you are still experiencing error 136 009, try using an alternative browser that is specially adapted to work with Russian certificates, such as Yandex Browser or Atom. These browsers have built-in support for Russian cryptography.

Method 10: Configuring Windows security settings.

Italojewerly WWItalojewerly WW

Incorrect Windows security settings can block the use of certificates and cause error 136 009. The Windows operating system contains many security settings that can affect the operation of cryptographic functions. Incorrect configuration of these settings can block access to certificates or limit the functionality of cryptographic providers.

  1. Use the search function to find “Start”, to find the administration tools. Open this window.
  2. Find and open the tool “Local security policy”. This tool allows you to configure various Windows security settings.
  3. In the window that opens “Local Security Policy” select the section “Local Policies” on the left side of the window, and then the subsection “Security settings”),.
  4. Scroll through the list of options on the right side of the window and find the option “System cryptography: use FIPS-compliant algorithms for encryption, hashing, and signing”.
  5. Double-click on this parameter to open its settings window. If the parameter is enabled (set to “Enabled” change it to “Disabled”. Enabling FIPS mode may block the operation of some Russian cryptographic algorithms.

As you can see, error 136 009 related to the certificate is usually not a serious problem. Most often, it occurs due to minor browser glitches or incorrect data that the browser cannot verify.

Start with the simplest steps: refresh the page, clear your browser cache, or try accessing the site from another device. In most cases, this helps to quickly resolve the issue, and you can continue working without any hassle.

If the error reappears, check the date and time on your computer — incorrect settings often cause such failures. It is also worth making sure that the problem is not on the website itself by waiting a while before trying again.

The main thing is not to worry. This error rarely indicates anything dangerous. The simple steps described above will almost certainly help you get back to surfing the Internet as usual.

Homestyler WWSunsky-online WWhidemynameItalojewerly WWItalojewerly WWItalojewerly WW
What function do you consider the most important in a new smartphone?
Share to friends
Elena Sokolova

I have been involved in technology journalism for more than 7 years. My focus is on innovation and the future of technology. I love discussing how gadgets and technology can change our world and sharing news about the most advanced developments.

Rate author
Appliances News
Add a comment