Help center support eXpress
We've collected answers to popular questions to make eXpress easy and convenient to use. Didn't find the answer to your question? Contact our support team.
- Welcome to eXpress
- eXpress Support
- Introducing eXpress & Glossary
- Installation & Updates & Requirements
- eXpress & ETS Apps
- Updates & Release Notes
- Network & Time Sync & Environment & Certificates
- Language & Spell Checking
- Android App
- iOS/iPadOS App
- Aurora App
- Windows Desktop App
- macOS Desktop App
- Linux Desktop App
- Web App
- Outlook Add-In for Conferences
- Server-Side Software
- Troubleshooting App Installation, Updates, and Operation
- Registering & Logging In
- User Profile
- Chats, Channels & Threads
- Contacts
- Tags & Tabs
- Files
- Calls & Conferences
- Push Notifications & Counters
- Fixing Background Work on Mobile
- Bots & SmartApps
- Diagnostics & Logs & Cache
- Admin Panel
- Jira Support Portal
- Technical Support for Admins
- Database Modifications Policy
- eXpress Documentation
- Privacy Policy
Network & Time Sync & Environment & Certificates
- Network Configuration
- Where App Traffic Goes
- Proxy Server
- VPN
- Browser Restrictions in the Web App
- Time Synchronization Setup
- Remote Desktop & Virtual Desktop
- Calls and Conferences via VDI/RDP
- Certificate Management
Network Configuration 
For the app to work on client devices, access to network resources must be provided (e.g., If your devices or network are managed by an organization, contact your organization’s support or system administrator for assistance with access permissions.
For Administrators: About Network Accesses for Clients & Servers, Traffic Inspection 
- If traffic inspection or filtering systems (NGFW, DPI, proxy) are used in the infrastructure, WebSocket connections must be allowed.
- Additionally, VPN tunnel configuration, WAF rules, or proxy server settings may be required.
- Depending on the application's architecture and the specifics of the organization's network infrastructure, the list of necessary access permissions may expand—it is recommended to consult the project documentation and test the connection in an isolated environment before deployment.
Common Issues with Traffic Inspection
| What is configured | How it manifests | What to do |
|---|---|---|
| NGFW or DPI drops long-lived connections | The app periodically shows Connecting, messages arrive with delay, the session drops | Allow WebSocket, increase the idle TCP session timeout for eXpress traffic |
| TLS inspection with certificate substitution (MITM), including on DLP systems | Connection errors and certificate errors, on Android — SSL error | Add eXpress addresses to inspection exclusions or install the corporate root certificate on devices — learn more. The Android app uses only built-in and system certificates |
| WAF in front of the corporate server | Some app requests are rejected with server errors | Configure WAF rules for the app API, allow WebSocket upgrade |
| Proxy server with authentication | The app doesn't connect | The app does not support proxies with username and password — learn more |
| Media traffic is routed through inspection | Calls fail to establish or drop | Media traffic cannot be inspected — it is end-to-end encrypted. Exclude connections to the Media server from inspection |
For Administrators: Network Requirements 
Client-Server Channel Requirements
| Activity | Consumed Traffic |
|---|---|
| Messages | 2 kbit/s per user |
| Files | 100 kbit/s per user |
Call and Conference Requirements
Bandwidth calculation for calls and conferences:
| Traffic | Formula |
|---|---|
| Incoming traffic | 1.5 Mbps × number of participants |
| Outgoing traffic | Depends on the call type:
|
Minimum Requirements for SIP Voice Calls: 16 kbps per participant.
Recommended Network Ping
| Activity | Recommended Ping |
|---|---|
| Calls and conferences | No more than 100 ms |
| Messages and files | No more than 150 ms |
When these values are significantly exceeded, the app may be unable to connect to the server — for example, when using satellite internet.
Client Device Bandwidth Requirements
| Platform | Average Traffic |
|---|---|
| PC | Outgoing: 1.5 mbit/s Incoming: 2 mbit/s |
| Mobile Devices | Outgoing: 1.5 mbit/s Incoming: 1.6 mbit/s |
Does the App Work When the Mobile Network in Russia Is in Whitelist Mode?
- For RTSandLite— yes, as these servers are included in the whitelists.
- For CTS,ETS/eCTS— check with your organization's support.
Where App Traffic Goes 
The app uses not one connection but several independent ones. Based on what exactly stopped working, you can immediately determine which access is blocked.
| What doesn't work | Which connection is responsible | What to check |
|---|---|---|
| The app doesn't connect, endless Connecting, chats and contacts don't update | Client → corporate server CTS /eCTS via HTTPS and WebSocket |
Whether the traffic inspection system blocks WebSocket; in the browser — access to the local network |
| Chats and files work, but calls and conferences don't: the call doesn't connect, there is no audio or video, participants get dropped | Client → Media server, separate ports, primarily via UDP | Whether the media server ports are open including UDP; whether UDP passes through the VPN tunnel — see VPN |
| The web app doesn't open | Client → web client server via HTTPS | Availability of the web app address (https://corp.express/ or your organization's address) |
| Files from external users don't arrive | Client → cloud file storage for public users | Access to the cloud — learn more |
| Captcha verification fails when requesting an SMS code | Client → Captcha services | Access to verification services, see the access list |
| Links to chats and calls don't open | Client → short link service | Access to the link service (or to your own link server) |
| The desktop app can't find updates | Client → update server | Access to the update server (for the ETS app — to your own) |
For Administrators: Web App and Front CTS / Back CTS Topology
CTS
ETS
eCTS
Messaging and media data from the web app go directly to the corporate server and the Media server, so the web app requires exactly the same network accesses as the desktop app, plus access to the web client address.
In a split deployment, the corporate server is published externally through Front CTS, and the media service is located next to it, so the client always retrieves media data from the Front, not from the closed network segment. Network connectivity matrices by deployment topology:
Proxy Server 
The app supports operation through an open proxy server configured in the network properties on a mobile device and a PC. The desktop app uses the system proxy settings of the operating system. Settings specified inside the browser and group proxy policies for browsers do not apply to the desktop app.
Can I Use Proxies That Require Login?
Proxy servers with authentication are not supported by the app itself. If such a proxy is used on your network, contact your network administrator — it may be necessary to use it as a system proxy, or configure an exception for eXpress traffic, or use an open proxy.
Open Proxy Server Configuration for Desktop App
- Close the desktop app.
- Launch the app via terminal or command line:
"app_path" "--proxy-server=IP:port" - It is recommended to create a shortcut to launch the desktop app with a proxy.
For example, on Windows:"C:\Program Files\eXpress\eXpress.exe" "--proxy-server=192.168.1.1:8080"
How to Launch the Desktop App Bypassing the Proxy?
If the eXpress servers are on an internal network and no proxy is needed to access them, the app can be launched with the parameter --no-proxy-server. With it, the app does not use system proxy settings and connects to servers directly.
"C:\Program Files\eXpress\eXpress.exe" --no-proxy-server
This same method is a convenient way to check whether the proxy is to blame. If with this parameter the app connects immediately, but without it remains in the Connecting... state, the cause is proxying — check the exception list.
To the Administrator: What Proxy Settings the Desktop App Uses and How to Set Exceptions on Windows 
The desktop application takes proxy settings from Windows system parameters, not from the browser. If exceptions for eXpress servers are specified only in the browser proxy group policy, the app will not see them and will continue to access the servers through the proxy. Set these exceptions in Windows system proxy settings: Internet Options > the Connections tab > LAN settings > Advanced, in the field Do not use proxy server for addresses beginning with.
What Windows Parameters Does the App Read?
The parameters are taken from the registry branch HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings.
Value ProxyEnable |
What the app uses |
|---|---|
| 1 — proxy is set manually | Proxy address from ProxyServer and exception list from ProxyOverride. The automatic configuration script AutoConfigURL is not applied in this case. |
| 0 — proxy is not set manually | Automatic configuration script (PAC file) from AutoConfigURL if it is specified. |
ProxyEnable.How to Write an Exception so That It Works.
The exception is compared with the host name that the app is accessing. It must either match this name exactly, or be a subdomain mask with an asterisk.
| Record in the exceptions list | What does it cover? | Will work for the node cts.example.ru |
|---|---|---|
cts.example.ru |
Only the node with this name | Yes |
*.example.ru |
All nodes in the domain example.ru |
Yes |
example.ru |
Only the node named example.ru is covered; subdomains are not. |
Not available |
cts |
Only the node named cts |
Not available |
cts does not cover the node cts.example.ru, and the record example.ru does not cover its subdomains. Specify full names of eXpress servers or a mask of the form *.example.ru.If the Exceptions Are Set Correctly, but the App Still Does Not Connect.
Check the following.
- Does the list of exceptions at the time of the failure match the one you see after the connection is restored? If multiple policies with proxy settings are applied to a computer, immediately after startup the policy that doesn't have the required exceptions may take effect, and later the correct one will override it. Capture the proxy settings at the exact moment when the app cannot connect.
- Is the certificate being replaced by an antivirus or traffic inspection tool? When substitution occurs, the app does not trust the connection, even if the proxy exceptions are set correctly. See. “Manage certificates”.
- Isn't the list of addresses allowed on the proxy too narrow? If only CTS server addresses are open, the app will connect, but some features will not work — for example, link preview. The list of required accesses is in the network access list.
- Does the proxy require authentication? The app does not support a proxy with a login and password prompt: you cannot connect through such a proxy, see the question above.
You can verify that the issue is indeed the proxy by launching the application with the parameter --no-proxy-server.
VPN 
When connecting to the network through VPN services, message delivery delays, call drops, and server connection errors may occur. It is recommended not to use a VPN with the app, or to add eXpress to the exception list (split tunneling) of your VPN client, or to contact your organization's support for a correct corporate VPN client configuration.
For Administrators: What Are the Limitations When Routing All eXpress Traffic Through a VPN Tunnel? 
eXpress has no technical restrictions on using VPN. However, in practice, performance depends heavily on the VPN channel's bandwidth and the specifics of network protocols. Experience shows that routing all traffic, including media data, through VPN can lead to call quality issues. It is recommended to avoid routing traffic through VPN to ensure stable operation.
What Must Reach the Servers Through the Tunnel
If traffic is still routed through VPN, it is not enough to allow only HTTPS to the corporate server — otherwise messaging will work, but calls will not. Connections to the Media server, including UDP, must also pass through the tunnel. For the list of ports, see the list of network accesses and the .
Common Reasons Why Media Traffic Does Not Pass Through VPN
| Reason | What to do |
|---|---|
| The tunnel works only over TCP (for example, a TLS tunnel on port 443), UDP is not transmitted | Either route media traffic outside the tunnel, or enable the Allow TCP ICE setting in the VoEx section of the admin panel — learn more. Note that TCP for media provides worse quality than UDP |
| The UDP port range of the media server is not fully open | Open the entire range — it is used for SRTP streams |
| Direct peer-to-peer (p2p) connection between clients is blocked, and TURN is not used | Enable the Use relay ICE candidates only setting in the VoEx section — all media traffic will go through the TURN server |
| Reduced MTU in the tunnel, UDP packet fragmentation | Check MTU and MSS clamping settings on the VPN gateway. Symptom: the call connects, but audio and video break up or work only in one direction |
| Double NAT (corporate NAT over provider NAT, CGNAT) | Verify correct NAT IP-to-IP mapping for the Media server and external addresses in TURN/STUN settings |
Browser Restrictions in the Web App 
The web app operates according to browser rules, not operating system rules. Even if all network accesses are open, the browser may block some connections. The most common restriction is local network access.
What Is Local Network Access and Why Does It Interfere?
Modern browsers consider it dangerous when a website from the internet accesses devices inside your network and require separate permission for this. The rule is triggered by the destination address: if the site is opened via a public address but accesses a private address (10.x.x.x, 172.16–31.x.x, 192.168.x.x), localhost, or a domain in the .local zone — the browser shows a permission prompt, and if denied, drops the connection.
For eXpress, this looks like this: the web app is opened via a public address (for example, https://corp.express/), while the corporate server and Media server are located in your organization's network. This leads to the following typical symptoms:
- everything works in the office or from home, but not when the corporate VPN is enabled (over VPN, server addresses become private);
- chats work, but calls and conferences don't connect or have no audio or video;
- the web app doesn't connect at all and endlessly shows “Connecting”;
- the desktop app on the same computer and in the same network works fine.
How to Grant Local Network Access Permission
You can wait for the browser prompt when opening the web app and click Allow. If the prompt was already denied, grant the permission manually and reload the page:
| Browser | How to grant permission |
|---|---|
| Google Chrome, Chromium, Microsoft Edge, Yandex Browser, Vivaldi, Opera | Click the site settings icon to the left of the address bar > Site settings (in Microsoft Edge — Permissions for this site) > allow Local network (in Yandex Browser — Access to local network) > reload the page |
| Mozilla Firefox | Click the padlock icon to the left of the address bar > Permissions > allow Local network devices. All granted permissions are listed under Settings > Privacy & Security > Permissions |
| Apple Safari | There is no separate site prompt. On macOS, check the system permission: System Settings > Privacy & Security > Local Network |
Other Browser Settings That Affect Operation
- Check other browser permissions — microphone, camera, notifications, clipboard, autoplay in Safari — and ad-blocking extensions: they are listed in the system requirements for the web app.
- Do not use incognito mode or private windows for regular work: some permissions and session data are not preserved in them.
For Administrators: Centralized Local Network Access Deployment (Policies) 
Relying on each user to respond correctly to the browser prompt is not advisable: the denial is remembered, and no error message is shown. The permission can be distributed via group policies.
Chromium-Based Browsers
The policy is called LocalNetworkAccessAllowedForUrls, type — list of strings. It contains the source addresses, that is, the eXpress web app address, not the server addresses.
| Browser | Windows: registry key | Linux: policies directory |
|---|---|---|
| Google Chrome | HKLM\SOFTWARE\Policies\Google\Chrome\LocalNetworkAccessAllowedForUrls |
/etc/opt/chrome/policies/managed/ |
| Chromium | HKLM\SOFTWARE\Policies\Chromium\LocalNetworkAccessAllowedForUrls |
DEB or RPM package (Astra Linux, RED OS, and others): /etc/chromium/policies/managed/⚠️ Snap package (how Chromium is installed by default in Ubuntu): /var/snap/chromium/current/policies/managed/. Files in /etc are ignored in this case |
| Microsoft Edge | HKLM\SOFTWARE\Policies\Microsoft\Edge\LocalNetworkAccessAllowedForUrls |
/etc/opt/edge/policies/managed/ |
| Yandex Browser | HKLM\SOFTWARE\Policies\YandexBrowser\LocalNetworkAccessAllowedForUrls |
/etc/opt/yandex/browser/policies/managed/ |
| Vivaldi | HKLM\SOFTWARE\Policies\Vivaldi\LocalNetworkAccessAllowedForUrls |
/etc/vivaldi/policies/managed/ |
| Opera | Not supported: policies are not applied on Windows. The permission is granted manually by the user | /etc/opt/opera/policies/managed/ |
Each address in the Windows registry is a separate string value (REG_SZ) with a numeric name. Example:
reg add "HKLM\SOFTWARE\Policies\Google\Chrome\LocalNetworkAccessAllowedForUrls" /v 1 /t REG_SZ /d "https://corp.express" /f
Example for Linux — file /etc/opt/chrome/policies/managed/express.json:
{
"LocalNetworkAccessAllowedForUrls": ["https://corp.express"]
}
On macOS, the same policy is distributed via a configuration profile for the preference domains com.google.Chrome, com.microsoft.Edge, and similar.
chrome://policy, edge://policy, browser://policy, vivaldi://policy. The policy should be displayed with the status OK and indicate the source — the directory or registry key from which it was read.Mozilla Firefox
The policy LocalNetworkAccess is used with an array of exceptions SkipDomains. The policies.json file:
{
"policies": {
"LocalNetworkAccess": {
"SkipDomains": ["corp.express"],
"Locked": true
}
}
}
The same via Windows group policies:
Software\Policies\Mozilla\Firefox\LocalNetworkAccess\SkipDomains\1 = "corp.express"
*.corp.express includes both the domain itself and all subdomains. An entry without *. applies only to an exact match.Apple Safari
There is no per-site local network access policy. Management is possible only at the macOS level — through the permission in the Local Network section of privacy settings, which Safari obtains automatically.
Temporarily Disabling Checks
While the infrastructure is not ready and the permission has not been distributed, checks can be disabled entirely — both centrally for all browsers in the organization and manually on a single computer for diagnostics. This should be an emergency measure, not a permanent setting.
| Browser | Centrally (for administrators) | Manually on a single instance |
|---|---|---|
| Chrome, Edge, Yandex Browser, Vivaldi | The same registry key or policies directory as for LocalNetworkAccessAllowedForUrls above — add the LocalNetworkAccessRestrictionsTemporaryOptOut parameter (REG_DWORD on Windows, boolean on macOS and Linux) with the value 1 / true |
chrome://flags/#local-network-access-check > select Disabled and restart the browser.In Edge — edge://flags/..., in Yandex Browser — browser://flags/..., in Vivaldi — vivaldi://flags/... |
| Opera | On Windows, it cannot be distributed centrally; on Linux — the same policies directory as above. | opera://flags/#local-network-access-check > Disabled |
| Mozilla Firefox | The same policies.json file as above — the LocalNetworkAccess policy with the parameter "Enabled": false disables all checks completely |
about:config > parameter network.lna.enabled > false |
| Apple Safari | Not applicable — WebKit has not yet implemented local network access restrictions, so there is nothing to disable | |
The value 1 / true for LocalNetworkAccessRestrictionsTemporaryOptOut does not just hide the warning: it disables the blocking of local network requests itself — instead of blocking, the browser only outputs a warning in the developer console when a potential violation occurs.
LocalNetworkAccessAllowedForUrls.What to Consider for the Future
- The restriction is gradually being extended to more connection types. Initially it affected regular requests to the server, then WebSocket connections, and application to WebRTC is in development. When that happens, media connections will also stop working directly without the granted permission.
- The restriction does not apply if the web app itself is opened via an address within your network. If the organization deploys its own instance of the web app in a closed network segment, the problem does not arise.
- The restriction is determined by the destination IP address, not by the domain name. The same web app address may require permission in one network and not in another — this is expected behavior.
Time Synchronization Setup 
For the application to work correctly, the time must be synchronized both on user devices and on servers. If the time is out of sync, sign-in errors, incorrect message timestamps, and a user status displayed with a future time are possible.
How Do I Customize the Time on My Device?
Turn on automatic date, time, and time zone: steps for each platform are in the table below. After that, you don’t need to log out or reinstall the app.
- If the app did not let you log in, try logging in again. If that doesn’t work, restart the app and try again.
- If you are already logged in, restart the app: on your phone, swipe it from the list of open apps; in the web and desktop apps, press Ctrl (Cmd) + R.
| Platform | Steps |
|---|---|
| Windows | Open Settings > Time & Language > Date & Time. Turn on Set time automatically and Set time zone automatically, then click Sync now. |
| macOS | Open System Preferences > General > Date & Time. Turn on Set date and time automatically and Set time zone automatically. |
| Linux | Turn on automatic time synchronization in your desktop settings (date and time section). If there is no such setting, run sudo timedatectl set-ntp true in the terminal and check the result with the command timedatectl status: in the System clock synchronized line, there should be yes. |
| Android | Turn on automatic date, time, and time zone in system settings. |
| iOS/iPadOS | Turn on automatic time setting in the system settings. If it is already enabled, turn it off and turn it on again. |
| Aurora | Turn on automatic date and time in system settings. |
If after that the time on the device still differs from the actual time, contact your organization's Support: on the corporate network, the source of accurate time may be set by policies.
For Administrators: Time Synchronization on Servers
CTS
eCTS
On platform servers, time is synchronized by the NTP client chrony. Installation and configuration are described in the operating system preparation sections: , , .
If your company has its own exact time sources, specify them in the chrony configuration instead of the pool line and restart the service. You can check which sources the server is connected to with the chronyc sources -v command.
Remote Desktop & Virtual Desktop 
When using VDI (such as VMware Horizon or Citrix) or connecting via the RDP protocol, preliminary configuration is required.
Why Do I Have to Sign In to the App Again After Ending a VDI Session?
The sign-in screen may appear again because VDI provides a new empty browser profile or a new user folder the next time the user connects. The solution is to configure folder persistence between VDI sessions.
For Administrators: Configure Folder Persistence in VDI Sessions
You need to configure the persistence of browser and application profile folders between VDI sessions. Otherwise, users will have to sign in to the application again each time they reconnect through VDI.
| OS | Folders |
|---|---|
| Windows |
|
| macOS |
|
| Linux |
|
Default is the default browser profile folder. If a user works in a different profile, specify that folder instead: it is named Profile 1, Profile 2, and so on (for Firefox — (<random_code>).default(-release)). The exact path is visible in the browser itself on the chrome://version page (in Yandex Browser — browser://version) in the Profile Path field. A profile named Default might not exist at all.
Data must be copied and restored when the browser is closed.
If persisting the entire profile folder is not possible (for example, the size of the roaming profile is limited), the minimum required set within it is:
IndexedDB— required: this is where the eXpress web app stores the session. It is not stored in cookies; the server does not set them at all.Local Storage— required along withIndexedDB: without it, the saved session will be considered outdated.Network(Windows only) — cookies for other sites.Local Statein the root of the browser folder (Windows only) — the key used to encrypt cookies.
Cache, Code Cache, and Service Worker folders do not need to be persisted: they will be repopulated, but they account for the bulk of the profile size — several gigabytes.
The
Network subfolder within the profile exists only for Chromium-based browsers on Windows. On macOS and Linux, the same browsers store the cookies file directly in the profile folder.
The cookie encryption key is stored separately from the profile: on Windows — in the
Local State file, on macOS — in the Keychain, on Linux — in GNOME Keyring or KWallet. If the profile folder is persisted without them, cookies cannot be decrypted.
You can verify the result in the browser: F12 > Application > IndexedDB > there should be an
authState database with non-empty storage.Calls and Conferences via VDI/RDP 
Why do calls via VDI work worse than on a physical computer?
⚠️ We cannot guarantee that audio/video calls will work correctly over VDI, and the following recommendations may not help in all cases. Developers are continuing to optimize app performance in VDI environments.For Administrators: Blocking Calls in VDI for the Desktop App 
If your VDI environment does not support calls, you can forcibly disable them in the application. The application does not always correctly detect a VDI environment, so this mode must be set separately:
| Desktop Platform | Steps |
|---|---|
| Windows |
|
| macOS |
|
| Linux |
|
For Administrators: Configure Sound in VMware Remote Console
You can use VMware Remote Console to add and remove sound cards on Windows and Linux Horizon virtual machines. To add a sound card:
- Go to the required virtual machine in VMware Remote Console and open its settings:
- In Windows, select VMRC > Manage > Virtual Machine Settings.
- In Linux, select Virtual Machine > Virtual Machine Settings.
- Open the Hardware tab and click Add.
- Select Sound Card and click the Finish button.
Configure Sound in the VMware Horizon Client
In the Horizon client settings, you need to select specific audio and video input/output devices. If you don't do this, some devices might not work in the desktop application.
How to select devices:
- In the VMware Horizon client, select Settings.
- In the Real-Time Audio-Video section, instead of All in the fields, select the devices that will be used for communication.
Select devices in the settings of the desktop application installed on the virtual machine:
- Microphone: Microphone array (VMware Virtual Microphone). You might need to switch to another device and then select this one again for it to work (the indicator "comes alive").
- Output device: Specify the default device used in the system.
- Camera: There might be several options, but only one will work.
For Administrators: Configure Sound on the RDP Server (Windows)
In the Group Policy Editor under Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection, enable the following policies:
- Allow audio and video playback redirection
- Allow audio recording redirection
Configure Sound in the RDP Client
For sound to work in conferences when connecting via RDP, allow access to your computer's audio devices in the connection settings:
| OS and Client | Steps |
|---|---|
| Windows (Remote Desktop Connection) |
|
| macOS (Microsoft Remote Desktop) |
|
| Linux (Remmina) |
|
Certificate Management 
For Administrators: About SSL Certificates & Diagnostics
CTS
ETS
eCTS
Client Certificates
Most corporate servers use standard certificates included in popular client operating systems, which do not require manual installation. When using organization's own certificates, install the certificate in the device's OS.
Server Certificates
Installation instructions: administrator documentation.
Certificate Verification
Refer to SSL Certificates Diagnostics.
-
❓Related Topics:
- Certificate installation: Android | iOS/iPadOS | Windows | macOS | Linux | Web | Server
- Unhandled_service_error | “An Error Occurred” After Entering SMS Code
- “Network Error, Check Server Connection”, “Server with Specified Hostname Not Found”, “Pairing Error” When Scanning QR Code
- “SSL Error”, “Server Connection Error”, “Connection Error” on Android When Entering Phone Number, Email Code, or Corporate Server Address
- The app stopped connecting after a certificate change
- The server certificate has been revoked or has expired
Ministry of Digital Development National Certification Authority Certificates 
If your organization's server has switched to a TLS certificate from the Ministry of Digital Development National Certification Authority (Russian Trusted Root CA and Russian Trusted Sub CA), some devices will require manual installation of this authority's certificates — otherwise the app will not be able to connect to the server.
Whether any action is needed depends on the operating system:
| Platform | What to do |
|---|---|
| Russian operating systems: Astra Linux, RED OS, Aurora Russian browsers: Yandex Browser, Chromium GOST, Atom |
No action needed. The Ministry of Digital Development certificates are included in the operating system or browser, and the app uses them. |
| Android | No action needed. Starting from version 3.24, the app uses developer-built-in certificates — the Ministry of Digital Development certificates are among them. ETS
Exception — branded ETS apps and builds with SSL Pinning: their built-in certificate set may differ, and after the server switches to the Ministry of Digital Development certificates, the app stops connecting for all employees at once. This is resolved on the build side — contact your organization's support. ⚠️ If your organization's server uses a certificate from a different certification authority whose root is not built into the app, the connection on Android will not work: installing the certificate in the system on versions 3.24 and later has no effect. In this case, contact your organization's support — the issue is resolved on the app build side. |
| Windows | Install both certificates manually following the instructions. |
| macOS | Install both certificates manually and be sure to enable trust for them following the instructions. |
| iOS / iPadOS | Install both certificates manually and enable trust for them following the instructions. |
| Other Linux: Debian, Ubuntu, Linux Mint, and derivatives |
Install both certificates manually. ⚠️ On these systems, installing the certificate in the system-wide store is not enough for the desktop app — see the instructions. |
After installing the certificates, fully quit the app and start it again. On Windows, macOS, and Linux, the app keeps running in the background after the window is closed — close it using the icon in the notification area (system tray).
Where to Get Ministry of Digital Development Certificates
The root and intermediate certificates are published on the Gosuslugi portal: . Both are needed.
If the organization's server uses a regular (non-GOST) certificate, take the non-GOST option. GOST certificates require a separate cryptographic provider on each device and are not suitable here.
For Administrators: How to Verify the Result and Mass Deployment
How to Check That the Server Has Switched to Ministry of Digital Development Certificates
Open a link like https://your_server_address/system/settings/version in the browser and check the certificate details using the padlock icon in the address bar. The issuer field will show Russian Trusted Sub CA.
If the browser reports that the certificate is untrusted, the Ministry of Digital Development certificates have not yet been installed on this device.
Mass Deployment
On Windows, certificates are distributed via group policies to the local computer store. On macOS and iOS — only through a mobile device management (MDM) system or a configuration profile: only the user at the computer can manually set trust for a certificate — this cannot be done by script or remotely.