Français

English

You cannot login

"This page can't be displayed" or "Can't connect securely" error message when trying to login to the 3SKey portal

If you get an error message after clicking the Login button on https://www2.swift.com/3skey or after selecting your corp certificate, then please perform the following actions:

1

Verify that the 3SKey software is running

Verify that the 3SKey software has been installed on your system and that the Safenet Authentication Client is running. You should see the icon in the notification area at the bottom right of your desktop.

If the client is not running, then please start it from the Start Menu : All Programs > Safenet > Safenet Authentication Client > Safenet Authentication Client.

2

Verify that the token is detected on the system

If the token is detected in the Safenet Authentication Client software the icon will be bright red. Right-clicking the icon allows to click on "Certificate Information" to show the certificate data on the token.


On this screen you can verify that the certificate is not expired (status Valid) and test its password using the Log On button. You can also verify that the token has been activateed by double-clicking the corpxxxxxxxx certificate to display its properties. The policy displayed will be 1.3.21.6.3.20.200.1 for an activated business certificate. If the policy is 1.3.21.6.6.10.200.2 then the tkoen must still be activated on the 3SKey portal. Note that the presence of the certificate does not mean that the token is valid for signing or hasn't been revoked. Login with the token on the 3SKey portal to verify that the certificate is valid and activated, and check with your bank partners that it's been registered with them.

If the token is not detected by the Safenet application, check that the power led of the USB token is on. Compare with another USB port, another computer and another token to determine if the issue is linked to the port, computer or token.

With the help of your IT support check in the Device Manager (devmgmt.msc) that the token appears as USB Token under USB Controlers. In the Windows services (services.msc) restart the following services:
  • Smart Card
  • Certificate Propagation
3

Cleanup the Windows certificate cache

  1. Unplug your 3SKey token(s)
  2. Open the Personal Certificates store
  3. Press the Windows Key + R and type in inetcpl.cpl to open the Internet Options. Alternatively open Internet Explorer and go to Tools > Internet Options. Then go the Content tab and click on Certificates.

  4. If present remove cached 3SKey certificates issued by SWIFT
  5. If you see a corpxxxxxxxx certificate issued by SWIFT in the Personal or Other People tabs when no 3SKey tokens are plugged in, then you can safely remove it (the actual certificate resides on the token). Other personal certificates may be installed on your system - make sure that you only remove the corp certificates of your 3SKey tokens.

  6. Clear the SSL State
  7. Click Close to return to the Content tab, then click on Clear SSL State.

  8. Verify that the certificate is redetected and valid
  9. Reinsert the token and after 5 seconds click on Certificates to verify that the corp certificate of the token has been redetected.

    Verify the validity of the certificate by making sure that the "Expiration Date" value has not been passed yet. If the date has passed this means your certificate is expired and needs recovery.

  10. Attempt to login again and verify that you are selecting the certificate that corresponds to your token
  11. Go to https://www2.swift.com/3skey and click on login. If a certificate selection window opens and you do not see your corp certificate click on More Choices to select it.

4

Reset the TLS and browser settings



If the certificate is detected but you still can't login, then proceed with the following steps:
  1. Go to Internet Options > Advanced. In the dropdown list de-select all the SSL and TLS settings, then click on apply. Then reselect only TLS 1.2 and click on apply.
  2. On the same screen, click on Reset under the dropdown list to reset the Internet Explorer settings. If you wish to keep your browsing history and saved website passwords do NOT check the box “reset personal settings”.
  3. In the General tab click Delete under Browsing History. Tick the boxes Temporary Internet files and website files as well as Cookies and website data. Then click the Delete button.
  4. Click OK to apply the changes. Restart your computer if prompted to.
5

Check your organisation's network and security settings

If the certificate is detected but you still cannot login to the 3SKey portal after going through the above steps then contact your local IT support to check that nothing blocks or filters the TLS connection to the secure part of the portal https://www.3skey.com (IP 149.134.170.3) at the proxy, firewall or security level of your enterprise's infrastructure. If you have the Bit Defender antivirus you must uncheck "Encrypted web scan" under Online Threat Prevention. Kasperky antivirus can also filter the access to the secure web page.

To confirm that the token and its certificate can be accessed and that the issue is not with the local computer you can open a command prompt (start > cmd.exe) and run "certutil -scinfo". The command should prompt you for the token password then display its corpxxxxxxxx certificate.

SWIFT © 2019