Callback
  • From a market stall to a store

  • -

  • From a store to a retail chain

  • -

  • From retail to manufacturing

PECR does not load business units: how to restore the connection

Volodymyr Vytyshchenko
Volodymyr Vytyshchenko

Trade automation expert at Torgsoft

pECR does not load business units: how to restore the connection after Error connecting with SSL / tlsv1 alert protocol version

When registering or configuring a pECR in Torgsoft, the program connects to the State Tax Service services to retrieve available business units, registered pECRs, and cashiers based on the QES data. Entrepreneurs usually ask specialists why the list does not load, whether the Error connecting with SSL / tlsv1 alert protocol version message is related to the QES key, which versions of Torgsoft and Windows are required, whether reinstalling certificates will help, and in what order the computer, network, and registration data should be checked.

Short answer

The Error connecting with SSL message with the detail tlsv1 alert protocol version means that a secure TLS connection could not be negotiated. The exchange of application data with the State Tax Service has not yet started, so the program could not retrieve the list of business units.

For Torgsoft, the key check is the program version. The fix for loading taxpayer data and support for TLS 1.3 were added in stable version 2022.0.59; the corresponding changes were also included in the 2022.4.12 test branch. This is confirmed by the release notes for version 2022.0.59 and the release notes for version 2022.4.12.

The practical procedure is as follows:

  1. Record the full message text and identify the computer where Torgsoft is actually running.

  2. Check the date, time, Torgsoft version, and Windows version.

  3. Update Torgsoft to the current stable version on the workstation or server.

  4. Install Windows system updates and restart that specific computer or server.

  5. Test the connection through another trusted network.

  6. Only after restoring the TLS connection should you check the QES, certificates, and registration of the business unit with the State Tax Service.

Basic concepts

What is a business unit

 A business unit is a store, warehouse, kiosk, online store, or another facility where a business entity conducts its activities. The facility is reported to the State Tax Service using Form 20-OPP, after which a pECR can be linked to it.

One Sole Proprietorship or one legal entity may have several business units. During configuration, Torgsoft loads only the facilities that the signer has access to using the selected QES.

What are TLS and SSL

 TLS is a protocol for secure data exchange between the program and the server. The term SSL is often retained in program messages and libraries, although modern connections use TLS.

Before sending a request, the parties perform a TLS handshake:

  • they negotiate the protocol version and cryptographic parameters;

  • the server provides its TLS certificate;

  • the program verifies whether the certificate is trusted;

  • after successful verification, a secure channel is established.

If this stage is not completed, Torgsoft receives neither the list of business units nor information about their registration status from the State Tax Service service.

The server TLS certificate and QES are different things

Two independent sets of certificates are involved in diagnostics:

  • The server TLS certificate protects the network connection. Its trust is verified by the program and the operating system.

  • The Qualified Electronic Signature (QES) and the signer’s certificate identify the entrepreneur or cashier and determine access to pECR data.

Therefore, reinstalling the QES is not the first step when tlsv1 alert protocol version appears. First, the TLS connection must be restored. Checking the QES makes sense when the secure channel is already working but the State Tax Service does not return the required facilities or does not recognize the signer.

What exactly does tlsv1 alert protocol version mean

According to the TLS specification, the protocol_version alert is sent when one party recognizes the proposed protocol version but does not support it; this alert terminates the connection.

 Important clarification: the word tlsv1 in the technical message name does not prove that the program was necessarily trying to connect using TLS 1.0. It is the name of a class of TLS messages in the library. For diagnostics, the important part is alert protocol version: the client, server, or an intermediate network node could not negotiate an acceptable protocol version.

For Torgsoft, there is a known historical scenario: version 2022.0.59 fixed the taxpayer data update function, which previously ended with Error connecting with SSL, and added support for TLS 1.3 instead of the previously used TLS 1.2. This does not mean that every current failure is caused solely by the Torgsoft version. A similar response may also be returned by a proxy server, an HTTPS traffic inspection tool, or another intermediate network component.

How to distinguish a TLS failure from a State Tax Service registration problem

Symptom

Stage at which it occurs

What to check first

Error connecting with SSL and tlsv1 alert protocol version

Before receiving an application-level response from the State Tax Service

Torgsoft version, Windows, network path, proxy, and HTTPS inspection

certificate verify failed, certificate not trusted

While verifying the server TLS certificate

Date and time, system updates, root certificates, proxy, or antivirus with HTTPS inspection

“Key certificate not found”

While working with the QES

QES validity period, QTSP, IIT cryptographic libraries, path to “CA User”

“Operation not supported”, library not initialized

When starting local cryptographic components

Path to the components and Windows account permissions

“No available business units” without SSL text

The TLS connection has already been established, but no facilities were returned for the signer

20-OPP, 1-pECR, 5-pECR, Receipt No. 2, and KeyID

This distinction saves time. If an empty list appears after the update instead of the SSL message, this is not a continuation of the TLS failure. The network stage has already been completed, and you should proceed to checking the registration data.

How to distinguish a TLS failure from a State Tax Service registration problem?

Step-by-step connection check

Step 1. Record the initial data

Before changing any settings, take a screenshot and record:

  • the full message text, including the line after Error connecting with SSL;

  • the date and time when it appeared;

  • the action after which it appeared: “Update taxpayer data”, selecting a business unit, registering a pECR, or another operation;

  • the Torgsoft version;

  • the Windows edition and build number;

  • whether the program runs locally, from a network folder, or through Remote Desktop.

Do not delete the configured pECR, business unit, or key. Recreating records does not resolve TLS incompatibility and may complicate further troubleshooting.

Step 2. Determine where Torgsoft is actually running

This is important for stores with a server or RDP.

  • If Torgsoft is running directly on the checkout PC, this PC must be checked and updated.

  • If an employee opens the program via Remote Desktop, the server initiates the TLS connection. Updating the home or checkout computer does not replace updating the server.

  • If a shortcut launches the program from a network resource, determine which executable file is being used and where its components are located.

When contacting support, describe this setup in one sentence, for example: “Torgsoft is running in an RDP session on Windows Server.”

Step 3. Check the Torgsoft version

In the program, open “Help” → “About” and record the full version number.

Reference points for this specific message:

  • 2022.0.59 — the stable version in which taxpayer data loading was fixed and TLS 1.3 support was added;

  • 2022.4.12 — the corresponding historical test branch.

If the version is older, do not waste time manually copying DLL files or editing the Windows registry. First:

  1. create a backup of the current Torgsoft database;

  2. have all users exit the program;

  3. install the current stable version using the standard procedure;

  4. restart the program;

  5. run “Update taxpayer data” again.

Even if version 2022.0.59 or later is installed, a production system should use the current stable release rather than remain on the historical minimum version. Current releases are published in the Torgsoft update log.

Step 4. Check Windows, date, and time

Press Win + R, enter winver, and record the Windows edition and build. Then check:

  • the correct date;

  • the correct time;

  • the UTC+02:00 / UTC+03:00 time zone for Ukraine depending on the season;

  • automatic time synchronization;

  • available system updates;

  • completion of the update by restarting the computer.

An incorrect time may make a valid certificate appear “not yet valid” or “expired”. An outdated system may lack current root certificates and cryptographic components.

Torgsoft TLS support should not be equated with system-level TLS support in Windows. According to the Microsoft Schannel matrix, native TLS 1.3 support starts with Windows 11 and Windows Server 2022; Microsoft does not recommend forcibly enabling TLS 1.3 in Schannel on earlier versions. At the same time, an individual program may use its own TLS library. Therefore, manually changing Schannel settings is not a substitute for updating Torgsoft.

For a pECR workstation, it is advisable to use an operating system that receives security updates. Support for Windows 8.1 ended on January 10, 2023, and standard support for Windows 10 ended on October 14, 2025. This is stated in the Windows 8.1 lifecycle and Microsoft Windows Update documentation. The fact that Torgsoft can run on an older version of Windows does not mean that such a system continues to receive security fixes.

Step 5. Check the network path

Perform three control tests:

  1. Open the official State Tax Service website in a browser on the same computer or server.

  2. Try loading the business units in Torgsoft again.

  3. Temporarily connect this computer to another trusted network, for example via a mobile hotspot, and repeat the operation.

Interpret the results as follows:

  • Neither the browser nor Torgsoft works — check the internet connection, DNS, gateway, proxy, and general network restrictions.

  • The browser opens the website, but Torgsoft displays a TLS message — this does not rule out a TLS problem. The browser and the program may use different libraries, protocol sets, and certificate stores.

  • Torgsoft works through mobile internet but not through the store network — the cause is most likely the local router, proxy, firewall, DNS filter, or HTTPS traffic inspection.

  • The result is the same on both networks — return to checking the Torgsoft version, Windows, and cryptographic components on this computer.

If the company uses a proxy or antivirus with HTTPS inspection, provide the administrator with the exact time of the attempt and the name of the Torgsoft executable file. The administrator should check blocking logs and outbound HTTPS connection rules.

Do not permanently disable the firewall or antivirus, and do not create broad exceptions for the entire drive or all programs. If a control test requires a temporary change to protection settings, it should be performed by the responsible administrator, with the settings restored afterward.

Step 6. Check TLS certificates only when the symptom indicates it

If the message changes to a certificate trust error, check:

  • the system date and time;

  • installed Windows updates;

  • whether a proxy or antivirus is replacing the server certificate with its own;

  • whether Windows trusts the corporate root certificate if HTTPS inspection is actually being used;

  • whether the same result occurs on another network.

Do not install random root certificates from forums or add them to the trusted store merely because their names look similar to the required certificate. A root certificate can establish trust for websites, so its source and purpose must be verified.

Step 7. Check the QES and cryptographic components

Proceed to this step if the TLS connection has already been restored or if the message directly refers to the key.

Check:

  • whether the key of the correct Sole Proprietorship or legal entity is selected;

  • whether the certificate has expired;

  • whether the key has been revoked;

  • whether the password is entered correctly;

  • whether the signing certificate, rather than the encryption certificate, is registered with the State Tax Service;

  • whether the Windows account has access to the cryptographic components folder.

For the “Key certificate not found” message, Torgsoft recommends updating the IIT components using the official “CA User” installer and then restarting the computer or server. A detailed procedure is provided in the Torgsoft guide on a missing certificate.

If “Operation not supported” appears or the program reports an uninitialized library, check the path to the installed “CA User” and the permissions of the account under which Torgsoft is actually running. Do not grant Everyone full access to program folders without analysis: sufficient permissions should be granted to the specific user or service account.

If the QES has been replaced because it expired, first register the new key with the State Tax Service using Form 5-pECR, wait for Receipt No. 2, and then select the new key in Torgsoft. The replacement procedure is described in the Torgsoft guide on a new QES.

Step 8. Check the registration of the business unit

If the SSL text has disappeared and the key can be read, but the list of business units is empty, check the documents in the following order:

  1. 20-OPP — the business unit has been reported and registered.

  2. 1-pECR — the pECR is registered for the correct business unit and has a valid status.

  3. 5-pECR — the certificate of the signer whose QES is selected in Torgsoft is linked to the pECR.

  4. Receipt No. 2 — the document has been accepted, not merely sent.

  5. KeyID — the certificate identifier in the receipt matches the identifier of the selected key.

After the registration form has been accepted, the data may not appear immediately. The Torgsoft explanation about missing business units recommends waiting from 15 minutes to one or two hours after receiving Receipt No. 2 and then trying to load the data again.

The State Tax Service also explains that the business units and pECRs available to a cashier are determined by the signer’s KeyID. The signing certificate identifier specified in the notification of public key certificates is used for login. See the State Tax Service explanation regarding missing business units.

If the documents have been accepted but the facility has not appeared, additionally check whether the pECR has been blocked using Form 2-pECR and whether the cashier’s work has been terminated.

Step 9. Repeat the control procedure

After each significant change, test the same procedure:

  1. Start Torgsoft under the same Windows account.

  2. Open “Settings” → “Software ECR” → “pECR Registration”.

  3. Select the company and the required QES.

  4. Update the taxpayer data.

  5. Open the business unit selection.

A successful result has two separate indicators:

  • the TLS message does not appear;

  • the expected business unit appears in the list, or the State Tax Service returns a clear response about its status.

If the TLS message has disappeared but the required unit is still missing, do not return to reinstalling TLS components: proceed to checking 20-OPP, 1-pECR, 5-pECR, and KeyID.

Practical scenarios

Scenario 1. Old Torgsoft version, State Tax Service website opens

Condition: the internet works in the browser, but when taxpayer data is updated, Torgsoft displays tlsv1 alert protocol version; the program version is older than 2022.0.59.

Cause: the browser and Torgsoft use different TLS components. A working browser does not update the network library of an old Torgsoft version.

Action: back up the database, update Torgsoft to the current stable version, restart it, and test again.

Scenario 2. Works on a mobile network but not on the store network

Condition: the Torgsoft version is current; the list loads through a mobile hotspot but not through the store’s main provider.

Cause: the problem is in the store’s network path — proxy, firewall, DNS filtering, router, or HTTPS inspection.

Action: provide the administrator with the exact test time and the network comparison result; check security logs and outbound HTTPS connections.

Scenario 3. The list is empty after the update

Condition: the TLS text no longer appears, the QES password is accepted, but the program reports that no business units are available.

Cause: the transport layer is already working; the State Tax Service does not associate the selected KeyID with an active business unit, or the changes have not yet been synchronized.

Action: check the acceptance of 20-OPP, 1-pECR, and 5-pECR, Receipt No. 2, and whether the KeyID matches; after the latest form is accepted, wait up to two hours.

Scenario 4. Working through Remote Desktop

Condition: the cashier connects from Windows 11 to a server running an older Windows Server, and Torgsoft runs in an RDP session.

Cause: the TLS request is made by the server, not the cashier’s computer.

Action: check and update Torgsoft, Windows, time, certificates, and network rules specifically on the server.

What not to do

  • Do not manually copy libssl, libcrypto, or other DLL files from random sources. An incompatible architecture or version may make the program unstable.

  • Do not edit the Windows registry to forcibly enable TLS 1.3 on a system where Microsoft does not support it.

  • Do not delete pECR configuration folders or recreate the registrar until the initial data has been recorded.

  • Do not permanently disable protection or add the entire drive to antivirus exclusions.

  • Do not install unknown root certificates to bypass trust verification.

  • Do not randomly resubmit registration forms. First check the status and Receipt No. 2 for the previous form.

  • Do not send the private key file or password to technical support. For diagnostics, the provider name, validity period, public certificate, or KeyID without secret data is sufficient.

Frequently asked questions

?

Does tlsv1 mean that Torgsoft uses TLS 1.0?

Not necessarily. It is part of the technical name of the TLS alert. The decisive part is alert protocol version: the parties did not negotiate an acceptable protocol version.

?

Why does the State Tax Service website open while the business units do not load?

The browser and Torgsoft may use different TLS libraries, certificate stores, and network rules. A browser test confirms only general internet access, not whether the specific Torgsoft connection works.

?

Will reinstalling the QES certificate help?

For tlsv1 alert protocol version — usually not, because the failure occurs before the signer’s access is checked. The QES should be checked when the program reports an issue with the key certificate, validity period, password, KeyID, or absence of available units.

?

Should I wait for the data to appear on its own?

Waiting for up to one or two hours is appropriate after the form has been accepted and Receipt No. 2 has been received, provided that the TLS connection is already working. Waiting will not resolve TLS version incompatibility.

?

Is installing Torgsoft 2022.0.59 enough?

For a production system, install the current stable release compatible with your database and configuration, and create a backup before updating.

?

Can I continue using Windows 7, 8.1, or 10?

The fact that the program runs does not mean the operating system is still supported by its manufacturer. Windows 7 and 8.1 no longer receive standard security updates, and standard support for Windows 10 ended on October 14, 2025. For a checkout workstation, you should plan to migrate to a supported version of Windows or an appropriate server edition.

?

Do all workstations need to be updated?

Start with the computer or server where the problematic operation is actually being performed. In a network installation, version updates should be coordinated so that clients and server components operate in a supported configuration.

?

If mobile internet helped, should Torgsoft be reinstalled?

Not as the first step. A successful test through another network points to the local network path. Check the router, proxy, firewall, DNS filtering, and HTTPS inspection.

?

Why is the business unit still missing after the SSL message has been resolved?

Because this is a different stage. The connection has already been established, but the selected QES may not have access to the facility. Check the sequence 20-OPP → 1-pECR → 5-pECR, Receipt No. 2, and KeyID.

What to prepare for technical support

To prevent the specialist from having to start diagnostics by collecting the same information again, send:

  • a screenshot showing the full message text;

  • the exact time of the most recent failed attempt;

  • the Torgsoft version number;

  • the Windows edition and build from winver;

  • a description of the setup: local PC, network folder, or RDP server;

  • the name of the internet provider and the result of testing through another network;

  • the QES provider name and certificate validity period, without the key file or password;

  • the statuses of 20-OPP, 1-pECR, and 5-pECR and whether Receipt No. 2 is available, if TLS is already working;

  • whether the message appeared after updating Windows or Torgsoft, replacing the QES, router, or antivirus.

A Torgsoft support request is created via “Help” → “Technical Support Request”. Current contact details:

  • phone: +38 (067) 558-37-84, Monday–Saturday, 09:00–18:00;

  • Telegram: @torgsoft_help daily.

  • email: info@torgsoft.ua.

Contact details and working hours are published on the Torgsoft technical support page and in the guide to creating a support request.

Final troubleshooting algorithm

If Torgsoft does not load business units and displays Error connecting with SSL / tlsv1 alert protocol version, check the system level by level:

  1. Program: current Torgsoft version; the historical fix has been available since 2022.0.59.

  2. Computer: correct date and time, updated supported Windows version, and restart of the actual PC or server.

  3. Network: compare the main connection with another trusted network; check the proxy, firewall, and HTTPS inspection.

  4. TLS certificates: analyze trust only when the message concerns the server certificate.

  5. QES: validity period, revocation, QTSP, cryptographic libraries, user permissions, and the correct signing certificate.

  6. State Tax Service register: 20-OPP, 1-pECR, 5-pECR, Receipt No. 2, and matching KeyID.

This sequence helps avoid confusing a transport-level TLS failure with the absence of registration access. First, the program must establish a secure connection; then the State Tax Service identifies the signer, and only after that can Torgsoft display the available business units.


Програма обліку товару | Торгсофт



Facebook Instagram YouTube Twitter Google News Apple Podcast SounCloud

Add comment

Add comment
Thank you for your feedback! It will be published after being reviewed by a moderator.

Related articles