CoSign
CoSign, from ARX (Algorithmic Research), holds FIPS 140-2 certificate #1422 at overall level 3. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in FIPS mode
Certificate
| Certificate number | 1422 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | Multi-chip standalone |
| Vendor | ARX (Algorithmic Research) · website |
| Hardware versions | 7.0 |
| Firmware versions | 5.2 and 6.0 |
Module description
Quoted from the NIST CMVP entry for this certificate.
CoSign is a digital signature appliance that is connected to the organizational network and manages all signature keys and certificates of organization's end-users. End-users will connect securely to CoSign from their PC for the purpose of signing documents and data.
Approved algorithms (6)
| Algorithm | CAVP certificates |
|---|---|
| HMAC | 799, 1405 |
| RNG | 750, 1139 |
| RSA | 665, 1177 |
| SHS | 1244, 1245, 1970, 1971 |
| Triple-DES | 939, 940, 1437, 1438 |
| Triple-DES MAC | vendor affirmed |
Other algorithms
MD5; RSA (key wrapping; key establishment methodology provides 80 bits of encryption strength; non-compliant)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2010-10-25 | Initial | CYGNACOM SOLUTIONS INC |
| 2013-01-22 | Update | CYGNACOM SOLUTIONS INC |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2010-10-25, 2013-01-22