808bits

CoSign

FIPS 140-2 certificate #2590 · ARX (Algorithmic Research) · data as of 2026-08-28
Historical. Moved to historical list due to dependency on certificate #1883. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS Mode. This module contains the embedded module eToken 5105 validated to FIPS 140-2 under Cert. #1883 operating in FIPS mode. No assurance of the minimum strength of generated keys.

Certificate

Certificate number2590
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorARX (Algorithmic Research) · website
Hardware versions7.0
Firmware versions7.7

Module description

CoSign is a digital signature appliance that is connected to the organizational network and manages all signature keys and certificates of organization's end-users. End-users will connect securely to CoSign from their PC for the purpose of signing documents and data.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
CVL697
DRBG1028, 98
HMAC2441, 2453
PBKDFvendor affirmed
RSA1929
SHS3109, 3122
Triple-DES2074, 2087
Triple-DES MACvendor affirmed

Other algorithms

NDRNG; MD5; Triple-DES (Cert. #2074, key wrapping; key establishment methodology provides 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength); SHS (non-compliant); HMAC (non-compliant); Triple-DES (non-compliant); RSA-RESTful-TLS (key wrapping; non-compliant)

Tested configurations

  • N/A

Validation history

DateTypeLab
2016-03-24InitialCYGNACOM SOLUTIONS INC

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-03-24

Source documents