808bits

DocuSign Signature Appliance

FIPS 140-2 certificate #2665 · DocuSign, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to dependency on certificate #1883. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. This module contains the embedded module eToken 5105 validated to FIPS 140-2 under Cert. #1883 operating in FIPS mode. No assurance of the minimum strength of generated keys

Certificate

Certificate number2665
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorDocuSign, Inc. · website
Hardware versions7.0 and 8.0
Firmware versions8.0

Module description

The DocuSign Signature Appliance is a digital signature appliance that is connected to the organizational network and manages all signature keys and certificates of organization's end-users. End-users will connect securely to the appliance from their PC for the purpose of signing documents and data.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
CVL786, 787
DRBG98, 1137, 1138
HMAC2551, 2552, 2563, 2564
KTS
KTS
PBKDFvendor affirmed
RSA2005, 2006
SHS3237, 3238, 3248, 3249
Triple-DES2155, 2156, 2160, 2161
Triple-DES MACvendor affirmed

Other algorithms

HMAC (non-compliant); MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength); RSA-RESTful-TLS (key wrapping; non-compliant); SHS (non-compliant); Triple-DES (non-compliant)

Tested configurations

  • N/A

Validation history

DateTypeLab
2016-06-21InitialCYGNACOM SOLUTIONS INC
2016-07-25UpdateCYGNACOM SOLUTIONS INC

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-06-21, 2016-07-25

Source documents