DocuSign Signature Appliance
Caveat: When operated in FIPS mode. This module contains the embedded module eToken 5105 validated to FIPS 140-2 under Cert. #1883 operating in FIPS mode. No assurance of the minimum strength of generated keys. The module generates cryptographic keys whose strengths are modified by available entropy.
Certificate
| Certificate number | 3141 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | DocuSign, Inc. · website |
| Hardware versions | 8.0 |
| Firmware versions | 8.5 and 8.51.9.0 |
Module description
The DocuSign Signature Appliance is a digital signature appliance that is connected to the organizational network and manages all signature keys and certificates of organization's end-users. End-users will connect securely to the appliance from their PC for the purpose of signing documents and data.
Security level exceptions
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 5058, 5448 |
| CKG | vendor affirmed |
| CVL | 1615, 1894 |
| DRBG | 98, 1864, 2133 |
| HMAC | 3363, 3378, 3606, 3607 |
| KTS | |
| KTS | |
| KTS | |
| KTS | |
| KTS | vendor affirmed |
| PBKDF | vendor affirmed |
| RSA | 2729, 2743, 2924, 2925 |
| SHS | 1465, 4108, 4123, 4367, 4368 |
| Triple-DES | 2603, 2616, 2738, 2739 |
| Triple-DES MAC | vendor affirmed |
Allowed algorithms
MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2018-02-27 | Initial | CYGNACOM SOLUTIONS INC |
| 2018-08-17 | Update | CYGNACOM SOLUTIONS INC |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2018-02-27, 2018-08-17