DocuSign Signature Appliance
DocuSign Signature Appliance, from DocuSign, Inc., holds FIPS 140-2 certificate #3518 at overall level 3. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in FIPS mode. This module contains the embedded module eToken 5105 validated to FIPS 140-2 under Cert. #1883 operating in FIPS mode. No assurance of the minimum strength of generated keys
Certificate
| Certificate number | 3518 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | DocuSign, Inc. · website |
| Hardware versions | 8.0 |
| Firmware versions | 9.0.9.10 |
Module description
Quoted from the NIST CMVP entry for this certificate.
The DocuSign Signature Appliance is a digital signature appliance that is connected to the organizational network and manages all signature keys and certificates of organization's end-users. End-users will connect securely to the appliance from their PC for the purpose of signing documents and data. The DocuSign Signature Appliance also enables organization using AES based encryption keys for encrypting/decrypting data.
Security level exceptions
- Mitigation of Other Attacks: N/A
Approved algorithms (11)
| Algorithm | CAVP certificates |
|---|---|
| AES | C85, C86 |
| CKG | vendor affirmed |
| CVL | C86 |
| DRBG | 98, C85 |
| HMAC | C85, C86 |
| KTS | |
| PBKDF | vendor affirmed |
| RSA | C85, C86 |
| SHS | 1465, C85, C86 |
| Triple-DES | C85 |
| Triple-DES MAC | vendor affirmed |
Allowed algorithms
MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength); Triple-DES (Cert. #C85, key unwrapping)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2019-09-05 | Initial | CYGNACOM SOLUTIONS INC |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2019-09-05