Skip to main content
Ascertia ADSS Server is an enterprise platform that provides centralized digital signing, verification, and certificate validation services. It supports a wide range of document formats and signing standards including OASIS DSS, CAdES, XAdES, and PAdES. Integrating with CryptoHub through PKCS #11 keeps signing keys on FIPS-validated hardware — CryptoHub generates and stores keys so they are never exposed in software.

Key features

  • Multi-format document signing (PDF, XML, Office, CMS/CAdES)
  • OASIS DSS and proprietary signing endpoints (SOAP, REST-like)
  • Centralized signing profile management with granular client authorization
  • PKCS #11 crypto source support for hardware security modules
  • Certificate lifecycle management with integrated key generation
  • Three-layer authorization model for signing operations

Benefits of Vectera Plus integration through PKCS #11

  • Hardware-protected signing keys — RSA and ECC private keys are generated and used exclusively on the Vectera Plus, never exported to software
  • FIPS 140-2/3 compliance — Signing operations meet regulatory requirements for cryptographic key protection
  • Centralized key management — Manage all signing keys from a single HSM with full audit trail
  • Operational resilience — HSM clustering and key backup protect against key loss
  • Performance — Hardware-accelerated cryptographic operations for high-volume signing workloads

Guardian integration

For Guardian Series 3 integration with Ascertia ADSS Server, see the Guardian Series 3 PKCS #11 configuration guide.