Dragdox 0.2.2Windows 10 / 11 · Ubuntu 20.04, 22.04, 24.04 · Debian 1264-bitDownload the installer

How to Sign a PDF with a USB DSC Token

Use a USB digital signature certificate (DSC) token with Dragdox on Windows or Linux. Dragdox talks to the token through the manufacturer’s PKCS#11 driver, and on Windows it can also use the certificate through the Windows certificate store.

What you need

  • The token with a valid signing certificate on it, and its PIN.
  • The manufacturer’s driver (middleware) for your operating system, installed. Dragdox needs the 64-bit PKCS#11 library.
  • Dragdox installed. A Dragdox license is not a DSC and does not put a certificate on your token.

Steps

  1. Install the token driver and plug in the token.
  2. Open Dragdox → Settings → Keystore. On Windows either keep Win Store on, or turn on PKCS#11 Store. On Linux PKCS#11 is on by default. Check that your token’s driver is in the list, or add it with Browse PKCS#11 File.
  3. Open PDF, then Begin Sign and drag a rectangle where the signature should go (or pick an existing signature field).
  4. Choose your token’s certificate and click Choose.
  5. Set the appearance and click Sign. Enter the token PIN when asked.
  6. Choose where to save the signed copy.

Default driver locations

Windows

TokenDriver (PKCS#11 library)
HYP2003 (FIPS 140-2 setup)C:\Windows\System32\eps2003csp11v2.dll
HYP2003 (FIPS 140-3 setup)C:\Windows\System32\HYP2003csp11IND.dll
HYP2003 (Hypersecu HyperPKI middleware)C:\Windows\System32\HyperPKICsp11_2003.dll
WD PROXKeyC:\Windows\System32\SignatureP11.dll
mToken CryptoIDC:\Windows\System32\CryptoIDA_pkcs11.dll, cryptoida_pkcs11_f3.dll, cryptoida_pkcs11_f2.dll
InnaIT Key (Precision)C:\Windows\System32\InnaITPKCS11Driver.dll

Linux

TokenDriver (PKCS#11 library)
WD PROXKey/usr/lib/WatchData/ProxKey/lib/libwdpkcs_SignatureP11.so
mToken CryptoID/opt/CryptoID/x64/lib/libcryptoid_pkcs11.so
InnaIT Key (Precision)/opt/Precision_Biometric/InnaITDSC/libraries/libInnaITPKCS11Driver.so
HYP2003libcastle_v2.so.1.0.0 — no fixed location; add it yourself (see below)

What we have tested

Generic PKCS#11 support does not prove that every token and driver combination works. This is exactly what we have checked so far:

TokenSystemDriverResultDate
WD PROXKeyWindows 11SignatureP11.dll (WD PROXKey 7.0.0)Certificate listed in Dragdox, through the PKCS#11 driver and through the Windows certificate store28 September 2026
HYP2003 FIPS 140-3Ubuntu 24.04libcastle_v2.so.1.0.0 from the FIPS 140-3 Linux packageCertificate listed in Dragdox. The FIPS 140-2 library failed with this token.28 September 2026
mToken CryptoIDWindows 11, Ubuntu 24.04cryptoida_pkcs11_f2/_f3.dll; libcryptoid_pkcs11.soDriver loads. Not yet tested with a token.28 September 2026
InnaIT KeyWindows 11InnaITPKCS11Driver.dllDriver loads. Not yet tested with a token.28 September 2026

Signing with PIN entry has not yet been verified by us with any of these tokens. Test your own token with the free version before buying Premium.

If your certificate is not listed

  • Check that the driver file exists at the listed path and is the 64-bit version.
  • Dragdox lists only certificates that are valid today, allow digital signatures and are not certificate-authority certificates. An encryption-only or expired certificate on the token is not shown.
  • On Linux, make sure the smart-card service your driver uses is running, and that the vendor’s USB permission rules are installed.
  • Unplug and re-insert the token, then start signing again.

Driver downloads

Get drivers from your token’s manufacturer or the supplier who issued your DSC. Manufacturer download pages we have checked: Hypersecu (HYP2003) and InnaIT Key DSC.