U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.

Https

We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

Cryptographic Module Validation Program CMVP

Certificate #3916

Details

Module Name
YubiHSM 2 Cryptographic Module
Standard
FIPS 140-2
Status
Active
Sunset Date
5/2/2026
Overall Level
3
Caveat
When operated in FIPS mode, installed, initialized, and configured as specified in Section 3 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy.
Security Level Exceptions
  • Mitigation of Other Attacks: N/A
Module Type
Hardware
Embodiment
Single Chip
Description
The YubiHSM 2 is a USB-based, multi-purpose cryptographic device that is primarily used in servers. It is optimized for a small form factor and low power requirements.
Tested Configuration(s)
  • N/A
FIPS Algorithms
AES Cert. #C1680
CKG Vendor Affirmed
CVL Cert. #C1680
DRBG Cert. #C1680
ECDSA Cert. #C1680
HMAC Cert. #C1680
KAS-SSC Vendor Affirmed
KBKDF Cert. #C1680
KTS AES Cert. #C1680; key establishment methodology provides between 128 and 256 bits of encryption strength
KTS AES Cert. #C1680 and AES Cert #C1680; key establishment methodology provides 128 bits of encryption strength
RSA Certs. #A985 and #C1680
SHS Cert. #C1680
Allowed Algorithms
EC Diffie-Hellman (shared secret computation provides between 128 and 256 bits of encryption strength); NDRNG; RSA (CVL Cert. #C1680, key unwrapping; key establishment provides between 112 and 150 bits of encryption strength); RSA (key unwrapping; key establishment provides between 112 and 150 bits of encryption strength)
Hardware Versions
SLE78CLUFX3000PH and SLE78CLUFX5000PH
Firmware Versions
2.2.0

Vendor

Yubico, Inc.
530 Lytton Ave
Suite 301
n/a
Palo Alto, CA 94301
USA

Jakob Ehrensvard
jakob@yubico.com
Phone: +1 650-283-1537
Fax: n/a
n/a
n/a
Phone: n/a
Fax: n/a

Validation History

Date Type Lab
5/3/2021 Initial ACUMEN SECURITY, LLC