[Cscwg-public] FIPS token supporting RSA 3072

Tomas Gustavsson tomas.gustavsson at primekey.com
Thu Jan 14 17:52:25 UTC 2021


Hi,

I think I found, memory is bad since before holidays, the token I looked
at then.

The YubiKey FIPS token is a bit strange:
https://www.yubico.com/products/yubikey-fips/
Here it says RSA 2048,

but here
https://support.yubico.com/hc/en-us/articles/360013729079--YubiKey-C-FIPS

It says RSA3072 and 4096 with the OpenPGP module.

The FIPS certificate gives some technical details on HW and firmware...
https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/details?source=RSA&number=2569

https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/details?source=RSA&number=2569

"SLE78CLUFX3000PH e58230b8 with Infineon CL70 1.03.006" is probably a
very common chip to use, then it's the token vendor that has to to the
FIPS validation of course...

Still a bit confusing on the 3072 bit.

Regards,
Tomas



More information about the Cscwg-public mailing list