GIVE FEEDBACK

Generating Print Page

Yubico YubiHSM 2 FIPS - USB-A FIPS 140-2 Validated - v2.2 - 5060408464557

PB Tech price
PB Tech price
$ 1,886 .96
 +GST
$ 2,170 .00
 inc GST

Out of stock

Yubico YubiHSM 2 FIPS - USB-A FIPS 140-2 Validated - v2.2 - 5060408464557

  • Brand: Yubico
  • MPN: 5060408464557
  • Part #: MEMYBC0396
  • UPC:
PB Tech price
$ 1,886 .96 $ 2,170 .00
 +GST  inc GST

No store stock available.

Click & Collect: Collect unavailable
Delivery: Out of stock
  • Brand: Yubico
  • MPN: 5060408464557
  • Part #: MEMYBC0396
  • UPC:

Features

https://www.yubico.com/nz/product/yubihsm-2-fips/

The YubiHSM 2 FIPS enables organizations of all sizes to enhance cryptographic key security throughout the entire lifecycle, reduce risk and ensure adherence with compliance regulations. With the YubiHSM 2 SDK available as open source, organizations can easily and rapidly integrate support for the secure YubiHSM 2 FIPS into a wide range of platforms and systems for existing and emerging use cases where strong security is more critical than ever before

  • High quality - Built to last. IP68 rated (water and dust resistant), crush resistant, no batteries required, no moving parts.
  • Rapid Integration, Easy Management  - Custom application support using open source libraries. Interfaces via YubiHSM KSP, PKCS#11, and native libraries.
  • Form-factor - "Nano" for discrete in-port retention. USB-A connector for standard 1.0, 2.0 and 3.0 ports. Designed for low-power usage.
  • Securely manufactured - From component sourcing through manufacturing, Yubico ensures the highest levels of security. Made in the USA & Sweden.
  • NIST Certification - FIPS 140-2 validated (Overall Level 2, Physical Security Level 3.)

Exclusions under change of mind returns

Yubico only takes returns & replacements for faulty keys.

For security reasons, Yubico won't accept returns for change of mind returns.

Please choose carefully when purchasing Yubico

Specifications

Windows, Linux, macOS

Linux 
CentOS 7
Debian 8
Debian 9
Debian 10
Fedora 28
Fedora 30
Fedora 31
Ubuntu 1404
Ubuntu 1604
Ubuntu 1804
Ubuntu 1810
Ubuntu 1904
Ubuntu 1910

Windows 

Windows 10
Windows Server 2012
Windows Server 2016
Windows Server 2019

macOS 

10.12 Sierra
10.13 High Sierra
10.14 Mojave

Cryptographic interfaces (APIs)

Microsoft CNG (KSP)
PKCS#11 (Windows, Linux, macOS)
Native YubiHSM Core Libraries (C, python)

Cryptographic capabilities

Hashing (used with HMAC and asymmetric signatures)
SHA-1, SHA-256, SHA-384, SHA-512

RSA

2048, 3072, and 4096 bit keys
Signing using PKCS#1v1.5 and PSS
Decryption using PKCS#1v1.5 and OAEP

Elliptic Curve Cryptography (ECC)

Curves: secp224r1, secp256r1, secp256k1, secp384r1, secp521r, bp256r1, bp384r1, bp512r1, curve25519
Signing: ECDSA (all except curve25519), EdDSA (curve25519 only)
Decryption: ECDH (all except curve25519)

Key wrap

Import and export using NIST AES-CCM Wrap at 128, 196, and 256 bits

Random numbers

On-chip True Random Number Generator (TRNG) used to seed NIST SP 800-90 AES 256 CTR_DRBG

Attestation

Asymmetric key pairs generated on-device may be attested using a factory certified attestation key and certificate, or using your own key and certificate imported into the HSM

Performance

Performance varies depending on usage. The accompanying Software Development Kit includes performance tools that can be used for additional measurements. Example metrics from an otherwise unoccupied YubiHSM 2
RSA-2048-PKCS1-SHA256: ~139ms avg
RSA-3072-PKCS1-SHA384: ~504ms avg
RSA-4096-PKCS1-SHA512: ~852ms avg
ECDSA-P256-SHA256: ~73ms avg
ECDSA-P384-SHA384: ~120ms avg
ECDSA-P521-SHA512: ~210ms avg
EdDSA-25519-32Bytes: ~105ms avg
EdDSA-25519-64Bytes: ~121ms avg
EdDSA-25519-128Bytes: ~137ms avg
EdDSA-25519-256Bytes: ~168ms avg
EdDSA-25519-512Bytes: ~229ms avg
EdDSA-25519-1024Bytes: ~353ms avg
AES-(128|192|256)-CCM-Wrap: ~10ms avg
HMAC-SHA-(1|256): ~4ms avg
HMAC-SHA-(384|512): ~243ms avg

Storage capacity

All data stored as objects. 256 object slots, 128KB (base 10) max total
Stores up to 127 rsa2048, 93 rsa3072, 68 rsa4096 or 255 of any elliptic curve type, assuming only one authentication key is present
Object types: Authentication keys (used to establish sessions); asymmetric private keys; opaque binary data objects, e.g. x509 certs; wrap keys; HMAC keys

Management

Mutual authentication and secure channel between applications and HSM
M of N unwrap key restore via YubiHSM Setup Tool

Software Development Kit

A Software Development Kit for YubiHSM 2 is available for download on Yubico.com and includes:
YubiHSM Core Library (libyubihsm) for C, Python
YubiHSM Shell (Configuration CLI)
PKCS#11 Module
YubiKey Key Storage Provider (KSP) for use with Microsoft
YubiHSM Connector
YubiHSM Setup Tool
Documentation and code examples

Form factor

'nano' designed for confined spaces such as internal USB ports in servers

Dimensions

12mm x 13mm x 3.1mm

Weight

1 gram

Current requirements

20mA avg, 30mA max

Safety and environmental compliance

FCC
CE
WEEE
ROHS

Host interface

Universal Serial Bus (USB) 1.x Full Speed (12Mbit/s) Peripheral with bulk interface.

Manufacturer Part No:
5060408464557
Brand:
Yubico
Product Type:
-
UPC
-
Product Family:
YubiHSM
Shipping Weight:
1.01 kg
PB Part No:
MEMYBC0396
Product Model:
2
Warranty: 12 months *
* Warranty period is as stated above unless the manufacturer has chosen to specify a longer period.
All warranties are return to base unless otherwise specified.

Reviews

There are currently no reviews for this product

Do you own this product?

Write a review and go into the monthly draw Win A $100 PB Tech Gift Card!

Delivery & Pick-up

Potential courier delays: Please note that due to the high volumes currently within the NZ courier network there is potential for some deliveries to be delayed.

Delivery Estimates

The estimated time to ship for each product we sell is detailed on the individual product page just underneath the price. From when your items ship, products typically arrive within 1-2 working days for North Island deliveries and 2-3 working days for South Island deliveries. Rural deliveries may take an extra working day. Bulk & hazard deliveries may take an extra 2-4 working days.

Next Day Delivery

Need your order in a hurry? PB Tech offers next day delivery for local Auckland addresses. Simple place your order before 4pm (provided your items are in stock) and select our next day delivery option in the checkout. T&C's apply. Learn more about Next Day Delivery.

Same Day Delivery

Need your order in a hurry? PB Tech offers same day delivery for Auckland, Hamilton, Wellington and Christchurch. Simple place your order before 1pm (provided your items are in stock) and select one of our same day delivery options 'Evening Delivery' or 'Urgent 3-hour Delivery' in the checkout. T&C's apply. Learn more about Same Day Delivery.

Shipping Costs

Shipping costs vary based on your location and the items being shipped and in some cases shipping may even be FREE.

To calculate what the shipping costs will be for your order, add the items you are interested in to your cart, view the Shopping Cart page, and select your 'Delivery Area' to calculate the shipping cost.

Shipping Security & Insurance

All orders shipped by PB Tech are sent via a courier with a signature required for each delivery. In some cases, and only where you have given the courier company permission to leave orders at a designated location, your order may be delivered without requiring a signature. All orders sent by PB Tech are fully insured in the unlikely event that your item(s) are damaged or go missing in transit.

1 Hour Store Pick-up / Click & Collect

You can pick-up your online order from any of our stores nationwide. You can select which store you want to pick up from at the checkout. Provided the store you select has stock and there's no hold-ups with payment we will have your order ready within 1 hour (during normal trading hours for that store) otherwise it may take up to 5 working days to transfer the stock to the store so your order can be fulfilled. Learn more about our Click & Collect process.

Overseas Shipments

PB Tech regularly ships overseas to Australia and beyond. If you are located in Australia, you can order directly from our Australian site www.pbtech.com/au. If you are from another country you can order from www.pbtech.com

Returns & Warranty

7 day right of exchange

If you change your mind after making a purchase, or realise you have ordered the incorrect item, you can enjoy the peace of mind that we offer a 7 day exchange policy.

To exchange a product, goods must be sealed and unopened, with packaging in original condition, accompanied by a valid receipt dated no more than 7 calendar days from when you request an exchange. A 20% restocking fee may be applied where goods are not returned in sealed, original packaging condition.

If there is not a suitable product that can be exchanged for your returned item you will be offered a credit on your account or gift card based on the value paid at the time of purchase. Items purchased on finance cannot be exchanged for a gift card.

 

Hassle free warranty service

If your product develops a fault within the manufacturer warranty period, you can either contact the manufacturer directly (some manufacturers provide a high level of warranty service - including free pickup or in some cases onsite repair), or return to one of our services centres / stores. Where the product has been directly imported by PB Tech, you need to contact us directly or present the product at any one of our service centres / stores together with your proof of purchase.

If your product develops a fault outside of the manufacturer warranty or PB Tech warranty period, we offer a full repair service and are an authorised repair agent for leading brands such as Samsung, HP, Toshiba, Lenovo and more.

 

Returning a product / making a warranty claim

To contact the manufacturer directly to troubleshoot your product or to request a warranty repair, please view the list of manufacturer / brand warranty contacts (for products imported directly by PB Tech please return to us directly by completing our request a return form).

To return a product to PB Tech directly, please complete our request a return form.

Or view our returns policy for more information.

Yubico YubiHSM 2 FIPS - USB-A FIPS 140-2 Validated - v2.2 - 5060408464557

  • Brand: Yubico
  • MPN: 5060408464557
  • Part #: MEMYBC0396
PB Tech price $1,886.96 Excluding GST PB Tech price $2,170.00 Including GST

Date Created: 07:06, 14-09-2025
Product URL: https://www.pbtech.co.nz/product/MEMYBC0396/Yubico-YubiHSM-2-FIPS---USB-A-FIPS-140-2-Validated
Branch New Stock On Display
Auckland - Albany 0
Auckland - Glenfield 0
Auckland - Queen Street 0
Auckland - Auckland Uni 0
Auckland - Newmarket 0
Auckland - Westgate 0
Auckland - Penrose 0
Auckland - Henderson (Express) 0
Auckland - St Lukes 0
Auckland - Manukau 0
Hamilton 0
Tauranga 0
New Plymouth 0
Palmerston North 0
Petone 0
Wellington 0
Auckland - Head Office 0
Auckland - East Tamaki Warehouse 0
Christchurch - Hornby 0
Christchurch - Christchurch Central 0
Dunedin 0

Features

https://www.yubico.com/nz/product/yubihsm-2-fips/

The YubiHSM 2 FIPS enables organizations of all sizes to enhance cryptographic key security throughout the entire lifecycle, reduce risk and ensure adherence with compliance regulations. With the YubiHSM 2 SDK available as open source, organizations can easily and rapidly integrate support for the secure YubiHSM 2 FIPS into a wide range of platforms and systems for existing and emerging use cases where strong security is more critical than ever before

  • High quality - Built to last. IP68 rated (water and dust resistant), crush resistant, no batteries required, no moving parts.
  • Rapid Integration, Easy Management  - Custom application support using open source libraries. Interfaces via YubiHSM KSP, PKCS#11, and native libraries.
  • Form-factor - "Nano" for discrete in-port retention. USB-A connector for standard 1.0, 2.0 and 3.0 ports. Designed for low-power usage.
  • Securely manufactured - From component sourcing through manufacturing, Yubico ensures the highest levels of security. Made in the USA & Sweden.
  • NIST Certification - FIPS 140-2 validated (Overall Level 2, Physical Security Level 3.)

Exclusions under change of mind returns

Yubico only takes returns & replacements for faulty keys.

For security reasons, Yubico won't accept returns for change of mind returns.

Please choose carefully when purchasing Yubico

Specifications

Windows, Linux, macOS

Linux 
CentOS 7
Debian 8
Debian 9
Debian 10
Fedora 28
Fedora 30
Fedora 31
Ubuntu 1404
Ubuntu 1604
Ubuntu 1804
Ubuntu 1810
Ubuntu 1904
Ubuntu 1910

Windows 

Windows 10
Windows Server 2012
Windows Server 2016
Windows Server 2019

macOS 

10.12 Sierra
10.13 High Sierra
10.14 Mojave

Cryptographic interfaces (APIs)

Microsoft CNG (KSP)
PKCS#11 (Windows, Linux, macOS)
Native YubiHSM Core Libraries (C, python)

Cryptographic capabilities

Hashing (used with HMAC and asymmetric signatures)
SHA-1, SHA-256, SHA-384, SHA-512

RSA

2048, 3072, and 4096 bit keys
Signing using PKCS#1v1.5 and PSS
Decryption using PKCS#1v1.5 and OAEP

Elliptic Curve Cryptography (ECC)

Curves: secp224r1, secp256r1, secp256k1, secp384r1, secp521r, bp256r1, bp384r1, bp512r1, curve25519
Signing: ECDSA (all except curve25519), EdDSA (curve25519 only)
Decryption: ECDH (all except curve25519)

Key wrap

Import and export using NIST AES-CCM Wrap at 128, 196, and 256 bits

Random numbers

On-chip True Random Number Generator (TRNG) used to seed NIST SP 800-90 AES 256 CTR_DRBG

Attestation

Asymmetric key pairs generated on-device may be attested using a factory certified attestation key and certificate, or using your own key and certificate imported into the HSM

Performance

Performance varies depending on usage. The accompanying Software Development Kit includes performance tools that can be used for additional measurements. Example metrics from an otherwise unoccupied YubiHSM 2
RSA-2048-PKCS1-SHA256: ~139ms avg
RSA-3072-PKCS1-SHA384: ~504ms avg
RSA-4096-PKCS1-SHA512: ~852ms avg
ECDSA-P256-SHA256: ~73ms avg
ECDSA-P384-SHA384: ~120ms avg
ECDSA-P521-SHA512: ~210ms avg
EdDSA-25519-32Bytes: ~105ms avg
EdDSA-25519-64Bytes: ~121ms avg
EdDSA-25519-128Bytes: ~137ms avg
EdDSA-25519-256Bytes: ~168ms avg
EdDSA-25519-512Bytes: ~229ms avg
EdDSA-25519-1024Bytes: ~353ms avg
AES-(128|192|256)-CCM-Wrap: ~10ms avg
HMAC-SHA-(1|256): ~4ms avg
HMAC-SHA-(384|512): ~243ms avg

Storage capacity

All data stored as objects. 256 object slots, 128KB (base 10) max total
Stores up to 127 rsa2048, 93 rsa3072, 68 rsa4096 or 255 of any elliptic curve type, assuming only one authentication key is present
Object types: Authentication keys (used to establish sessions); asymmetric private keys; opaque binary data objects, e.g. x509 certs; wrap keys; HMAC keys

Management

Mutual authentication and secure channel between applications and HSM
M of N unwrap key restore via YubiHSM Setup Tool

Software Development Kit

A Software Development Kit for YubiHSM 2 is available for download on Yubico.com and includes:
YubiHSM Core Library (libyubihsm) for C, Python
YubiHSM Shell (Configuration CLI)
PKCS#11 Module
YubiKey Key Storage Provider (KSP) for use with Microsoft
YubiHSM Connector
YubiHSM Setup Tool
Documentation and code examples

Form factor

'nano' designed for confined spaces such as internal USB ports in servers

Dimensions

12mm x 13mm x 3.1mm

Weight

1 gram

Current requirements

20mA avg, 30mA max

Safety and environmental compliance

FCC
CE
WEEE
ROHS

Host interface

Universal Serial Bus (USB) 1.x Full Speed (12Mbit/s) Peripheral with bulk interface.

Date Created: 07:06, 14-09-2025
Product URL: https://www.pbtech.co.nz/product/MEMYBC0396/Yubico-YubiHSM-2-FIPS---USB-A-FIPS-140-2-Validated