{"id":62967,"date":"2023-08-17T20:57:25","date_gmt":"2023-08-17T17:57:25","guid":{"rendered":"https:\/\/lwallet.com.ua\/product\/yubihsm-2-v2-4\/"},"modified":"2026-04-23T22:05:03","modified_gmt":"2026-04-23T19:05:03","slug":"yubihsm-2-v2-4","status":"publish","type":"product","link":"https:\/\/lwallet.com.ua\/en\/product\/yubihsm-2-v2-4\/","title":{"rendered":"YubiHSM 2 v2.4"},"content":{"rendered":"<div class=\"wpb-content-wrapper\"><p>[vc_row][vc_column][vc_tta_tabs][vc_tta_section title=&#8221;About the device&#8221; tab_id=&#8221;1707917980236-790c717f-399e&#8221;][vc_row_inner][vc_column_inner css=&#8221;.vc_custom_1769167770222{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<h4 style=\"text-align: center;\">YubiHSM 2 v2.4<\/h4>\n<p>[\/vc_column_text][vc_column_text css=&#8221;&#8221;]<\/p>\n<div style=\"position: relative; margin: 0 auto; padding: 0; max-width: 1100px; text-align: center;\"><img decoding=\"async\" style=\"display: inline-block; width: 100%; max-width: 1100px; height: auto; border-radius: 40px;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/02\/yubi-hsm-2-v2.4-content-pic1.jpg\" alt=\"YubiHSM 2 v2.4 Main Header Image\" title=\"\"><\/div>\n<p>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_row_inner][vc_column_inner width=&#8221;1\/2&#8243; css=&#8221;.vc_custom_1769164336940{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<h4 data-start=\"93\" data-end=\"118\">What this device is for<br \/><\/h4>\n<p data-start=\"119\" data-end=\"348\">YubiHSM 2 is a USB-based HSM for companies where cryptographic keys cannot simply be stored on a server: PKI, certificate authorities, certificate signing, code signing, service encryption. It is purchased to avoid relying solely on software and OS-level permissions. The device acts as a hardware root of trust for signing and encryption operations within infrastructure.  <\/p>\n<p>[\/vc_column_text][vc_column_text css=&#8221;&#8221;]<\/p>\n<div style=\"position: relative; max-width: 720px; margin: 0 auto; aspect-ratio: 1 \/ 1; border-radius: 28px; overflow: visible;\">\n<div style=\"width: 100%; height: 100%; border-radius: 28px; overflow: hidden;\"><img decoding=\"async\" style=\"width: 100%; height: 100%; object-fit: cover; display: block;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/02\/yubi-hsm-2-v2.4-content-pic2.jpg\" alt=\"YubiHSM 2 v2.4 standing on desk\" title=\"\"><\/div>\n<\/div>\n<p>[\/vc_column_text][\/vc_column_inner][vc_column_inner width=&#8221;1\/2&#8243; css=&#8221;.vc_custom_1769164340795{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<h4 data-start=\"373\" data-end=\"412\">Isolated cryptographic keys<br \/><\/h4>\n<p data-start=\"413\" data-end=\"720\">Cryptographic keys can be generated, imported, and stored directly inside the YubiHSM 2, and all operations are executed within the device. This reduces the risk of key theft both during server attacks (malware, vulnerability exploitation) and in case of physical server compromise. The server receives only the result of the operation (signature\/encryption), not the key material itself. <\/p>\n<p>[\/vc_column_text][vc_column_text css=&#8221;&#8221;]<\/p>\n<div style=\"position: relative; max-width: 720px; margin: 0 auto; aspect-ratio: 1 \/ 1; border-radius: 28px; overflow: visible;\">\n<div style=\"width: 100%; height: 100%; border-radius: 28px; overflow: hidden;\"><img decoding=\"async\" style=\"width: 100%; height: 100%; object-fit: cover; display: block;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/02\/yubi-hsm-2-v2.4-content-pic3.jpg\" alt=\"YubiHSM 2 v2.4 plugging in in usb port\" title=\"\"><\/div>\n<\/div>\n<p>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_row_inner][vc_column_inner css=&#8221;.vc_custom_1769167770222{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<h4 data-start=\"727\" data-end=\"774\">Cryptography that prod relies on<\/h4>\n<p data-start=\"775\" data-end=\"1113\">YubiHSM 2 supports operations required in enterprise scenarios: hashing, key wrapping, asymmetric signing and decryption, including advanced signing scenarios with ed25519. It also supports attestation for asymmetric key pairs generated on the device. <\/p>\n<p>[\/vc_column_text][vc_column_text css=&#8221;&#8221;]<\/p>\n<div style=\"position: relative; margin: 0 auto; padding: 0; max-width: 1100px; text-align: center;\"><img decoding=\"async\" style=\"display: inline-block; width: 100%; max-width: 1100px; height: auto; border-radius: 40px;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/02\/yubi-hsm-2-v2.4-content-pic4.jpg\" alt=\"YubiHSM 2 v2.4 laying on desk with people in modenr office on background\" title=\"\"><\/div>\n<p>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_row_inner][vc_column_inner width=&#8221;1\/2&#8243; css=&#8221;.vc_custom_1769164336940{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<h4 data-start=\"1120\" data-end=\"1171\">Access control by roles and domains<br \/><\/h4>\n<p data-start=\"1172\" data-end=\"1637\">Inside the device there are security domains: keys and objects belong to domains, and permissions are assigned per authentication key \u2014 you can define \u201cwho signs\u201d, \u201cwho administers\u201d, and \u201cwho reads audit logs\u201d. <br data-start=\"1413\" data-end=\"1416\">Additionally, there is a tamper-evident audit log: event logs can be exported for monitoring and reporting, making any changes visible.<\/p>\n<p>[\/vc_column_text][vc_column_text css=&#8221;&#8221;]<\/p>\n<div style=\"position: relative; max-width: 720px; margin: 0 auto; aspect-ratio: 1 \/ 1; border-radius: 28px; overflow: visible;\">\n<div style=\"width: 100%; height: 100%; border-radius: 28px; overflow: hidden;\"><img decoding=\"async\" style=\"width: 100%; height: 100%; object-fit: cover; display: block;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/02\/yubi-hsm-2-v2.4-content-pic5.jpg\" alt=\"YubiHSM 2 v2.4 laying on desk behind monitors\" title=\"\"><\/div>\n<\/div>\n<p>[\/vc_column_text][\/vc_column_inner][vc_column_inner width=&#8221;1\/2&#8243; css=&#8221;.vc_custom_1769164340795{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<h4 data-start=\"1644\" data-end=\"1708\">Integrations and connectivity<br \/><\/h4>\n<p data-start=\"1709\" data-end=\"2092\">YubiHSM 2 is designed for large infrastructures: up to 16 concurrent connections, with options to make the HSM accessible to multiple systems (including virtual machines). Integration is built through standard interfaces: PKCS#11, YubiHSM KSP for Microsoft CNG, as well as native libraries for Windows\/Linux\/macOS. All of this works without custom workarounds.  <\/p>\n<p>[\/vc_column_text][vc_column_text css=&#8221;&#8221;]<\/p>\n<div style=\"position: relative; max-width: 720px; margin: 0 auto; aspect-ratio: 1 \/ 1; border-radius: 28px; overflow: visible;\">\n<div style=\"width: 100%; height: 100%; border-radius: 28px; overflow: hidden;\"><img decoding=\"async\" style=\"width: 100%; height: 100%; object-fit: cover; display: block;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/02\/yubi-hsm-2-v2.4-content-pic6.jpg\" alt=\"YubiHSM 2 v2.4 server room with screens\" title=\"\"><\/div>\n<\/div>\n<p>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_row_inner][vc_column_inner css=&#8221;.vc_custom_1769114775347{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<h4 data-start=\"1171\" data-end=\"1224\">Crypto Library Update<br \/><\/h4>\n<p data-start=\"1225\" data-end=\"1462\">In firmware v2.4, the cryptographic library for RSA and ECC operations (including signing and decryption) has been updated. This is Yubico\u2019s internal implementation, the same library used in the YubiKey 5.7 release.<\/p>\n<p>[\/vc_column_text][vc_column_text css=&#8221;&#8221;]<\/p>\n<div style=\"position: relative; margin: 0 auto; padding: 0; max-width: 1100px; text-align: center;\"><img decoding=\"async\" style=\"display: inline-block; width: 100%; max-width: 1100px; height: auto; border-radius: 40px;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/03\/yubi-hsm-2-v2.4-content-pic12.jpg\" alt=\"YubiHSM 2 v2.4 behind laptop on desk\" title=\"\"><\/div>\n<p>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_row_inner][vc_column_inner width=&#8221;1\/2&#8243; css=&#8221;.vc_custom_1769164336940{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<h4 data-start=\"474\" data-end=\"531\">Backup and key transfer using M-of-N rule<br \/><\/h4>\n<p data-start=\"532\" data-end=\"854\">YubiHSM 2 supports an M-of-N rule for wrap keys: restoring a key on another HSM requires participation from multiple administrators (a quorum), not just a single backup owner.<\/p>\n<p>[\/vc_column_text][vc_column_text css=&#8221;&#8221;]<\/p>\n<div style=\"position: relative; max-width: 720px; margin: 0 auto; aspect-ratio: 1 \/ 1; border-radius: 28px; overflow: visible;\">\n<div style=\"width: 100%; height: 100%; border-radius: 28px; overflow: hidden;\"><img decoding=\"async\" style=\"width: 100%; height: 100%; object-fit: cover; display: block;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/03\/yubi-hsm-2-v2.4-content-pic10.jpg\" alt=\"YubiHSM 2 v2.4 documents with laptop on desk\" title=\"\"><\/div>\n<\/div>\n<p>[\/vc_column_text][\/vc_column_inner][vc_column_inner width=&#8221;1\/2&#8243; css=&#8221;.vc_custom_1769164340795{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<h4 data-start=\"861\" data-end=\"912\">Audit Logging<br \/><\/h4>\n<p data-start=\"913\" data-end=\"1164\">YubiHSM 2 maintains an internal log of administrative and operational events. The log can be exported for monitoring and reporting, and entries are linked via a hash chain, making any attempt to alter or delete records detectable. <\/p>\n<p>[\/vc_column_text][vc_column_text css=&#8221;&#8221;]<\/p>\n<div style=\"position: relative; max-width: 720px; margin: 0 auto; aspect-ratio: 1 \/ 1; border-radius: 28px; overflow: visible;\">\n<div style=\"width: 100%; height: 100%; border-radius: 28px; overflow: hidden;\"><img decoding=\"async\" style=\"width: 100%; height: 100%; object-fit: cover; display: block;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/03\/yubi-hsm-2-v2.4-content-pic11.jpg\" alt=\"YubiHSM 2 v2.4 monitors with documents on desk\" title=\"\"><\/div>\n<\/div>\n<p>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_row_inner][vc_column_inner css=&#8221;.vc_custom_1769114775347{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<h4>Nano form factor + what\u2019s new in v2.4<br \/><\/h4>\n<p data-start=\"1670\" data-end=\"1829\">The Nano form factor is a truly compact HSM that fits neatly into a USB-A port without interfering in a server setup.<br data-start=\"1779\" data-end=\"1782\">New in v2.4:<\/p>\n<ul data-start=\"1830\" data-end=\"2120\">\n<li data-start=\"1830\" data-end=\"1982\">\n<p data-start=\"1832\" data-end=\"1982\">Asymmetric backups \u2014 a secure and practical way to create backups using asymmetric encryption, including transfer over the internet <\/p>\n<\/li>\n<li data-start=\"1983\" data-end=\"2120\">\n<p data-start=\"1985\" data-end=\"2120\">BYOK (Bring Your Own Key) \u2014 for cloud usage scenarios, allowing storage and management of your own keys in multi-cloud environments with a focus on control and compliance <\/p>\n<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;&#8221;]<\/p>\n<div style=\"position: relative; margin: 0 auto; padding: 0; max-width: 1100px; text-align: center;\"><img decoding=\"async\" style=\"display: inline-block; width: 100%; max-width: 1100px; height: auto; border-radius: 40px;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/02\/yubi-hsm-2-v2.4-content-pic7.jpg\" alt=\"YubiHSM 2 v2.4 inserted in server\" title=\"\"><\/div>\n<p>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_row_inner][vc_column_inner width=&#8221;1\/2&#8243; css=&#8221;.vc_custom_1769164336940{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<h4 data-start=\"141\" data-end=\"199\">Secure session<br \/><\/h4>\n<p data-start=\"200\" data-end=\"467\">When working with YubiHSM 2, communication between the application and the device is performed via a secure session with mutual authentication. This reduces the risk of interception or tampering with commands and responses, especially when the HSM is used in production and accessed automatically by services. <\/p>\n<p>[\/vc_column_text][vc_column_text css=&#8221;&#8221;]<\/p>\n<div style=\"position: relative; max-width: 720px; margin: 0 auto; aspect-ratio: 1 \/ 1; border-radius: 28px; overflow: visible;\">\n<div style=\"width: 100%; height: 100%; border-radius: 28px; overflow: hidden;\"><img decoding=\"async\" style=\"width: 100%; height: 100%; object-fit: cover; display: block;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/03\/yubi-hsm-2-v2.4-content-pic13-1.jpg\" alt=\"YubiHSM 2 secure session\" title=\"\"><\/div>\n<\/div>\n<p>[\/vc_column_text][\/vc_column_inner][vc_column_inner width=&#8221;1\/2&#8243; css=&#8221;.vc_custom_1769164340795{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<h4>Additional benefit for administrators<br \/><\/h4>\n<p>For administering YubiHSM 2, you can use a <a href=\"https:\/\/lwallet.com.ua\/en\/product-category\/security-keys-en\/\">YubiKey <\/a>with the YubiHSM Auth application: the key stores the data required to establish a secure session with the HSM. This ensures that secrets are not stored in server configs or scripts \u2014 access is tied to a physical YubiKey belonging to a specific administrator.[\/vc_column_text][vc_column_text css=&#8221;&#8221;]<\/p>\n<div style=\"position: relative; max-width: 720px; margin: 0 auto; aspect-ratio: 1 \/ 1; border-radius: 28px; overflow: visible;\">\n<div style=\"width: 100%; height: 100%; border-radius: 28px; overflow: hidden;\"><img decoding=\"async\" style=\"width: 100%; height: 100%; object-fit: cover; display: block;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/03\/yubi-hsm-2-v2.4-content-pic14.jpg\" alt=\"YubiHSM 2 v2.4 laptop with Yubikey on desk\" title=\"\"><\/div>\n<\/div>\n<p>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_row_inner][vc_column_inner css=&#8221;.vc_custom_1769114775347{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<h4 data-section-id=\"1xvyton\" data-start=\"99\" data-end=\"126\">Where YubiHSM 2 is used<br \/><\/h4>\n<p data-start=\"128\" data-end=\"585\"><span class=\"BZ_Pyq_fadeIn\">YubiHSM <\/span><span class=\"BZ_Pyq_fadeIn\">2  <\/span><span class=\"BZ_Pyq_fadeIn\">is typically <\/span><span class=\"BZ_Pyq_fadeIn\">chosen <\/span><span class=\"BZ_Pyq_fadeIn\">for <\/span><span class=\"BZ_Pyq_fadeIn\">scenarios <\/span><span class=\"BZ_Pyq_fadeIn\">where <\/span><span class=\"BZ_Pyq_fadeIn\">impotrant <\/span><span class=\"BZ_Pyq_fadeIn\">hardware <\/span><span class=\"BZ_Pyq_fadeIn\">protection <\/span><span class=\"BZ_Pyq_fadeIn\">of cryptographic <\/span><span class=\"BZ_Pyq_fadeIn\">keys<\/span> <span class=\"BZ_Pyq_fadeIn\">and <\/span><span class=\"BZ_Pyq_fadeIn\">secure <\/span><span class=\"BZ_Pyq_fadeIn\">execution <\/span><span class=\"BZ_Pyq_fadeIn\">of critical <\/span><span class=\"BZ_Pyq_fadeIn\">operations are required. <\/span><span class=\"BZ_Pyq_fadeIn\">Most <\/span><span class=\"BZ_Pyq_fadeIn\">often <\/span><span class=\"BZ_Pyq_fadeIn\">it <\/span><span class=\"BZ_Pyq_fadeIn\">is used <\/span><span class=\"BZ_Pyq_fadeIn\">for <\/span><span class=\"BZ_Pyq_fadeIn\">the protection <\/span><span class=\"BZ_Pyq_fadeIn\">of key <\/span><span class=\"BZ_Pyq_fadeIn\">infrastructure <\/span><span class=\"BZ_Pyq_fadeIn\">PKI\/<\/span><span class=\"BZ_Pyq_fadeIn\">CA<\/span><span class=\"BZ_Pyq_fadeIn\">,  <\/span><span class=\"BZ_Pyq_fadeIn\">integration <\/span><span class=\"BZ_Pyq_fadeIn\">with <\/span><span class=\"BZ_Pyq_fadeIn\">systems <\/span><span class=\"BZ_Pyq_fadeIn\">via <\/span><span class=\"BZ_Pyq_fadeIn\">PKCS#<\/span><span class=\"BZ_Pyq_fadeIn\">11<\/span> <span class=\"BZ_Pyq_fadeIn\">and <\/span><span class=\"BZ_Pyq_fadeIn\">other <\/span><span class=\"BZ_Pyq_fadeIn\">standard <\/span><span class=\"BZ_Pyq_fadeIn\">interfaces, <\/span><span class=\"BZ_Pyq_fadeIn\">working <\/span><span class=\"BZ_Pyq_fadeIn\">with <\/span><span class=\"BZ_Pyq_fadeIn\">Microsoft <\/span><span class=\"BZ_Pyq_fadeIn\">AD <\/span><span class=\"BZ_Pyq_fadeIn\">CS<\/span><span class=\"BZ_Pyq_fadeIn\">,  <\/span><span class=\"BZ_Pyq_fadeIn\">enhancing <\/span><span class=\"BZ_Pyq_fadeIn\">security <\/span><span class=\"BZ_Pyq_fadeIn\">in <\/span><span class=\"BZ_Pyq_fadeIn\">cryptocurrency exchanges <\/span><span class=\"BZ_Pyq_fadeIn\">and <\/span><span class=\"BZ_Pyq_fadeIn\">fintech-<\/span><span class=\"BZ_Pyq_fadeIn\">services<\/span><span class=\"BZ_Pyq_fadeIn\">,  <\/span><span class=\"BZ_Pyq_fadeIn\">and <\/span><span class=\"BZ_Pyq_fadeIn\">also <\/span><span class=\"BZ_Pyq_fadeIn\">for <\/span><span class=\"BZ_Pyq_fadeIn\">the protection <\/span><span class=\"BZ_Pyq_fadeIn\">of keys <\/span><span class=\"BZ_Pyq_fadeIn\">in <\/span><span class=\"BZ_Pyq_fadeIn\">IoT-<\/span><span class=\"BZ_Pyq_fadeIn\">infrastructure<\/span> <span class=\"BZ_Pyq_fadeIn\">and <\/span><span class=\"BZ_Pyq_fadeIn\">related <\/span><span class=\"BZ_Pyq_fadeIn\">with <\/span><span class=\"BZ_Pyq_fadeIn\">it&#8217;s <\/span><span class=\"BZ_Pyq_fadeIn\">devices<\/span><\/p>\n<p>[\/vc_column_text][vc_column_text css=&#8221;&#8221;]<\/p>\n<div style=\"position: relative; margin: 0 auto; padding: 0; max-width: 1100px; text-align: center;\"><img decoding=\"async\" style=\"display: inline-block; width: 100%; max-width: 1100px; height: auto; border-radius: 40px;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/03\/yubi-hsm-2-v2.4-content-pic15.jpg\" alt=\"YubiHSM 2 v2.4 laptop and monitor on desk\" title=\"\"><\/div>\n<p>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_tta_section][vc_tta_section title=&#8221;Device review&#8221; tab_id=&#8221;1769114549065-f23b61ba-a31a&#8221;][vc_row_inner][vc_column_inner css=&#8221;.vc_custom_1769164346070{padding-bottom: 25px !important;}&#8221;][vc_video link=&#8221;https:\/\/www.youtube.com\/watch?v=3Im_vFty58E&amp;t&#8221;][\/vc_column_inner][\/vc_row_inner][\/vc_tta_section][vc_tta_section title=&#8221;Technical Specifications&#8221; tab_id=&#8221;1769114566682-d4a13717-dd76&#8243;][vc_row_inner][vc_column_inner width=&#8221;1\/2&#8243; css=&#8221;.vc_custom_1769164351525{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<div class=\"flex-shrink-0 flex flex-col relative items-end\">\n<div class=\"pt-0\">\n<div class=\"gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full\">\n<h5>Security features<\/h5>\n<p>Hardware protection of private keys for PKI\/CA, signing and encryption (generation, import, storage, and usage inside the HSM)<br \/>\nAttestation for asymmetric key pairs generated on the device<br \/>\nSecure session between application and HSM (integrity\/confidentiality protection with mutual authentication)<br \/>\nSecurity domains + permissions at the authentication key level (separation of roles: signing \/ admin \/ audit)<br \/>\nTamper-evident audit log<br \/>\nNew in v2.4: asymmetric backups and BYOK for multi-cloud<\/p>\n<h5 data-start=\"989\" data-end=\"1019\">Interfaces and compatibility<br \/><\/h5>\n<p data-start=\"1022\" data-end=\"1085\">Microsoft CNG (KSP)<br \/>\nPKCS#11 (Windows \/ Linux \/ macOS)<br \/>\nNative YubiHSM Core Libraries (C, Python)<\/p>\n<h5 data-start=\"1260\" data-end=\"1293\">Cryptographic capabilities<br \/><\/h5>\n<p data-start=\"1296\" data-end=\"1388\">Hashing: SHA-1 \/ SHA-256 \/ SHA-384 \/ SHA-512<br \/>\nRSA: 2048 \/ 3072 \/ 4096, signing PKCS#1 v1.5 \/ PSS, decryption PKCS#1 v1.5 \/ OAEP<br \/>\nECC: curves secp224r1, secp256r1, secp256k1, secp384r1, secp521r1, bp256r1, bp384r1, bp512r1, curve25519; ECDSA\/EdDSA signing, ECDH key exchange<br \/>\nKey wrap: NIST AES-CCM Wrap (128\/192\/256)<br \/>\nRandom number generation: TRNG, DRBG per NIST SP 800-90 (AES-256 CTR_DRBG)<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p>[\/vc_column_text][\/vc_column_inner][vc_column_inner width=&#8221;1\/2&#8243; css=&#8221;.vc_custom_1769164471230{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<div style=\"position: relative; max-width: 720px; margin: 0 auto; aspect-ratio: 1 \/ 1; border-radius: 28px; overflow: visible;\">\n<div style=\"width: 100%; height: 100%; border-radius: 28px; overflow: hidden;\"><img decoding=\"async\" style=\"width: 100%; height: 100%; object-fit: cover; display: block;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/02\/yubi-hsm-2-v2.4-content-pic9.jpg\" alt=\"YubiHSM 2 v2.4 technical specification\" title=\"\"><\/div>\n<\/div>\n<p>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_tta_section][vc_tta_section title=&#8221;What&apos;s in the box?&#8221; tab_id=&#8221;1707917980247-2e585dac-367a&#8221;][vc_row_inner][vc_column_inner width=&#8221;1\/2&#8243; css=&#8221;.vc_custom_1769164462447{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]1\u00d7 YubiHSM 2 v2.4 security key[\/vc_column_text][\/vc_column_inner][vc_column_inner width=&#8221;1\/2&#8243; css=&#8221;.vc_custom_1769164467483{padding-bottom: 25px !important;}&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<div style=\"position: relative; max-width: 720px; margin: 0 auto; aspect-ratio: 1 \/ 1; border-radius: 28px; overflow: visible;\">\n<div style=\"width: 100%; height: 100%; border-radius: 28px; overflow: hidden;\"><img decoding=\"async\" style=\"width: 100%; height: 100%; object-fit: cover; display: block;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/02\/yubi-hsm-2-v2.4-content-pic8.jpg\" alt=\"YubiHSM 2 v2.4 in the box\" title=\"\"><\/div>\n<\/div>\n<p>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_tta_section][\/vc_tta_tabs][\/vc_column][\/vc_row][vc_row css=&#8221;.vc_custom_1568251269070{padding-top: 25px !important;padding-bottom: 25px !important;}&#8221;][vc_column css=&#8221;.vc_custom_1568245102508{padding-top: 25px !important;padding-bottom: 25px !important;}&#8221;][vc_separator title=&#8221;FAQ&#8221;][\/vc_column][vc_column][vc_tta_accordion][vc_tta_section title=&#8221;What is YubiHSM 2 and what is it used for?<br \/>&#8221; tab_id=&#8221;1772032509084-a0732ee2-bc21&#8243;][vc_column_text css=&#8221;&#8221;]It is a hardware security module (HSM) in USB-A form factor. Its purpose is simple: securely store cryptographic keys and perform operations required by server infrastructure. The most common use cases are PKI\/CA, certificate issuance and signing, code signing, and encryption keys for services.[\/vc_column_text][\/vc_tta_section][vc_tta_section title=&#8221;Is it the same as a YubiKey? Can it be used for 2FA?<br \/> &#8221; tab_id=&#8221;1772032839309-ecc56765-eb9a&#8221;][vc_column_text css=&#8221;&#8221;]No. YubiHSM 2 is designed for server-side data and infrastructure (PKI\/signing\/encryption). A standard YubiKey is used for user authentication (FIDO2, etc.).[\/vc_column_text][\/vc_tta_section][vc_tta_section title=&#8221;What \u201ckeys\u201d does it protect?<br \/>&#8221; tab_id=&#8221;1772032570440-8b82e426-083b&#8221;][vc_column_text css=&#8221;&#8221;]<\/p>\n<p data-start=\"438\" data-end=\"530\">Primarily private keys that must not be lost or copied:<\/p>\n<ul data-start=\"531\" data-end=\"821\">\n<li data-start=\"531\" data-end=\"569\">\n<p data-start=\"533\" data-end=\"569\">Root\/Intermediate CA keys for PKI<\/p>\n<\/li>\n<li data-start=\"570\" data-end=\"592\">\n<p data-start=\"572\" data-end=\"592\">Code signing keys<\/p>\n<\/li>\n<li data-start=\"593\" data-end=\"821\">\n<p data-start=\"595\" data-end=\"821\">Keys used by services to sign\/decrypt data<br \/><br data-start=\"652\" data-end=\"655\">YubiHSM 2 supports the full lifecycle: generation, storage, usage, backup, and, if needed, destruction.<\/p>\n<\/li>\n<\/ul>\n<p>[\/vc_column_text][\/vc_tta_section][vc_tta_section title=&#8221;Is it suitable for Microsoft AD CS and enterprise PKI?<br \/>&#8221; tab_id=&#8221;1772032610752-0ee93602-e0e8&#8243;][vc_column_text css=&#8221;&#8221;]Yes. For Windows, YubiHSM 2 Key Storage Provider (KSP) is used for Microsoft CNG. It has been tested with Active Directory Certificate Services (AD CS) and supports 2048\/3072\/4096-bit keys.[\/vc_column_text][\/vc_tta_section][vc_tta_section title=&#8221;How do applications and systems connect to it?<br \/>&#8221; tab_id=&#8221;1772032636651-684d16c5-83f9&#8243;][vc_column_text css=&#8221;&#8221;]<\/p>\n<p data-start=\"1181\" data-end=\"1215\">Standard integration options:<\/p>\n<ul data-start=\"1216\" data-end=\"1393\">\n<li data-start=\"1216\" data-end=\"1231\">\n<p data-start=\"1218\" data-end=\"1231\">PKCS#11<\/p>\n<\/li>\n<li data-start=\"1232\" data-end=\"1261\">\n<p data-start=\"1234\" data-end=\"1261\">KSP for Microsoft CNG<\/p>\n<\/li>\n<li data-start=\"1262\" data-end=\"1393\">\n<p data-start=\"1264\" data-end=\"1393\">Native libraries for Windows\/Linux\/macOS for more direct interaction<\/p>\n<\/li>\n<\/ul>\n<p>[\/vc_column_text][\/vc_tta_section][vc_tta_section title=&#8221;Can one YubiHSM be shared across multiple services or servers?<br \/>&#8221; tab_id=&#8221;1772032679588-9ba10dd1-3122&#8243;][vc_column_text css=&#8221;&#8221;]Yes. The device supports up to 16 concurrent connections. It can also be exposed over the network so that applications on other servers can use it (commonly used on hosts with multiple virtual machines).[\/vc_column_text][\/vc_tta_section][vc_tta_section title=&#8221;How is access control implemented?<br \/>&#8221; tab_id=&#8221;1772032718485-ab53952f-1c3c&#8221;][vc_column_text css=&#8221;&#8221;]There are security domains inside the device. Permissions are assigned per authentication key: you can grant separate rights for signing, administration, and audit access. This is useful when different teams are responsible for different parts of the infrastructure.[\/vc_column_text][\/vc_tta_section][vc_tta_section title=&#8221;Is there audit logging? Can it be trusted?<br \/> &#8221; tab_id=&#8221;1772032758842-3f710d6e-6826&#8243;][vc_column_text css=&#8221;&#8221;]Yes. There is a tamper-evident audit log: operational logs can be exported for monitoring and reporting. Entries are linked via a hash chain, so any modification or deletion can be detected.[\/vc_column_text][\/vc_tta_section][vc_tta_section title=&#8221;What\u2019s new specifically in version v2.4?<br \/>&#8221; tab_id=&#8221;1772032786476-c5eb8457-d803&#8243;][vc_column_text css=&#8221;&#8221;]<\/p>\n<p data-start=\"2425\" data-end=\"2449\">Two major updates:<\/p>\n<ul data-start=\"2450\" data-end=\"2707\">\n<li data-start=\"2450\" data-end=\"2533\">\n<p data-start=\"2452\" data-end=\"2533\">Simplified and more secure backups (including asymmetric cryptography)<\/p>\n<\/li>\n<li data-start=\"2534\" data-end=\"2707\">\n<p data-start=\"2536\" data-end=\"2707\">BYOK (Bring Your Own Key) for hybrid\/multi-cloud scenarios, allowing you to store and manage your own keys instead of relying on provider-managed keys<\/p>\n<\/li>\n<\/ul>\n<p>[\/vc_column_text][\/vc_tta_section][vc_tta_section title=&#8221;Why is your store better than the rest?&#8221; tab_id=&#8221;1568244234287-a88a629e-6cee&#8221;][vc_column_text]LWallet.com.ua is an online store in Ukraine that specializes in the sale of cryptocurrency storage devices and security keys. In our store the widest range of such goods in the country. We deliver to any city of Ukraine. We not only sell wallets, but also help to customize them, give advice. For all products we provide a guarantee of 1 year.[\/vc_column_text][\/vc_tta_section][vc_tta_section title=&#8221;What&apos;s the warranty on the devices?&#8221; tab_id=&#8221;1568244416703-b73f91b7-619b&#8221;][vc_column_text]We give a manufacturer&#8217;s warranty and change any faulty device within a year.[\/vc_column_text][\/vc_tta_section][vc_tta_section title=&#8221;What does technical support mean?&#8221; tab_id=&#8221;1568244417949-1f88e967-c8b0&#8243;][vc_column_text]We will help you set up your wallet in our office or remotely. If you have any questions about your devices, we&#8217;ll always advise you over the phone or even over Zoom.[\/vc_column_text][\/vc_tta_section][vc_tta_section title=&#8221;Where can I order shipping?&#8221; tab_id=&#8221;1568244419027-1776864c-710c&#8221;][vc_column_text]We deliver to any city of Ukraine. When you check out the order, you will be able to choose the nearest point of issue to you.[\/vc_column_text][\/vc_tta_section][vc_tta_section title=&#8221;Can I pay when I receive it?&#8221; tab_id=&#8221;1568244432719-c4730277-fdc6&#8243;][vc_column_text]Yes, you can pay the courier or at the point of issue when you receive it. You can also pay immediately by transferring to your bank account.[\/vc_column_text][\/vc_tta_section][vc_tta_section title=&#8221;Which device is right for me?&#8221; tab_id=&#8221;1568244432719-c4730277-fdc7&#8243;][vc_column_text] <a href=\"https:\/\/www.yubico.com\/quiz\/\" rel=\"nofollow noopener\" target=\"_blank\">Take the test<\/a> [\/vc_column_text][\/vc_tta_section][\/vc_tta_accordion][\/vc_column][\/vc_row]<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<div style=\"font-weight: 500; transform: scale(0.5); transform-origin: left;\">\n<div style=\"display: flex; align-items: center; white-space: nowrap;\"><a style=\"display: flex; align-items: center; text-decoration: none; color: inherit;\" href=\"https:\/\/www.yubico.com\/support\/resellers\/\"><br \/>\n<img decoding=\"async\" width=\"121\" height=\"32\" class=\"alignnone size-full wp-image-43324\" style=\"vertical-align: middle;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2024\/09\/logo-yubico-pic1.png\" alt=\"yubico logo\"><br \/>\n<span style=\"margin: 0 10px; text-transform: uppercase; font-size: 25px;\">Official partner<\/span><br \/>\n<img decoding=\"async\" width=\"32\" height=\"32\" class=\"alignnone size-full wp-image-43327\" style=\"vertical-align: middle;\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2024\/09\/verified-mark.png\" alt=\"\"><br \/>\n<\/a><\/div>\n<\/div>\n<p>Release 2.4<\/p>\n<ul>\n<li>Direct connection via USB<\/li>\n<li>Advanced hardware security module<\/li>\n<li>Support for asymmetric cryptographic operations<\/li>\n<li>Compatibility with Windows, Linux, and Mac operating systems<\/li>\n<li>USB-A interface for fast connection<\/li>\n<\/ul>\n","protected":false},"featured_media":32413,"comment_status":"open","ping_status":"closed","template":"","meta":[],"product_brand":[],"product_cat":[651],"product_tag":[],"class_list":{"0":"post-62967","1":"product","2":"type-product","3":"status-publish","4":"has-post-thumbnail","6":"product_cat-security-keys-en","7":"pa_brand-yubico-en","8":"pa_country_of_manufacturer-usa","9":"pa_port-usb-a-en","10":"pa_size-12-x-13-x-3-mm","11":"pa_warranty-12-months","12":"pa_weight-1-gram","14":"first","15":"onbackorder","16":"shipping-taxable","17":"purchasable","18":"product-type-simple"},"_links":{"self":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/product\/62967","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/product"}],"about":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/types\/product"}],"replies":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/comments?post=62967"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media\/32413"}],"wp:attachment":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media?parent=62967"}],"wp:term":[{"taxonomy":"product_brand","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/product_brand?post=62967"},{"taxonomy":"product_cat","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/product_cat?post=62967"},{"taxonomy":"product_tag","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/product_tag?post=62967"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}