Yubikey FIPS Support
IdExchange supports the issuance and management of the YubiKey FIPS device for organizations that require NIST SP800-63B authenticator assurance level 3 (AAL3) hardware devices.
Capabilities:
- Derivation and insertion of new secure management keys and PUK values via the secure channel protocol (SCP)
- YubiKey device chain of custody
- Certificate Attestation
- Support for YubiKey FIPS 5.4
- Generation and loading of PKI certificates
- Support for FIDO credential generation
- Device verification and chain of custody
- Certificate renewal
- PIN change