<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=2026" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-09-15T11:34:18+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=2026</id>
<entry>
<author><name><![CDATA[mprinkey]]></name></author>
<updated>2015-09-15T11:34:18+01:00</updated>
<published>2015-09-15T11:34:18+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2026&amp;p=7806#p7806</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2026&amp;p=7806#p7806"/>
<title type="html"><![CDATA[Re: FIPS 140-2 Certification of NEO?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2026&amp;p=7806#p7806"><![CDATA[
Any yubico people able to respond to this?  There is a lot of pressure in the wake of US Govt hacking incidents to tighten up security.  We currently use Yubikeys and I want to continue to use them, but I need supporting documentation to sell the PIV yubikeys up the line.  If I can't make that happen, I will have to investigate other PIV solutions and engineer a changeover.<br /><br />Thanks.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2308">mprinkey</a> — Tue Sep 15, 2015 11:34 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[mprinkey]]></name></author>
<updated>2015-09-09T16:54:38+01:00</updated>
<published>2015-09-09T16:54:38+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2026&amp;p=7782#p7782</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2026&amp;p=7782#p7782"/>
<title type="html"><![CDATA[FIPS 140-2 Certification of NEO?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2026&amp;p=7782#p7782"><![CDATA[
The Standard and Nano have been FIPS 140-2 certified to Level 1.  Will the Yubico be seeking similar certification for the NEO and if so, what level of certification do to anticipate it receiving?  In particular, do you anticipate that it could meet the requirements of NIST SP 800-63-1 Level 4?<br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br /><em><strong>Level 4</strong> – Level 4 is intended to provide the highest practical remote network authentication assurance. Level 4 authentication is based on proof of possession of a key through a cryptographic protocol. At this level, in-person identity proofing is required. Level 4 is similar to Level 3 except that only “hard” cryptographic tokens are allowed.  The token is required to be a hardware cryptographic module validated at Federal Information Processing Standard (FIPS) 140-2 Level 2 or higher overall with at least FIPS 140-2 Level 3 physical security. Level 4 token requirements can be met by using the PIV authentication key of a FIPS 201 compliant Personal Identity Verification (PIV) Card.</em><br /></div><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2308">mprinkey</a> — Wed Sep 09, 2015 4:54 pm</p><hr />
]]></content>
</entry>
</feed>