YubiKey Firmware 5.7.4 Adds Support for 3072-bit RSA Code Signing Keys

Related Content

Want to keep learning?

Subscribe to SSL.com’s newsletter, stay informed and secure.

Good news for YubiKey users: Yubico has released firmware 5.7.4 for the YubiKey 5 FIPS Series, and it changes what you can do with your device for code signing. The update adds support for RSA-3072 and RSA-4096 key generation on the PIV applet. Yubico submitted the firmware for FIPS 140-3 validation. The YubiKey 5 FIPS Series is now validated under Certificate #5291.

Why this matters

If you’ve been using a YubiKey for code signing, you may remember the limitation we wrote about back in 2021 in New Minimum RSA Key Size for Code Signing Certificates. At the time, YubiKey firmware topped out at a 2048-bit RSA key size. Since SSL requires a minimum 3072-bit RSA key for code signing certificates, RSA wasn’t an option. You had to choose ECCP256 or ECCP384 instead.

That’s no longer the case.

What’s changed

If your YubiKey is running firmware 5.7.4 or later, you can now generate a 3072-bit RSA key directly on the device, right alongside the existing ECCP256 and ECCP384 options.

That means when you set up a new code signing certificate on a qualifying YubiKey, you now have three algorithm options:

  • RSA3072
  • ECCP256
  • ECCP384

Check your firmware version first

Before you choose RSA3072, check your firmware version. There are two easy ways to do it:

  • Open the YubiKey Manager app. Your firmware version shows up right on the home screen.
  • Run ykman info from the command line with your YubiKey connected.

If your device reports an older version, update to firmware 5.7.4 or later using the YubiKey Manager app.

Which option should you choose?

If you need a hardware-enforced 3072-bit RSA key on your YubiKey, you now have that option. If you’re already using ECCP256 or ECCP384, there’s no need to switch. Your existing certificates stay valid until they expire, no matter which algorithm they’re built on.

For step-by-step instructions, check out our guide: Key Generation and Attestation with YubiKey for Code Signing Certificates.

Questions? Reach out to the SSL Support Team using the form below, or start a chat in the lower-right corner of this page for faster help. We’re here for you.

SSL.com

We’d love your feedback

Take our survey and let us know your thoughts on your recent purchase.

Privacy Overview
SSL.com

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognizing you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

For more information read our Cookie and privacy statement.

3rd Party Cookies

This website uses Google Analytics & Statcounter to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping these cookies enabled helps us to improve our website.

Show details