yubihsm2-sdk
« Back to VersTracker
Description:
Libraries and utilities to interact with a YubiHSM 2 natively and via PKCS#11
Type: Cask  |  Latest Version: 2026-01@0  |  Tracked Since: Dec 28, 2025
Links: Homepage  |  @Yubico  |  formulae.brew.sh
Category: Security
Tags: yubikey hsm pkcs11 security cryptography
Install: brew install --cask yubihsm2-sdk
About:
The YubiHSM 2 SDK provides the essential libraries and command-line utilities required to configure, manage, and interact with a YubiHSM 2 hardware security module. It includes the native `yubihsm-shell` tool for direct device commands and a robust PKCS#11 provider for integrating hardware-backed key storage into applications like web servers and VPNs.
Key Features:
  • Native command-line interface (yubihsm-shell) for device management
  • PKCS#11 library for integration with OpenSSL and other standard applications
  • Support for secure key generation, storage, and cryptographic operations
  • Backup and recovery utilities for disaster planning
Use Cases:
  • Securing TLS private keys for web servers (Nginx, Apache)
  • Generating and storing Certificate Authority (CA) keys offline
  • Hardware-backed authentication for VPN infrastructure
Alternatives:
  • OpenSC – OpenSC is an open-source PKCS#11 provider for many smart cards, whereas YubiHSM 2 SDK is vendor-specific and optimized for the YubiHSM 2 hardware.
Version History
Detected Version Rev Change Commit
Jan 20, 2026 5:20pm 2026-01 0 VERSION_BUMP e2dc5cf8
Aug 5, 2025 6:01pm 2025-06b 0 VERSION_BUMP f5d24728
Aug 2, 2025 8:00am 2025-06b 0 VERSION_BUMP 016c1021