CKM_RSA_PKCS

Firmware 7.7.2 and Newer Summary

FIPS approved? Yes
Supported functions Sign | Verify | Encrypt | Decrypt | Wrap | Unwrap
Functions restricted from FIPS use Cannot wrap | Cannot legacy decrypt | Cannot legacy unwrap | Cannot encrypt
Minimum key length (bits) 256
Minimum key length for FIPS use (bits) 2048
Minimum legacy key length for FIPS use (bits) 1024
Maximum key length (bits) 8192
Block size 0
Digest size 0
Key types RSA
Algorithms None
Modes None
Flags None

Firmware 7.7.0-7.7.1 Summary

FIPS approved? Yes
Supported functions Sign | Verify | Encrypt | Decrypt | Wrap | Unwrap
Functions restricted from FIPS use Cannot wrap
Minimum key length (bits) 256
Minimum key length for FIPS use (bits) 2048
Minimum legacy key length for FIPS use (bits) 1024
Maximum key length (bits) 8192
Block size 0
Digest size 0
Key types RSA
Algorithms None
Modes None
Flags None

NOTE   To comply with FIPS SP800-131a Rev2 published in March 2019, when the HSM is in FIPS mode, this mechanism is not allowed to wrap objects.

Firmware 7.4.2 and Older Summary

FIPS approved? Yes
Supported functions Sign | Verify | Encrypt | Decrypt | Wrap | Unwrap
Functions restricted from FIPS use None
Minimum key length (bits) 256
Minimum key length for FIPS use (bits) 2048
Minimum legacy key length for FIPS use (bits) 1024
Maximum key length (bits) 8192
Block size 0
Digest size 0
Key types RSA
Algorithms None
Modes None
Flags None

NOTE   When the HSM is in FIPS mode, this mechanism cannot be used to sign data using less than 224 bits.

This algorithm must be combined with a FIPS-approved hash algorithm to be FIPS compliant.