Requirements
What the regulation expects

FIPS-validated components, not a marketing label
Required for US federal work and common in regulated financial security reviews.
Algorithms and operations covered
AES-256, RSA 2048/4096, HMAC-SHA256, secure random generation and key zeroization procedures.
Relevant for federal and financial buyers
FIPS component validation is often checked early in US federal and regulated financial security reviews.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Route key ops through FIPS-validated backends (HSM or validated software modules) according to the deployment model.
Learn moreHSM-backed custody
Pin keys to PKCS#11 HSMs where FIPS module validation is a hard requirement.
Learn moreKey themes
Where independent key control fits
Status: aligned (FIPS-validated components). DuoKey uses FIPS-validated cryptographic components; individual deployments are not themselves FIPS-validated modules unless a specific module certificate applies.
Symmetric encryption
AES-256 (including GCM) via FIPS-validated cryptographic components.
Asymmetric operations
RSA 2048/4096 key operations on validated components where the backend supports them.
Integrity and randomness
HMAC-SHA256 for integrity; secure random number generation for key and nonce material.
Key zeroization
Documented zeroization procedures when keys are destroyed or modules are decommissioned.
Parlons des décisions qui comptent pour votre programme de sécurité.
Dites-nous où le contrôle est difficile aujourd’hui. Nous vous aiderons à définir une prochaine étape concrète.
