This article describes the end-of-life of the YubiKey Validation Server (YK-VAL), the YubiKey Key Storage Module (YK-KSM) and YubiHSM 1 and next steps for customers.
YK-VAL is a server that validates YubiKey one-time passwords (OTPs). YK-VAL is written in PHP, for use behind web servers such as Apache. YK-KSM provides an AES key storage facility for use with a YubiKey validation server.
End of life and end of support timeline:
- End-of-life YK-VAL and YK-KSM on 1 May 2021
- End-of-sale YubiHSM 1 on 1 Nov 2021
- End-of-support YubiHSM 1 on 1 May 2022
On 26 April 2021, Yubico declared end-of-life of YK-VAL and YK-KSM and moved both to YubicoLabs as a reference architecture. Yubico discontinued the sale of YubiHSM 1 on 1 May 2022.
The YK-VAL service relied on PHP 5 which is deprecated.
Products and libraries on YubicoLabs are experimental projects and reference architectures to be used by anyone as-is without any option to purchase Priority Support, receive free support, or request development, bug-fixes or platform support from Yubico.
Yubico recommends customers who use these libraries to migrate to YubiCloud, a free validation service offered by Yubico that is not encumbered by YK-VAL’s limitations, and which benefits from a SaaS-delivered service with security reviews, patches and upgrades, continuous delivery and continuous improvement.