Post-Quantum PKI
Issue certificates with NIST post-quantum signature algorithms, or a hybrid that keeps classical assurance too.
Why post-quantum
A future quantum computer could break RSA and ECC signatures. To stay ahead, DuoKey can issue certificates signed with NIST-standardized post-quantum signature algorithms, and a hybrid composite that combines a post-quantum and a classical signature so a certificate remains trustworthy even if one scheme is later weakened.
Supported algorithms
| Algorithm | Standard | Type |
|---|---|---|
ML-DSA-44 | FIPS 204 | Lattice-based signature (Dilithium) |
ML-DSA-65 | FIPS 204 | Lattice-based signature (Dilithium) |
ML-DSA-87 | FIPS 204 | Lattice-based signature (Dilithium) |
SLH-DSA-128F | FIPS 205 | Hash-based signature (SPHINCS+), fast variant |
SLH-DSA-128S | FIPS 205 | Hash-based signature (SPHINCS+), small variant |
ML-DSA-65 + ECDSA-P256 | Composite | Hybrid: post-quantum plus classical in one certificate |
These are offered alongside the classical algorithms (RSA-2048/4096, EC-P256/P384). There is no RSA-3072, EC-P521 or 8192-bit option.
Vault-signed PQC certificate authorities
Post-quantum and hybrid certificate authorities are vault-signed — their signing keys live in the vault / HSM rather than being generated locally. Classical CAs can still sign locally.
When you create an intermediate under a PQC or hybrid parent, the platform enforces parent-algorithm compatibility so the whole chain verifies. Plan your hierarchy with the signature family in mind (see CA Management).
Issuing a post-quantum certificate
Use a vault-backed CA
Ensure the issuing CA is vault-backed and uses a PQC or hybrid algorithm.
Select a PQC / hybrid algorithm
Choose ML-DSA, SLH-DSA or the hybrid composite when requesting the certificate.
Issue and deploy
Issue as usual; the leaf key is vault-resident. Deploy to targets that understand the chosen algorithms.
Not every browser, server or device understands ML-DSA / SLH-DSA yet. Use PQC where you control both ends, and the hybrid composite where you need to stay interoperable with classical relying parties while gaining quantum resistance.
Related: quantum-readiness tooling
DuoKey also includes an adjacent post-quantum readiness capability — cryptography discovery scans, a CBOM (cryptographic bill of materials), migration planning and a quantum risk score — to help you find and prioritize what to migrate. See the DuoKey post-quantum readiness tooling for that workflow.