Skip to main content
ClassicalRSA-2048 / 4096EC-P256 / P384widely compatible todayPost-quantumML-DSA-44 / 65 / 87SLH-DSA-128f / 128squantum-resistant (FIPS 204/205)HybridTRANSITIONML-DSA-65 + ECDSA-P256quantum-resistant + classical
Sign with classical, post-quantum, or a hybrid composite — the hybrid stays interoperable with classical relying parties while adding quantum resistance.
Applies to:
DuoKey Cockpit v2ML-DSA · SLH-DSA · hybridVault-signed PQC CAs

Why post-quantum​

A future quantum computer could break RSA and ECC signatures. To stay ahead, DuoKey can issue certificates signed with NIST-standardized post-quantum signature algorithms, and a hybrid composite that combines a post-quantum and a classical signature so a certificate remains trustworthy even if one scheme is later weakened.

Supported algorithms​

AlgorithmStandardType
ML-DSA-44FIPS 204Lattice-based signature (Dilithium)
ML-DSA-65FIPS 204Lattice-based signature (Dilithium)
ML-DSA-87FIPS 204Lattice-based signature (Dilithium)
SLH-DSA-128FFIPS 205Hash-based signature (SPHINCS+), fast variant
SLH-DSA-128SFIPS 205Hash-based signature (SPHINCS+), small variant
ML-DSA-65 + ECDSA-P256CompositeHybrid: post-quantum plus classical in one certificate
Also alongside classical

These are offered alongside the classical algorithms (RSA-2048/4096, EC-P256/P384). There is no RSA-3072, EC-P521 or 8192-bit option.

Vault-signed PQC certificate authorities​

Post-quantum and hybrid certificate authorities are vault-signed — their signing keys live in the vault / HSM rather than being generated locally. Classical CAs can still sign locally.

Build the chain PQC-aware

When you create an intermediate under a PQC or hybrid parent, the platform enforces parent-algorithm compatibility so the whole chain verifies. Plan your hierarchy with the signature family in mind (see CA Management).

Issuing a post-quantum certificate​

1

Use a vault-backed CA

Ensure the issuing CA is vault-backed and uses a PQC or hybrid algorithm.

2

Select a PQC / hybrid algorithm

Choose ML-DSA, SLH-DSA or the hybrid composite when requesting the certificate.

3

Issue and deploy

Issue as usual; the leaf key is vault-resident. Deploy to targets that understand the chosen algorithms.

Ecosystem support is still maturing

Not every browser, server or device understands ML-DSA / SLH-DSA yet. Use PQC where you control both ends, and the hybrid composite where you need to stay interoperable with classical relying parties while gaining quantum resistance.

DuoKey also includes an adjacent post-quantum readiness capability — cryptography discovery scans, a CBOM (cryptographic bill of materials), migration planning and a quantum risk score — to help you find and prioritize what to migrate. See the DuoKey post-quantum readiness tooling for that workflow.