ART-86 · Wave 18 · Post-Quantum Cryptography · TLS/PKI Migration

TLS / X.509 PKI Migration Planner

Sequences TLS and PKI migration from RSA/ECDSA to post-quantum algorithms. Builds a phased plan (root CAs → intermediates → leaf certificates), models payload impact per NIST FIPS 203/204, and flags interoperability risks. Reuses CBOM inventory from tool 499. Part of the pqc-tls-pki and pqc-hndl-protocol-plan chains.

NIST FIPS 203 · FIPS 204 ML-KEM-768 · ML-DSA-65 Hybrid / Composite / Replace
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
PKI configuration
Migration strategy
Strategy
Est. Total Weeks
3
Phases
Migration phases
PhaseTargetEst. WeeksNotes
Payload impact
New sig size (per cert)
bytes
Algorithm refs (NIST FIPS 203/204)
ML-KEM-768 PK: 1 184 bytes
ML-DSA-65 sig: 3 309 bytes
RSA-2048 sig: 256 bytes
Hybrid overhead: ~2.1×
Interoperability risks
Rollback points
Compliance flags
Algorithm sizes: NIST FIPS 203 (Aug 2024) — ML-KEM-768 public key 1 184 bytes · NIST FIPS 204 (Aug 2024) — ML-DSA-65 signature 3 309 bytes · Hybrid overhead multiplier ~2.1× (verify current primary source). Effort estimates are indicative — adjust for organisational capacity. DECISION-SUPPORT DRAFT.
OpenChainGraph v0.4 artifact · execution_hash: