ART-86 · Wave 18 · Post-Quantum Cryptography · TLS/PKI Migration

TLS / X.509 PKI Migration Planner

Sequences TLS and PKI migration from RSA/ECDSA to post-quantum algorithms. Builds a phased plan (root CAs → intermediates → leaf certificates), models payload impact per NIST FIPS 203/204, and flags interoperability risks. Reuses CBOM inventory from tool 499. Part of the pqc-tls-pki and pqc-hndl-protocol-plan chains.

NIST FIPS 203 · FIPS 204 ML-KEM-768 · ML-DSA-65 Hybrid / Composite / Replace
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
PKI configuration
Migration strategy
Strategy
Est. Total Weeks
3
Phases
Migration phases
PhaseTargetEst. WeeksNotes
Payload impact
New sig size (per cert)
bytes
Algorithm refs (NIST FIPS 203/204)
ML-KEM-768 PK: 1 184 bytes
ML-DSA-65 sig: 3 309 bytes
RSA-2048 sig: 256 bytes
Hybrid overhead: ~2.1×
Interoperability risks
Rollback points
Compliance flags
Algorithm sizes: NIST FIPS 203 (Aug 2024) — ML-KEM-768 public key 1 184 bytes · NIST FIPS 204 (Aug 2024) — ML-DSA-65 signature 3 309 bytes · Hybrid overhead multiplier ~2.1× (verify current primary source). Effort estimates are indicative — adjust for organisational capacity. DECISION-SUPPORT DRAFT.
OpenChainGraph v0.4 artifact · execution_hash:


    

Ask your agent

Copy this paragraph into Claude, OpenClaw, or any MCP-aware agent to run this exact tool, with this sample, and verify the artifact.

Run the AINumbers MCP tool `plan_tls_pki_migration`. Task: Sequence TLS and X.509 PKI migration from RSA/ECDSA to post-quantum algorithms (ML-KEM/ML-DSA per NIST FIPS 203/204 Aug 2024).
Call it with arguments: {"policy_parameters":{}}
Verify before trusting: call `verify_execution_hash` on mcp.ainumbers.co (https://mcp.ainumbers.co/mcp) with the parameter `claimed_hash` set to the returned `execution_hash`, passing the full artifact the run returned (the object containing `policy_parameters` + `output_payload` + `execution_hash`; equivalently `policy_parameters` + `output_payload` with `claimed_hash`), not the bare hash string.
Return the ledger link https://ledger.ainumbers.co/ so a human can re-verify without contacting us.
PII rule: All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Open the tool with the sample prefilled: https://ainumbers.co/chaingraph/art-86-tls-pki-migration-planner.html#p=v1.H4sIAAAAAAAA_wECAP3_e31Dv6ajAgAAAA