{
      "tool_id": "art-86-tls-pki-migration-planner",
      "tool_version": "1.0.0",
      "display_name": "TLS / X.509 PKI Migration Planner",
      "mcp_name": "plan_tls_pki_migration",
      "mandate_type": "compliance_mandate",
      "wave": 18,
      "gpu": false,
      "url": "https://ainumbers.co/chaingraph/art-86-tls-pki-migration-planner.html",
      "description": "Sequences TLS and X.509 PKI migration from RSA/ECDSA to post-quantum algorithms (ML-KEM/ML-DSA per NIST FIPS 203/204 Aug 2024). Builds a phased plan (root CAs -> intermediates -> leaf certificates), models payload impact for hybrid/composite/replace strategies, and flags interoperability risks. Reuses CBOM inventory from tool 499.",
      "input_schema_ref": "chaingraph/art-86-tls-pki-migration-planner.html#manifest",
      "consumes": [
        "art-85-pqc-timeline-fit-diagnostic",
        "499-crypto-asset-inventory-classifier"
      ],
      "feeds": [
        "cry-04-merkle-batch-verifier",
        "cry-05-agent-action-audit-trail-aggregator"
      ],
      "status": "live",
      "conformance_fixtures": false,
      "compute_capability": "server",
      "compute_proof_ready": "ready",
      "compute_images": [{"system":"sha256-source","image_id":"sha256:e85d6bf7a77f232f5abd1634ba2c1b56fdf0bb46db01403dc6bf55e317bfe718","valid_from":"2026-07-10"},{"system":"risc0","image_id":"sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6","valid_from":"2026-06-28"}],
      "compute_proof": {
        "type": "ZkVmReceipt",
        "system": "risc0",
        "receiptFormat": "groth16-bn254",
        "imageId": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
        "seal": "JlTyMfi7PEPg9GJnIVqPysJmjCI4j0ZZrOmIME3KC7wlqafEfxQLm4dd7/PiVhpo0VwSTaeCTYf18yvXnqyz+RmHO2cUH/vQbOhfiNIIGaV1G3tIGKTHGEq+E8Jqhmf6HzFFA3JS56BrejPoIy4nod5vc7JXjA7tKljJHd3+zlgRJQPmJ/2Dky7PH3ZmiAnNy7CvbC1TDm0ite+Ir6mv5SJKqRj34DRr5rQZ6xvcs5ug+qX0G7dUipMe2kpJRCKXGNDpNDRuF447gG8sn6aR8XIyPThP6bqcZpT6Wpyhoe4F4Snw3HiNBnjsG66hPFN9kOAIihEuFC9An/nZ2wdlVQ==",
        "journal": {
          "chaingraph_version": "0.4.0",
          "kernel_digest": "sha256:e85d6bf7a77f232f5abd1634ba2c1b56fdf0bb46db01403dc6bf55e317bfe718",
          "output": {
            "algorithm_refs": {
              "hybrid_overhead_mult": 2.1,
              "ml_dsa_65_sig_bytes": 3309,
              "ml_kem_768_pk_bytes": 1184,
              "rsa2048_sig_bytes": 256
            },
            "estimated_total_weeks": 20,
            "interop_risks": [
              "Hybrid mode doubles certificate chain size (~2.1× overhead) — verify path length constraints"
            ],
            "inventory_ref": null,
            "migration_plan": [
              {
                "effort_weeks": 6,
                "notes": "1 root CA(s) — high effort; test in offline environment first",
                "phase": 1,
                "target": "Root CA migration"
              },
              {
                "effort_weeks": 8,
                "notes": "2 intermediate CA(s) — schedule CRL/OCSP updates",
                "phase": 2,
                "target": "Intermediate CA migration"
              },
              {
                "effort_weeks": 6,
                "notes": "1,000 leaf certs — automate via ACME or SCEP where possible",
                "phase": 3,
                "target": "Leaf certificate / TLS endpoint rollout"
              }
            ],
            "note": "DECISION-SUPPORT DRAFT. Algorithm sizes from NIST FIPS 203/204 (Aug 2024). Hybrid overhead multiplier is approximate — verify against current PQC overhead benchmarks. Effort estimates are indicative; adjust for organisational capacity and toolchain maturity.",
            "payload_impact_bytes": 3565,
            "pki_summary": {
              "intermediate_count": 2,
              "leaf_population": 1000,
              "root_cas": 1,
              "tls_versions": []
            },
            "reference_version": "2026-06",
            "rollback_points": [
              "After root CA switch",
              "After intermediate rollout"
            ],
            "strategy": "hybrid"
          }
        }
      },
      "export_capability": [
        "pdf",
        "xlsx"
      ]
    }
