๐ค AI Summary
Industrial post-quantum cryptography (PQC) migration faces a critical gap in the X.509 certificate ecosystem: lack of lightweight, command-line-driven tooling for hybrid and composite certificates. Method: This paper designs and open-sources the first modular CLI tool supporting both ML-DSA and SLH-DSA, built atop Bouncy Castle and fully compliant with X.509 standards. It enables unified generation and verification of classical, hybrid (Catalyst), composite, and partial-chameleon certificates, operating headlessly on resource-constrained platforms. Contribution/Results: The tool fills a major void in the open-source ecosystemโunlike OpenSSL and other existing solutions, it provides native CLI support for PQC hybrid and composite certificates. Experimental evaluation confirms its feasibility within industrial certificate workflows, delivering a reusable, extensible infrastructure to bridge the gap between PQC standardization and real-world deployment.
๐ Abstract
The transition to post-quantum cryptography (PQC) presents significant challenges for certificate-based identity management in industrial environments, where secure onboarding of devices relies on long-lived and interoperable credentials. This work analyzes the integration of PQC into X.509 certificate structures and compares existing tool support for classical, hybrid, composite, and chameleon certificates. A gap is identified in available open-source solutions, particularly for the generation and validation of hybrid and composite certificates via command-line interfaces. To address this, a proof-of-concept implementation based on the Bouncy Castle library is developed. The tool supports the creation of classical, hybrid (Catalyst), composite, and partially chameleon certificates using PQC algorithms such as ML-DSA and SLH-DSA. It demonstrates compatibility with standard X.509 workflows and aims to support headless operation and constrained platforms typical of industrial systems. The implementation is modular, publicly available, and intended to facilitate further research and testing of PQC migration strategies in practice. A comparison with OpenSSL-based solutions highlights current limitations in standardization, toolchain support, and algorithm coverage.