PRODUCT MANUAL

QuantumSafe Certificate Fabric
Technical usage guide

Design, issue, validate and migrate classical, hybrid and PQC certificate profiles across CA, RA, VA, TSA, HSM and relying-party ecosystems.

OVERVIEW

QuantumSafe Certificate Fabric

PQC certificate migration affects hierarchy design, OIDs, enrollment, revocation, OCSP, timestamping, HSM support, relying-party parsing and operational ceremonies.

WORKFLOW

  1. 01 Inventory current hierarchy, profiles and relying parties
  2. 02 Define classical, hybrid and PQC target certificate profiles
  3. 03 Configure CA/RA enrollment and protected signing keys
  4. 04 Issue controlled certificates and publish status services
  5. 05 Test chain building, revocation, applications and trust stores
  6. 06 Run coexistence, migration waves and certificate sunset

COMPONENT REFERENCE

COMPONENT ARCHITECTURE

Govern profiles, issue credentials, protect trust-service keys and validate relying-party compatibility.

Migration and coexistence span the full trust chain rather than appearing as a final operational step.

SOURCE INPUTS
Classical profileHybrid profileControlled PQC profile
01

Profile & OID Registry

Controls algorithm identifiers, certificate extensions, profile versions, approvals and relying-party expectations.

PROFILE GOVERNANCE
02

CA/RA Enrollment Services

Validates enrollment requests, identity evidence, CSR profile and issuance policy while keeping RA and CA responsibilities separate.

ISSUANCE
03

Protected CA/TSA Key Operations

Executes approved CA and TSA operations inside an HSM boundary with auditable key and policy controls.

TRUST CORE
04

Validation Authority

Publishes OCSP, CRL and validation facts independently from issuance and records freshness evidence.

STATUS SERVICE
05

Relying-Party Compatibility Lab

Tests parser, chain, trust-store and application behavior against versioned certificate combinations.

INTEROPERABILITY
GOVERNED OUTPUTS
CertificatesStatus servicesCompatibility evidence

INTERFACES

  • X.509 / PKIX
  • CMP / EST / SCEP / ACME profiles
  • OCSP / CRL
  • RFC 3161
  • PKCS#11 / HSM
  • PAdES/CAdES/XAdES integration

LIMITATIONS & ACCEPTANCE

  • Exact PQC and hybrid certificate profiles depend on approved standards, product versions and relying-party support.
  • FIPS 140-3 validation of a cryptographic module does not by itself validate a PQC certificate profile or application integration.
  • Migration design must include revocation, renewal, chain compatibility and rollback—not only new key issuance.