Profile & OID Registry
Controls algorithm identifiers, certificate extensions, profile versions, approvals and relying-party expectations.
PROFILE GOVERNANCEPRODUCT MANUAL
Design, issue, validate and migrate classical, hybrid and PQC certificate profiles across CA, RA, VA, TSA, HSM and relying-party ecosystems.
OVERVIEW
PQC certificate migration affects hierarchy design, OIDs, enrollment, revocation, OCSP, timestamping, HSM support, relying-party parsing and operational ceremonies.
WORKFLOW
COMPONENT REFERENCE
COMPONENT ARCHITECTURE
Migration and coexistence span the full trust chain rather than appearing as a final operational step.
Controls algorithm identifiers, certificate extensions, profile versions, approvals and relying-party expectations.
PROFILE GOVERNANCEValidates enrollment requests, identity evidence, CSR profile and issuance policy while keeping RA and CA responsibilities separate.
ISSUANCEExecutes approved CA and TSA operations inside an HSM boundary with auditable key and policy controls.
TRUST COREPublishes OCSP, CRL and validation facts independently from issuance and records freshness evidence.
STATUS SERVICETests parser, chain, trust-store and application behavior against versioned certificate combinations.
INTEROPERABILITYINTERFACES
LIMITATIONS & ACCEPTANCE