SSL · PROVIDER / SDK PROFILE

Trusted PQC OpenSSL 3 Provider
Roadmap

Planned provider surface for Linux, CLI, CMS and controlled TLS interoperability testing.

CUSTOMER PROBLEM

Planned provider surface for Linux, CLI, CMS and controlled TLS interoperability testing.

Linux and OpenSSL 3 applications need a provider model, packaging and interoperability evidence before PQC support can be represented as a production capability.

Roadmap
Portfolio class
Provider / SDK profile
Public profile
2026.07
Version rule
Confirmed in quotation / release record

PRODUCT-SPECIFIC IMPLEMENTATION FLOW

How Trusted PQC OpenSSL 3 Provider operates from input to evidence.

Linux distributions, OpenSSL 3 applications and controlled test environments. Roadmap approval, implementation tests and release-specific compatibility evidence before public support.

01

Application issues algorithm/property query

OpenSSL 3 provider architecture

02

OpenSSL core selects Mobile-ID provider

CLI, CSR, CMS and controlled TLS profiles

03

Provider dispatches keymgmt/signature/KEM

Linux distribution packaging

04

Backend performs protected operation

Containerized test environment

05

TLS/CMS/CLI consumes result

Algorithm fetch and property governance

06

Test harness records provider and library build

Performance and interoperability publication gate

NAMED COMPONENTS AND RESPONSIBILITIES

What Trusted PQC OpenSSL 3 Provider contains and what each component does.

The descriptions below state concrete technical behaviour rather than generic support language.

01

OpenSSL 3 provider architecture

Implements the OpenSSL 3 provider dispatch model for key management, signature, digest and approved KEM functions without relying on legacy ENGINE hooks.

02

CLI, CSR, CMS and controlled TLS profiles

Defines tested CLI, CSR, CMS and controlled TLS commands with property queries that make provider and algorithm selection visible.

03

Linux distribution packaging

Packages provider binaries, configuration, dependencies and signatures for named Linux distributions and CPU architectures.

04

Containerized test environment

Supplies a containerized test image with pinned OpenSSL, provider, certificate, test corpus and reproducible command scripts.

05

Algorithm fetch and property governance

Uses property governance to prevent silent fallback to an unintended provider or algorithm when multiple implementations are installed.

06

Performance and interoperability publication gate

Blocks public support until performance, interoperability, negative tests, downgrade behavior and exact release combinations are published.

CUSTOMER OUTCOMES
  • OpenSSL 3 provider model
  • Containerized test profile
  • TLS/CMS pilot path
INTEGRATION BOUNDARY

Linux distributions, OpenSSL 3 applications and controlled test environments.

DEPLOYMENT PATTERNS

Developer sandbox

A pinned provider/SDK build, sample application, test key backend and diagnostics are supplied for repeatable integration.

Application pilot

One named application and runtime are integrated with exact algorithms, key backend, test corpus and rollback.

Enterprise release channel

Signed packages, compatibility matrix, upgrade policy, monitoring and support ownership govern broader rollout.

EVIDENCE REQUIRED
  • Roadmap approval, implementation tests and release-specific compatibility evidence before public support.
  • Version and configuration manifest for: Linux distributions, OpenSSL 3 applications and controlled test environments.
  • Negative, failure and recovery tests for “TLS/CMS/CLI consumes result” and “Test harness records provider and library build”.
  • Signed acceptance record, accountable owner, published limitations and next review date.
STANDARDS & PROFILES
  • OpenSSL 3 Provider API
  • CMS / PKIX
  • TLS experimentation
  • Linux packaging

PRODUCT-SPECIFIC BOUNDARIES

Conditions that must remain true for Trusted PQC OpenSSL 3 Provider.

These points come from the product profile, not from a shared disclaimer.

NEXT STEP

Join a design-partner review: Trusted PQC OpenSSL 3 Provider

Validate the target use case, platform dependency and release gate.