%% You should probably cite draft-ietf-lamps-pq-composite-sigs-14 instead of this revision. @techreport{ietf-lamps-pq-composite-sigs-12, number = {draft-ietf-lamps-pq-composite-sigs-12}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-lamps-pq-composite-sigs/12/}, author = {Mike Ounsworth and John Gray and Massimiliano Pala and Jan Klaußner and Scott Fluhrer}, title = {{Composite ML-DSA for use in X.509 Public Key Infrastructure}}, pagetotal = 203, year = 2025, month = oct, day = 10, abstract = {This document defines combinations of ML-DSA {[}FIPS.204{]} in hybrid with traditional algorithms RSASSA-PKCS1-v1.5, RSASSA-PSS, ECDSA, Ed25519, and Ed448. These combinations are tailored to meet regulatory guidelines. Composite ML-DSA is applicable in applications that uses X.509 or PKIX data structures that accept ML- DSA, but where the operator wants extra protection against breaks or catastrophic bugs in ML-DSA, and where EUF-CMA-level security is acceptable.}, }