Skip to main content

Composite ML-DSA for use in Internet PKI

Document Type Replaced Internet-Draft (individual)
Expired & archived
Authors Mike Ounsworth , John Gray , Massimiliano Pala , Jan Klaußner
Last updated 2024-03-04
Replaced by draft-ietf-lamps-pq-composite-sigs
RFC stream (None)
Intended RFC status (None)
Additional resources GitHub Repository
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Replaced by draft-ietf-lamps-pq-composite-sigs
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:


This document defines Post-Quantum / Traditional composite Key Signaturem algorithms suitable for use within X.509, PKIX and CMS protocols. Composite algorithms are provided which combine ML-DSA with RSA, ECDSA, Ed25519, and Ed448. The provided set of composite algorithms should meet most X.509, PKIX, and CMS needs.


Mike Ounsworth
John Gray
Massimiliano Pala
Jan Klaußner

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)