Challenge Assignment
Design the certificate transition plan for your CA hierarchy:
Phase A (now – 2027): Dual-cert delivery
- Root CA: issue two intermediates (one ECDSA, one ML-DSA)
- Servers: present both chains, clients negotiate
- Advantage: no client changes required
Phase B (2027–2030): Composite certs (once IETF RFC is finalized)
- Single cert with both signatures
- Root CA: composite signature
- Streamlines cert management
Phase C (2030+): Pure ML-DSA
- Drop ECDSA infrastructure
For each phase, list: what changes, what stays the same, what the risk is.
Save to your migration roadmap as "Certificate Transition Plan."