diff --git a/.gitignore b/.gitignore new file mode 100644 index 00000000..0fd9a5ba --- /dev/null +++ b/.gitignore @@ -0,0 +1,5 @@ +providers/oqs/oqsprovider/artifacts +providers/entrust/default/artifacts +providers/corey-digicert/default/artifacts +providers/bc/java-artifacts +providers/botan/default/artifacts diff --git a/docs/pqc_hackathon_results.html b/docs/pqc_hackathon_results.html index b81896b9..790689e7 100644 --- a/docs/pqc_hackathon_results.html +++ b/docs/pqc_hackathon_results.html @@ -57,11503 +57,11503 @@

Algorithms

Rows are producers. Columns are parsers.

ecPublicKey (1.2.840.10045.2.1)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonextTA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
entrust
isi-wolfssl
kris
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonextTA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
entrust
isi-wolfssl
kris
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutls
oqs-openssl111
oqs-provider

prime256v1 (1.2.840.10045.3.1.7)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ❌
EE: ❌
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ❌
EE: ❌
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

prime256v1 & Dilithium2 (1.2.840.10045.3.1.7_1.3.6.1.4.1.2.267.7.4.4)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

prime256v1 & Dilithium2 & Falcon-1024 (1.2.840.10045.3.1.7_1.3.6.1.4.1.2.267.7.4.4_1.3.9999.3.4)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

prime256v1 & Dilithium3 (1.2.840.10045.3.1.7_1.3.6.1.4.1.2.267.7.6.5)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

prime256v1 & Dilithium3 & Falcon-512 (1.2.840.10045.3.1.7_1.3.6.1.4.1.2.267.7.6.5_1.3.9999.3.1)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

ecdsa-with-SHA256 (1.2.840.10045.4.3.2)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bcTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
botan
carl-redhound
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbcTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
botan
carl-redhound
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

rsaEncryption (1.2.840.113549.1.1.1)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutls
oqs-openssl111
oqs-provider

DilithiumAES2 (1.3.6.1.4.1.2.267.11.4.4)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bcTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
bcTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌

DilithiumAES3 (1.3.6.1.4.1.2.267.11.6.5)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bcTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
bcTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌

DilithiumAES5 (1.3.6.1.4.1.2.267.11.8.7)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bcTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
bcTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌

Dilithium2 (1.3.6.1.4.1.2.267.7.4.4)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bcTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonextTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ❌
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutls
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
bcTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonextTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ❌
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutlsTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌

Dilithium3 (1.3.6.1.4.1.2.267.7.6.5)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bcTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonextTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ❌
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutlsTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
bcTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonextTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ❌
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutlsTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌

Dilithium5 (1.3.6.1.4.1.2.267.7.8.7)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bcTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonextTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ❌
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutls
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
bcTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonextTA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ❌
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutlsTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌

kyber512 (1.3.6.1.4.1.22554.5.6.1)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonextTA: ✅
CA: ✅
EE: ❌
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbcTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
carl-redhoundTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
cryptonextTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ❌
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-gnutlsTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-openssl111TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-providerTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌

kyber768 (1.3.6.1.4.1.22554.5.6.2)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonextTA: ✅
CA: ✅
EE: ❌
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbcTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
carl-redhoundTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
cryptonextTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ❌
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-gnutlsTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-openssl111TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-providerTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌

kyber1024 (1.3.6.1.4.1.22554.5.6.3)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonextTA: ✅
CA: ✅
EE: ❌
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbcTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
carl-redhoundTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
cryptonextTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ❌
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-gnutlsTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-openssl111TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-providerTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌

Falcon-512 (1.3.9999.3.1)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bcTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
botan
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonextTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutls
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
bcTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonextTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutlsTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌

Falcon-1024 (1.3.9999.3.4)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bcTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
botan
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonextTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutls
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
bcTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
carl-redhoundTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonextTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutlsTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-openssl111TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌

Falcon-512 (1.3.9999.3.6)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

Falcon-1024 (1.3.9999.3.9)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

SPHINCS+-SHA256-128f-robust (1.3.9999.6.4.1)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
bc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-providerTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌

SPHINCS+-SHA256-128s-simple (1.3.9999.6.4.10)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

SPHINCS+-SHA256-128f-simple (1.3.9999.6.4.4)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

SPHINCS+-SHA256-128s-robust (1.3.9999.6.4.7)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

SPHINCS+-SHA256-192f-robust (1.3.9999.6.5.1)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

SPHINCS+-SHA256-192f-simple (1.3.9999.6.5.3)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

SPHINCS+-SHA256-192s-robust (1.3.9999.6.5.5)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

SPHINCS+-SHA256-192s-simple (1.3.9999.6.5.7)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

SPHINCS+-SHA256-256f-robust (1.3.9999.6.6.1)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

SPHINCS+-SHA256-256f-simple (1.3.9999.6.6.3)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

SPHINCS+-SHA256-256s-robust (1.3.9999.6.6.5)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

SPHINCS+-SHA256-256s-simple (1.3.9999.6.6.7)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

sphincsshake128fsimple (1.3.9999.6.7.4)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonextTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbcTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
carl-redhoundTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
cryptonextTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-gnutlsTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-openssl111TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-providerTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌

sphincsshake192fsimple (1.3.9999.6.8.3)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonextTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbcTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
carl-redhoundTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
cryptonextTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-gnutlsTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-openssl111TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-providerTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌

sphincsshake256fsimple (1.3.9999.6.9.3)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonextTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbcTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
carl-redhoundTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
corey-digicertTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
cryptonextTA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-gnutlsTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-openssl111TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-providerTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌

COMPOSITE-KEY (2.16.840.1.114027.80.4.1)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bcTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
botan
carl-redhound
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonextTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
isi-wolfssl
kris
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutls
oqs-openssl111
oqs-providerbcTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
botanTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
carl-redhoundTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonextTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
isi-wolfssl
krisTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
oqs-gnutlsTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-openssl111TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-providerTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌

COMPOSITE_KEY_HASH_N_SIGN (2.16.840.1.114027.80.4.1.2)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonextTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicert
cryptonextTA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

COMPOSITE-KEY & Unknown (2.16.840.1.114027.80.4.1_generic_traditional)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
opencaTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
oqs-gnutls
oqs-openssl111
oqs-provider

ExplicitCompositeSignature (2.16.840.1.114027.80.5.1)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhoundTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ❌
CA: ❌
EE: ❌
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

id-Dilithium3-RSA-PKCS15-SHA256 (2.16.840.1.114027.80.5.1.1)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

id-Dilithium3-RSA-PSS-SHA256 (2.16.840.1.114027.80.5.1.14)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

id-Dilithium3-ECDSA-P256-SHA256 (2.16.840.1.114027.80.5.1.2)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

id-Dilithium3-ECDSA-brainpoolP256r1-SHA256 (2.16.840.1.114027.80.5.1.3)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

id-Dilithium5-ECDSA-P384-SHA384 (2.16.840.1.114027.80.5.1.5)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

id-Dilithium5-ECDSA-brainpoolP384r1-SHA384 (2.16.840.1.114027.80.5.1.6)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

id-Falcon512-ECDSA-P256-SHA256 (2.16.840.1.114027.80.5.1.8)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
TA: ❌
CA: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

id-Falcon512-ECDSA-brainpoolP256r1-SHA256 (2.16.840.1.114027.80.5.1.9)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicert
cryptonext
entrustTA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌
TA: ❌
CA: ❌
EE: ❌
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

Unknown & Unknown (artifacts)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicert
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

Unknown & Unknown (chameleon-base)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

Unknown & Unknown (chameleon-delta)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

Unknown & Unknown (chameleon-extracted-delta)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider

Unknown & Unknown (hybrid-catalyst)

- +
-------------+++++++++++++ - - - - - - - - - - - - - + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider-bcbotancarl-redhoundcorey-digicertcryptonextentrustisi-wolfsslkrisopencaoqs-gnutlsoqs-openssl111oqs-provider
bc
botan
carl-redhound
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ❌
EE: ❌
CRL TA: ✅
CRL CA: ❌
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-providerbc
botan
carl-redhound
corey-digicertTA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ✅
EE: ✅
TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅
TA: ✅
CA: ❌
EE: ❌
CRL TA: ✅
CRL CA: ❌
cryptonext
entrust
isi-wolfssl
kris
openca
oqs-gnutls
oqs-openssl111
oqs-provider
diff --git a/docs/pqc_hackathon_results.md b/docs/pqc_hackathon_results.md index 6149d2bc..0cd6c104 100644 --- a/docs/pqc_hackathon_results.md +++ b/docs/pqc_hackathon_results.md @@ -253,137 +253,137 @@ Rows are producers. Columns are parsers. |-|bc|botan|carl-redhound|corey-digicert|cryptonext|entrust|isi-wolfssl|kris|openca|oqs-gnutls|oqs-openssl111|oqs-provider| | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | -|bc||TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| -|botan|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌|||TA: ✅
CA: ✅
EE: ✅|||||| -|carl-redhound|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ❌
EE: ❌|||||| -|corey-digicert|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌|||||| -|cryptonext||TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌||TA: ✅
CA: ✅
EE: ❌
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| -|entrust|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌||||||||| -|isi-wolfssl||||||||||||| -|kris|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|openca|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|oqs-gnutls||||||||||||| -|oqs-openssl111|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|oqs-provider|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|bc||TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| +|botan|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌||TA: ✅
CA: ✅
EE: ✅|||||| +|carl-redhound|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ❌
EE: ❌|||||| +|corey-digicert|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌|||||| +|cryptonext||TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ❌
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| +|entrust|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|||||||| +|isi-wolfssl||||||||||||| +|kris|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|openca|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|oqs-gnutls|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-openssl111|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|oqs-provider|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅|||TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| # Dilithium3 (1.3.6.1.4.1.2.267.7.6.5) |-|bc|botan|carl-redhound|corey-digicert|cryptonext|entrust|isi-wolfssl|kris|openca|oqs-gnutls|oqs-openssl111|oqs-provider| | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | -|bc||TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| -|botan|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌|||TA: ✅
CA: ✅
EE: ✅|||||| -|carl-redhound|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ❌
EE: ❌|||||| -|corey-digicert|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌|||||| -|cryptonext||TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌||TA: ✅
CA: ✅
EE: ❌
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| -|entrust|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌||||||||| +|bc||TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| +|botan|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌||TA: ✅
CA: ✅
EE: ✅|||||| +|carl-redhound|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ❌
EE: ❌|||||| +|corey-digicert|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌|||||| +|cryptonext||TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ❌
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| +|entrust|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|||||||| |isi-wolfssl||||||||||||| -|kris|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|openca|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|oqs-gnutls|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| -|oqs-openssl111|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|oqs-provider|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|kris|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|openca|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|oqs-gnutls|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| +|oqs-openssl111|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|oqs-provider|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅|||TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| # Dilithium5 (1.3.6.1.4.1.2.267.7.8.7) |-|bc|botan|carl-redhound|corey-digicert|cryptonext|entrust|isi-wolfssl|kris|openca|oqs-gnutls|oqs-openssl111|oqs-provider| | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | -|bc||TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| -|botan|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌|||TA: ✅
CA: ✅
EE: ✅|||||| -|carl-redhound|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ❌
EE: ❌|||||| -|corey-digicert|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌|||||| -|cryptonext||TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌||TA: ✅
CA: ✅
EE: ❌
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| -|entrust|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌||||||||| +|bc||TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| +|botan|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌||TA: ✅
CA: ✅
EE: ✅|||||| +|carl-redhound|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ❌
EE: ❌|||||| +|corey-digicert|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌|||||| +|cryptonext||TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ❌
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| +|entrust|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|||||||| |isi-wolfssl||||||||||||| -|kris|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|openca|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|oqs-gnutls||||||||||||| -|oqs-openssl111|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|oqs-provider|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|kris|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|openca|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|oqs-gnutls|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-openssl111|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|oqs-provider|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅|||TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| # kyber512 (1.3.6.1.4.1.22554.5.6.1) |-|bc|botan|carl-redhound|corey-digicert|cryptonext|entrust|isi-wolfssl|kris|openca|oqs-gnutls|oqs-openssl111|oqs-provider| | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | -|bc||||||||||||| -|botan||||||||||||| -|carl-redhound||||||||||||| -|corey-digicert||||||||||||| -|cryptonext|||||||TA: ✅
CA: ✅
EE: ❌|||||| -|entrust||||||||||||| +|bc|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|botan|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|carl-redhound|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|corey-digicert|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|cryptonext|||||TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌||TA: ✅
CA: ✅
EE: ❌|||||| +|entrust|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| |isi-wolfssl||||||||||||| -|kris||||||||||||| -|openca||||||||||||| -|oqs-gnutls||||||||||||| -|oqs-openssl111||||||||||||| -|oqs-provider||||||||||||| +|kris|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|openca|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-gnutls|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-openssl111|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-provider|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| # kyber768 (1.3.6.1.4.1.22554.5.6.2) |-|bc|botan|carl-redhound|corey-digicert|cryptonext|entrust|isi-wolfssl|kris|openca|oqs-gnutls|oqs-openssl111|oqs-provider| | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | -|bc||||||||||||| -|botan||||||||||||| -|carl-redhound||||||||||||| -|corey-digicert||||||||||||| -|cryptonext|||||||TA: ✅
CA: ✅
EE: ❌|||||| -|entrust||||||||||||| +|bc|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|botan|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|carl-redhound|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|corey-digicert|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|cryptonext|||||TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌||TA: ✅
CA: ✅
EE: ❌|||||| +|entrust|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| |isi-wolfssl||||||||||||| -|kris||||||||||||| -|openca||||||||||||| -|oqs-gnutls||||||||||||| -|oqs-openssl111||||||||||||| -|oqs-provider||||||||||||| +|kris|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|openca|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-gnutls|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-openssl111|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-provider|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| # kyber1024 (1.3.6.1.4.1.22554.5.6.3) |-|bc|botan|carl-redhound|corey-digicert|cryptonext|entrust|isi-wolfssl|kris|openca|oqs-gnutls|oqs-openssl111|oqs-provider| | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | -|bc||||||||||||| -|botan||||||||||||| -|carl-redhound||||||||||||| -|corey-digicert||||||||||||| -|cryptonext|||||||TA: ✅
CA: ✅
EE: ❌|||||| -|entrust||||||||||||| +|bc|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|botan|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|carl-redhound|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|corey-digicert|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|cryptonext|||||TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌||TA: ✅
CA: ✅
EE: ❌|||||| +|entrust|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| |isi-wolfssl||||||||||||| -|kris||||||||||||| -|openca||||||||||||| -|oqs-gnutls||||||||||||| -|oqs-openssl111||||||||||||| -|oqs-provider||||||||||||| +|kris|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|openca|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-gnutls|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-openssl111|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-provider|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| # ~~Falcon-512~~ (1.3.9999.3.1) |-|bc|botan|carl-redhound|corey-digicert|cryptonext|entrust|isi-wolfssl|kris|openca|oqs-gnutls|oqs-openssl111|oqs-provider| | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | -|bc||TA: ❌
CA: ❌
EE: ❌||||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| -|botan||||||||||||| -|carl-redhound|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌||||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ❌
EE: ❌|||||| -|corey-digicert|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌||||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||||||| -|cryptonext||TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|entrust|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||||||||||| +|bc||TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| +|botan|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|carl-redhound|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ❌
EE: ❌|||||| +|corey-digicert|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||||||| +|cryptonext||TA: ❌
CA: ❌
EE: ❌|||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|entrust|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| |isi-wolfssl||||||||||||| -|kris|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|openca|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|oqs-gnutls||||||||||||| -|oqs-openssl111|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|oqs-provider|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|kris|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|openca|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|oqs-gnutls|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-openssl111|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|oqs-provider|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| # ~~Falcon-1024~~ (1.3.9999.3.4) |-|bc|botan|carl-redhound|corey-digicert|cryptonext|entrust|isi-wolfssl|kris|openca|oqs-gnutls|oqs-openssl111|oqs-provider| | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | -|bc||TA: ❌
CA: ❌
EE: ❌||||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| -|botan||||||||||||| -|carl-redhound|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌||||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ❌
EE: ❌|||||| -|corey-digicert|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌||||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||||||| -|cryptonext||TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|entrust|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||||||||||| +|bc||TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅|||||| +|botan|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|carl-redhound|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ❌
EE: ❌|||||| +|corey-digicert|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||||||| +|cryptonext||TA: ❌
CA: ❌
EE: ❌|||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|entrust|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| |isi-wolfssl||||||||||||| -|kris|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|openca|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|oqs-gnutls||||||||||||| -|oqs-openssl111|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|oqs-provider|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|kris|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|openca|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|oqs-gnutls|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-openssl111|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|oqs-provider|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|||||| # Falcon-512 (1.3.9999.3.6) @@ -627,69 +627,69 @@ Rows are producers. Columns are parsers. |-|bc|botan|carl-redhound|corey-digicert|cryptonext|entrust|isi-wolfssl|kris|openca|oqs-gnutls|oqs-openssl111|oqs-provider| | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | -|bc||||||||||||| -|botan||||||||||||| -|carl-redhound||||||||||||| -|corey-digicert||||||||||||| -|cryptonext||TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅|||||| -|entrust||||||||||||| +|bc|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|botan|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|carl-redhound|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|corey-digicert|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|cryptonext||TA: ❌
CA: ❌
EE: ❌|||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅|||||| +|entrust|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| |isi-wolfssl||||||||||||| -|kris||||||||||||| -|openca||||||||||||| -|oqs-gnutls||||||||||||| -|oqs-openssl111||||||||||||| -|oqs-provider||||||||||||| +|kris|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|openca|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-gnutls|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-openssl111|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-provider|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| # sphincsshake192fsimple (1.3.9999.6.8.3) |-|bc|botan|carl-redhound|corey-digicert|cryptonext|entrust|isi-wolfssl|kris|openca|oqs-gnutls|oqs-openssl111|oqs-provider| | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | -|bc||||||||||||| -|botan||||||||||||| -|carl-redhound||||||||||||| -|corey-digicert||||||||||||| -|cryptonext||TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅|||||| -|entrust||||||||||||| +|bc|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|botan|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|carl-redhound|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|corey-digicert|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|cryptonext||TA: ❌
CA: ❌
EE: ❌|||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅|||||| +|entrust|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| |isi-wolfssl||||||||||||| -|kris||||||||||||| -|openca||||||||||||| -|oqs-gnutls||||||||||||| -|oqs-openssl111||||||||||||| -|oqs-provider||||||||||||| +|kris|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|openca|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-gnutls|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-openssl111|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-provider|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| # sphincsshake256fsimple (1.3.9999.6.9.3) |-|bc|botan|carl-redhound|corey-digicert|cryptonext|entrust|isi-wolfssl|kris|openca|oqs-gnutls|oqs-openssl111|oqs-provider| | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | -|bc||||||||||||| -|botan||||||||||||| -|carl-redhound||||||||||||| -|corey-digicert||||||||||||| -|cryptonext||TA: ❌
CA: ❌
EE: ❌||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅|||||| -|entrust||||||||||||| +|bc|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|botan|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|carl-redhound|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|corey-digicert|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|cryptonext||TA: ❌
CA: ❌
EE: ❌|||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅|||||| +|entrust|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| |isi-wolfssl||||||||||||| -|kris||||||||||||| -|openca||||||||||||| -|oqs-gnutls||||||||||||| -|oqs-openssl111||||||||||||| -|oqs-provider||||||||||||| +|kris|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|openca|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-gnutls|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-openssl111|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-provider|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| # COMPOSITE-KEY (2.16.840.1.114027.80.4.1) |-|bc|botan|carl-redhound|corey-digicert|cryptonext|entrust|isi-wolfssl|kris|openca|oqs-gnutls|oqs-openssl111|oqs-provider| | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | -|bc||TA: ❌
CA: ❌
EE: ❌||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||TA: ❌
CA: ❌|||||| -|botan||||||||||||| -|carl-redhound||||||||||||| -|corey-digicert|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌|||||| -|cryptonext||TA: ❌
CA: ❌
EE: ❌||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌||TA: ❌
CA: ❌
EE: ❌|TA: ❌
CA: ❌
EE: ❌|||||| -|entrust|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||||||| +|bc||TA: ❌
CA: ❌
EE: ❌||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌||TA: ❌
CA: ❌|||||| +|botan|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|carl-redhound|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|corey-digicert|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅|TA: ❌
CA: ❌
EE: ❌|||||| +|cryptonext||TA: ❌
CA: ❌
EE: ❌||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌|TA: ❌
CA: ❌
EE: ❌|||||| +|entrust|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||TA: ✅
CA: ✅
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ❌
CRL CA: ❌|TA: ✅
CA: ✅
EE: ✅
CRL TA: ✅
CRL CA: ✅||||||| |isi-wolfssl||||||||||||| -|kris||||||||||||| -|openca|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||TA: ❌
CA: ❌
EE: ❌|||||| -|oqs-gnutls||||||||||||| -|oqs-openssl111||||||||||||| -|oqs-provider||||||||||||| +|kris|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|openca|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌||TA: ❌
CA: ❌
EE: ❌|||||| +|oqs-gnutls|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-openssl111|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| +|oqs-provider|||||TA: ❌
CA: ❌
EE: ❌
CRL TA: ❌
CRL CA: ❌|||||||| # COMPOSITE_KEY_HASH_N_SIGN (2.16.840.1.114027.80.4.1.2) diff --git a/providers/oqs/Makefile b/providers/oqs/Makefile index a47a15e6..a4f55068 100644 --- a/providers/oqs/Makefile +++ b/providers/oqs/Makefile @@ -8,7 +8,7 @@ PROVIDER_NAME := OQS # Directories for (possibly) multiple products # supported by the same provider # DIRS := ... -DIRS := openssl111 oqsprovider +DIRS := oqsprovider # Script for Generating the artifacts (if any) GEN_SCRIPT := ./gen.sh @@ -113,10 +113,12 @@ cross_verify: requirements/verify @if [ -f "$(VERIFY_SCRIPT)" ] ; then \ echo && echo "[ $(PROVIDER_NAME) ] Cross Verifying Artifacts:" ; \ echo > "$(VERIFY_LOGFILE)" ; \ - for i in ../* ; do \ - echo " - $$i" ; \ - result=`cd "$$i" && make verify 2>&1 > "$(VERIFY_LOGFILE)" ` ; \ - done ; \ + ${VERIFY_SCRIPT} ../bc/java-artifacts 2>&1 > compatMatrices/bc_$(PROVIDER_NAME) ; \ + ${VERIFY_SCRIPT} ../botan/default 2>&1 > compatMatrices/botan_$(PROVIDER_NAME) ; \ + ${VERIFY_SCRIPT} ../cryptonext/default 2>&1 > compatMatrices/cryptonext_$(PROVIDER_NAME) ; \ + ${VERIFY_SCRIPT} ../corey-digicert/default 2>&1 > compatMatrices/corey-digicert_$(PROVIDER_NAME); \ + ${VERIFY_SCRIPT} ../entrust/default 2>&1 > compatMatrices/entrust_$(PROVIDER_NAME) ; \ + ${VERIFY_SCRIPT} oqsprovider 2>&1 > compatMatrices/oqsprovider_$(PROVIDER_NAME) ; \ echo "[ $(PROVIDER_NAME) ] Done (Ok)." && echo; \ fi @@ -125,8 +127,8 @@ clean: @rm -rf generate_log.txt verify_log.txt @for i in $(DIRS) ; do \ rm -rf $$i/artifacts ; \ - rm -rf $$i/1.3.6* ; \ + rm -rf $$i/1.3.* ; \ done distclean: clean - @rm -rf logs \ No newline at end of file + @rm -rf logs diff --git a/providers/oqs/README.md b/providers/oqs/README.md new file mode 100644 index 00000000..7f0a1944 --- /dev/null +++ b/providers/oqs/README.md @@ -0,0 +1,30 @@ +# OQS + +The scripts in this setup can be executed if [oqsprovider](https://github.com/open-quantum-safe/oqs-provider) is run with the latest [openssl](https://github.com/openssl/openssl). + +A docker image is available to facilitate that: [openquantumsafe/oqs-ossl3:interop](https://hub.docker.com/repository/docker/openquantumsafe/oqs-ossl3/general) contains the latest, complete set of QSC algorithms available for this testing. + +## Sample execution + + docker run -v `pwd`:/opt/ietf -it openquantumsafe/oqs-ossl3:interop bash + +opens a shell in which the `gen.sh` and `check.sh` scripts can be run with the `oqsprovider`+`liboqs`+`openssl` setup described above active. + +### Creating artifacts + + cd /opt/ietf/providers/oqs && ./gen.sh + +(or `make generate`) creates the data as required for interop testing in the "oqsprovider/artifacts" directory. + +### Checking artifacts + + cd /opt/ietf/providers/oqs && ./check.sh oqsprovider + +(or `make verify`) checks the data generating a CSV report for correctness/verify-ability of the artifacts created with the command above. + +### Cross-checking artifacts + +In order to check other implementation's artifacts, run `make cross_verify` (after suitably uncompressing the artifacts as documented, i.e., using `make unzip` in their respective directories) -- or run `./check.sh` passing the directory of the artifacts to be tested as a parameter, e.g. + + ./check.sh ../bc/java-artifacts/ + diff --git a/providers/oqs/ca.cnf b/providers/oqs/ca.cnf new file mode 100644 index 00000000..013a1178 --- /dev/null +++ b/providers/oqs/ca.cnf @@ -0,0 +1,70 @@ +[ ca ] # The default CA section +default_ca = CA_default # The default CA name + +[ CA_default ] # Default settings for the intermediate CA +dir = /root/oqsCA/intermediateCA # Intermediate CA directory +certs = $dir/certs # Certificates directory +crl_dir = $dir/crl # CRL directory +new_certs_dir = $dir/newcerts # New certificates directory +database = $dir/index.txt # Certificate index file +serial = $dir/serial # Serial number file +RANDFILE = $dir/private/.rand # Random number file +private_key = $dir/private/intermediate.key.pem # Intermediate CA private key +certificate = $dir/certs/intermediate.cert.pem # Intermediate CA certificate +crl = $dir/crl/intermediate.crl.pem # Intermediate CA CRL +crlnumber = $dir/crlnumber # Intermediate CA CRL number +crl_extensions = crl_ext # CRL extensions +default_crl_days = 30 # Default CRL validity days +default_md = sha256 # Default message digest +preserve = no # Preserve existing extensions +email_in_dn = no # Exclude email from the DN +name_opt = ca_default # Formatting options for names +cert_opt = ca_default # Certificate output options +policy = policy_loose # Certificate policy + +[ policy_loose ] # Policy for less strict validation +countryName = optional # Country is optional +stateOrProvinceName = optional # State or province is optional +localityName = optional # Locality is optional +organizationName = optional # Organization is optional +organizationalUnitName = optional # Organizational unit is optional +commonName = supplied # Must provide a common name +emailAddress = optional # Email address is optional + +[ req ] # Request settings +default_bits = 2048 # Default key size +distinguished_name = req_distinguished_name # Default DN template +string_mask = utf8only # UTF-8 encoding +default_md = sha256 # Default message digest +x509_extensions = v3_intermediate_ca # Extensions for intermediate CA certificate + +[ req_distinguished_name ] # Template for the DN in the CSR +countryName = CH +stateOrProvinceName = State or Province Name +localityName = Locality Name +0.organizationName = Organization Name +organizationalUnitName = Organizational Unit Name +commonName = Common Name +emailAddress = Email Address + +[ v3_intermediate_ca ] # Intermediate CA certificate extensions +subjectKeyIdentifier = hash # Subject key identifier +authorityKeyIdentifier = keyid:always,issuer # Authority key identifier +basicConstraints = critical, CA:true, pathlen:0 # Basic constraints for a CA +keyUsage = critical, digitalSignature, cRLSign, keyCertSign # Key usage for a CA + +[ crl_ext ] # CRL extensions +authorityKeyIdentifier=keyid:always # Authority key identifier + +[ server_cert ] # Server certificate extensions +basicConstraints = CA:FALSE # Not a CA certificate +nsCertType = server # Server certificate type +keyUsage = critical, digitalSignature, keyEncipherment # Key usage for a server cert +extendedKeyUsage = serverAuth # Extended key usage for server authentication purposes (e.g., TLS/SSL servers). +authorityKeyIdentifier = keyid,issuer # Authority key identifier linking the certificate to the issuer's public key. +authorityInfoAccess = OCSP;URI:http://ocsp.openquantumsafe.org + +[ ocsp ] +basicConstraints = CA:FALSE +keyUsage = nonRepudiation, digitalSignature, keyEncipherment +extendedKeyUsage = OCSPSigning diff --git a/providers/oqs/check.sh b/providers/oqs/check.sh index 23a0cec5..4488a1d7 100755 --- a/providers/oqs/check.sh +++ b/providers/oqs/check.sh @@ -1,5 +1,7 @@ #!/bin/bash +#set -x + function check_dir() { # We want to check that the needed structures @@ -10,21 +12,17 @@ function check_dir() { if ! [ -f "$DIR/ta/ta.pem" ]; then # Checks for the RootCA in DER format - if ! [ -f "$DIR/ta/ta.der" ] ; then - echo - echo "ERROR: missing $DIR/ta/ta.der file ... " - echo - exit 1; - fi - - # Providing the PEM version of the RootCA - echo "Converting $DIR/ta/ta.der to $DIR/ta/ta.pem ... " - openssl x509 -inform DER -in "$DIR/ta/ta.der" -out "$DIR/ta/ta.pem" - if [ $? -gt 0 ] ; then - echo - echo "ERROR: Cannot convert $DIR/ta/ta.der into PEM format" - echo - exit 1 + if [ -f "$DIR/ta/ta.der" ] ; then + + # Providing the PEM version of the RootCA + echo "Converting $DIR/ta/ta.der to $DIR/ta/ta.pem ... " + openssl x509 -inform DER -in "$DIR/ta/ta.der" -out "$DIR/ta/ta.pem" + if [ $? -gt 0 ] ; then + echo + echo "ERROR: Cannot convert $DIR/ta/ta.der into PEM format" + echo + exit 1 + fi fi fi @@ -33,122 +31,163 @@ function check_dir() { if ! [ -f "$DIR/ca/ca.pem" ]; then # Checks for the RootCA in DER format - if ! [ -f "$DIR/ca/ca.der" ] ; then - echo - echo "ERROR: missing $DIR/ca/ca.der file ... " - echo - exit 1; - fi - - # Converts the DER into PEM - openssl x509 -inform DER -in "$DIR/ca/ca.der" -out "$DIR/ca/ca.pem" - if [ $? -gt 0 ] ; then - echo - echo "ERROR: Cannot convert $DIR/ta/ta.der into PEM format" - echo - exit 1 + if [ -f "$DIR/ca/ca.der" ] ; then + # Converts the DER into PEM + openssl x509 -inform DER -in "$DIR/ca/ca.der" -out "$DIR/ca/ca.pem" + if [ $? -gt 0 ] ; then + echo + echo "ERROR: Cannot convert $DIR/ca/ca.der into PEM format" + echo + exit 1 + fi fi fi + + # Checks if we have the PEM version of the + # EE cert + if ! [ -f "$DIR/ee/cert.pem" ]; then + # Checks for the EE cert in DER format + if [ -f "$DIR/ee/cert.der" ] ; then + # Converts the DER into PEM + openssl x509 -inform DER -in "$DIR/ee/cert.der" -out "$DIR/ee/cert.pem" + if [ $? -gt 0 ] ; then + echo + echo "ERROR: Cannot convert $DIR/ee/cert.der into PEM format" + echo + exit 1 + fi + fi + fi + } check() { # Extracts the argument DIR=$1 + result="" # Change directory if ! [ -d "$DIR" ] ; then - echo "ERROR: missing dir $DIR" - exit 1; + #echo "ERROR: missing dir $DIR" + echo "N,N,N,N,N,N" + return fi # Change Directory cd "$DIR" - # Generate PEM files if missing - if [ ! -f ta/ta.pem ]; then - openssl x509 -in ta/ta.der -out ta/ta.pem - fi - if [ ! -f ca/ca.pem ]; then - openssl x509 -in ca/ca.der -out ca/ca.pem - fi # Baseline test whether TA cert is well formed - openssl x509 -in ta/ta.pem -text -noout > /dev/null 2>&1 + openssl x509 -in ta/ta.pem -text -noout 2>/dev/null > /dev/null + if [ $? -ne 0 ]; then + #echo "No suitable ta/ta.pem found." + echo "N,N,N,N,N,N" + return + fi + # Baseline test whether TA cert is self-signed + openssl verify -CAfile ta/ta.pem ta/ta.pem 2>/dev/null >/dev/null if [ $? -ne 0 ]; then - echo "No suitable ta/ta.pem found. Exiting $1." + #echo "ta/ta.pem not self-signed." + echo "N,N,N,N,N,N" return fi # Checking for some parsing errors - openssl x509 -in ta/ta.pem -text -noout | grep error + openssl x509 -in ta/ta.pem -text -noout | grep error 2>/dev/null > /dev/null if [ $? -ne 0 ]; then - echo "No error parsing TA certificate in $1"; + #echo "No error parsing TA certificate in $1"; # Extracting algorithm name - openssl x509 -in ta/ta.pem -text -noout | grep "Public Key Algorithm" + openssl x509 -in ta/ta.pem -text -noout | grep "Public Key Algorithm" 2>&1 > /dev/null + if [ $? -ne 0 ]; then + echo "N,N,N,N,N,N" + return + fi # Verifying cert chain TA->CA - openssl verify -CAfile ta/ta.pem ca/ca.pem + openssl verify -CAfile ta/ta.pem ca/ca.pem 2>/dev/null >/dev/null if [ $? -ne 0 ]; then - echo "Error verifying $1/ca/ca.pem" - exit -1 - else - echo "cert chain TA->CA verified for $1" + #echo "Error verifying $1/ca/ca.pem" + echo "Y,N,N,N,N,N" + return + #else + # echo "cert chain TA->CA verified for $1" fi else - echo "Error parsing TA certificate in $1" + #echo "Error parsing TA certificate in $1" + echo "N,N,N,N,N,N" + return fi - echo "--------------" + # From this point on we know TA & CA are OK, so we collect specific test results + ee_csr="N" + ta_crl="N" + ca_crl="N" + + # Now check EE + # First create cert chain + cat ca/ca.pem ta/ta.pem > ca-chain.pem + # then verify + openssl verify -CAfile ca-chain.pem ee/cert.pem 2>/dev/null > /dev/null + if [ $? -ne 0 ]; then + #echo "Error verifying $1/ee/cert.pem" + ee_crt="N" + else + ee_crt="Y" + fi + + if [ -f ee/cert.csr ]; then + # EE CSR check + openssl req -verify -in ee/cert.csr 2>/dev/null > /dev/null + if [ $? -eq 0 ]; then + ee_csr="Y" + fi + fi + + if [ -f crl/crl_ta.crl ]; then + # TA CRL check + openssl crl -verify -in crl/crl_ta.crl -CAfile ta/ta.pem 2>/dev/null >/dev/null + if [ $? -eq 0 ]; then + ta_crl="Y" + fi + fi + + if [ -f crl/crl_ca.crl ]; then + # CA CRL check + openssl crl -verify -in crl/crl_ca.crl -CAfile ca-chain.pem 2>/dev/null >/dev/null + if [ $? -eq 0 ]; then + ca_crl="Y" + fi + fi + + # TODO: How to check OCSP artifact(s)?? + + echo "Y,Y,${ee_crt},${ee_csr},${ta_crl},${ca_crl}" cd .. } -# Checks for the input -# List of Sub Directories -SUBDIRS="oqsprovider" - -# Checks for the input -if ! [ "x$1" = "x" ] ; then - EXT_PREFIX=$1 -else - # if parameter not present, self-test - EXT_PREFIX="." -fi - -# Checks each directory -for sd in ${SUBDIRS}; do - if [ $sd == "oqsprovider" ]; then - # check openssl actually supports providers - openssl list --providers 2>&1 | grep oqsprovider > /dev/null - if [ $? -ne 0 ]; then - echo "oqsprovider not available" - continue - fi + if [ $# -ne 1 ]; then + echo "No target directory to check provided. Exiting." + exit -1 + else + pushd $1 >/dev/null 2>/dev/null fi - - echo "Checking in ${sd}" - cd $sd/artifacts + #echo "Checking in $(pwd)" + if [ ! -d "artifacts" ]; then + echo "No artifacts found. Exiting." + exit -1 + fi + cd artifacts + echo "key_algorithm_oid,ta,ca,ee,csr,crl_ta,crl_ca" for oid_folder in *; do - target=${oid_folder} - if [ $EXT_PREFIX == "." ]; then - dir=$EXT_PREFIX - else - dir=../../$EXT_PREFIX - fi + target=${oid_folder} - # Executing the Check Script - if [ -d "${dir}" ] ; then - cd "${dir}" && echo "${oid_folder}:" \ - && check_dir "${target}" && check "${target}" - if [ $? -ne 0 ]; then - echo "Failure testing $EXT_PREFIX. Exiting." - exit -1 - else - echo "Successfully tested $dir/$target" - fi - else - echo "Directory $dir not found. Exiting test." - exit -1 - fi + # Executing the Check Script + check_dir "${target}" + if [ $? -ne 0 ]; then + echo "${target},N,N,N,N,N,N" + else + result=$(check "${target}") + echo "${target},${result}" + fi done -done -echo "All tests passed successfully" + popd 2>/dev/null >/dev/null diff --git a/providers/oqs/compatMatrices/bc_OQS b/providers/oqs/compatMatrices/bc_OQS new file mode 100644 index 00000000..1be80d32 --- /dev/null +++ b/providers/oqs/compatMatrices/bc_OQS @@ -0,0 +1,11 @@ +key_algorithm_oid,ta,ca,ee,csr,crl_ta,crl_ca +1.2.840.10045.4.3.2,N,N,N,N,N,N +1.3.6.1.4.1.2.267.11.4.4,N,N,N,N,N,N +1.3.6.1.4.1.2.267.11.6.5,N,N,N,N,N,N +1.3.6.1.4.1.2.267.11.8.7,N,N,N,N,N,N +1.3.6.1.4.1.2.267.7.4.4,Y,Y,Y,Y,Y,Y +1.3.6.1.4.1.2.267.7.6.5,Y,Y,Y,Y,Y,Y +1.3.6.1.4.1.2.267.7.8.7,Y,Y,Y,Y,Y,Y +1.3.9999.3.1,N,N,N,N,N,N +1.3.9999.3.4,N,N,N,N,N,N +2.16.840.1.114027.80.4.1,N,N,N,N,N,N diff --git a/providers/oqs/compatMatrices/botan_OQS b/providers/oqs/compatMatrices/botan_OQS new file mode 100644 index 00000000..6c7a8053 --- /dev/null +++ b/providers/oqs/compatMatrices/botan_OQS @@ -0,0 +1,7 @@ +key_algorithm_oid,ta,ca,ee,csr,crl_ta,crl_ca +1.3.6.1.4.1.2.267.11.4.4,N,N,N,N,N,N +1.3.6.1.4.1.2.267.11.6.5,N,N,N,N,N,N +1.3.6.1.4.1.2.267.11.8.7,N,N,N,N,N,N +1.3.6.1.4.1.2.267.7.4.4,N,N,N,N,N,N +1.3.6.1.4.1.2.267.7.6.5,N,N,N,N,N,N +1.3.6.1.4.1.2.267.7.8.7,N,N,N,N,N,N diff --git a/providers/oqs/compatMatrices/corey-digicert_OQS b/providers/oqs/compatMatrices/corey-digicert_OQS new file mode 100644 index 00000000..fecf2ea7 --- /dev/null +++ b/providers/oqs/compatMatrices/corey-digicert_OQS @@ -0,0 +1,17 @@ +key_algorithm_oid,ta,ca,ee,csr,crl_ta,crl_ca +1.2.840.10045.2.1,Y,Y,Y,N,Y,Y +1.3.6.1.4.1.2.267.7.4.4,Y,Y,Y,N,Y,Y +1.3.6.1.4.1.2.267.7.6.5,Y,Y,Y,N,Y,Y +1.3.6.1.4.1.2.267.7.8.7,Y,Y,Y,N,Y,Y +1.3.9999.3.6,Y,Y,Y,N,Y,Y +1.3.9999.3.9,Y,Y,Y,N,Y,Y +2.16.840.1.114027.80.4.1,N,N,N,N,N,N +2.16.840.1.114027.80.5.1,N,N,N,N,N,N +base,Y,Y,Y,Y,Y,Y +chameleon-base,Y,Y,Y,Y,Y,Y +chameleon-delta,Y,Y,Y,N,Y,Y +chameleon-extracted-delta,Y,Y,Y,N,Y,Y +delta,Y,Y,Y,N,Y,Y +extracted,Y,Y,Y,N,Y,Y +hybrid,Y,N,N,N,N,N +hybrid-catalyst,Y,N,N,N,N,N diff --git a/providers/oqs/compatMatrices/cryptonext_OQS b/providers/oqs/compatMatrices/cryptonext_OQS new file mode 100644 index 00000000..843f31b1 --- /dev/null +++ b/providers/oqs/compatMatrices/cryptonext_OQS @@ -0,0 +1,15 @@ +key_algorithm_oid,ta,ca,ee,csr,crl_ta,crl_ca +1.2.840.10045.2.1,Y,Y,Y,Y,N,N +1.3.6.1.4.1.2.267.7.4.4,N,N,N,N,N,N +1.3.6.1.4.1.2.267.7.6.5,N,N,N,N,N,N +1.3.6.1.4.1.2.267.7.8.7,N,N,N,N,N,N +1.3.6.1.4.1.22554.5.6.1,N,N,N,N,N,N +1.3.6.1.4.1.22554.5.6.2,N,N,N,N,N,N +1.3.6.1.4.1.22554.5.6.3,N,N,N,N,N,N +1.3.9999.3.1,N,N,N,N,N,N +1.3.9999.3.4,N,N,N,N,N,N +1.3.9999.6.7.4,N,N,N,N,N,N +1.3.9999.6.8.3,N,N,N,N,N,N +1.3.9999.6.9.3,N,N,N,N,N,N +2.16.840.1.114027.80.4.1,N,N,N,N,N,N +2.16.840.1.114027.80.4.1.2,N,N,N,N,N,N diff --git a/providers/oqs/compatMatrices/entrust_OQS b/providers/oqs/compatMatrices/entrust_OQS new file mode 100644 index 00000000..b46c637f --- /dev/null +++ b/providers/oqs/compatMatrices/entrust_OQS @@ -0,0 +1,30 @@ +key_algorithm_oid,ta,ca,ee,csr,crl_ta,crl_ca +1.3.6.1.4.1.2.267.11.4.4,N,N,N,N,N,N +1.3.6.1.4.1.2.267.11.6.5,N,N,N,N,N,N +1.3.6.1.4.1.2.267.11.8.7,N,N,N,N,N,N +1.3.6.1.4.1.2.267.7.4.4,N,N,N,N,N,N +1.3.6.1.4.1.2.267.7.6.5,N,N,N,N,N,N +1.3.6.1.4.1.2.267.7.8.7,N,N,N,N,N,N +1.3.9999.3.1,N,N,N,N,N,N +1.3.9999.3.4,N,N,N,N,N,N +1.3.9999.6.4.1,N,N,N,N,N,N +1.3.9999.6.4.10,N,N,N,N,N,N +1.3.9999.6.4.4,N,N,N,N,N,N +1.3.9999.6.4.7,N,N,N,N,N,N +1.3.9999.6.5.1,N,N,N,N,N,N +1.3.9999.6.5.3,N,N,N,N,N,N +1.3.9999.6.5.5,N,N,N,N,N,N +1.3.9999.6.5.7,N,N,N,N,N,N +1.3.9999.6.6.1,N,N,N,N,N,N +1.3.9999.6.6.3,N,N,N,N,N,N +1.3.9999.6.6.5,N,N,N,N,N,N +1.3.9999.6.6.7,N,N,N,N,N,N +2.16.840.1.114027.80.4.1,N,N,N,N,N,N +2.16.840.1.114027.80.5.1.1,N,N,N,N,N,N +2.16.840.1.114027.80.5.1.14,N,N,N,N,N,N +2.16.840.1.114027.80.5.1.2,N,N,N,N,N,N +2.16.840.1.114027.80.5.1.3,N,N,N,N,N,N +2.16.840.1.114027.80.5.1.5,N,N,N,N,N,N +2.16.840.1.114027.80.5.1.6,N,N,N,N,N,N +2.16.840.1.114027.80.5.1.8,N,N,N,N,N,N +2.16.840.1.114027.80.5.1.9,N,N,N,N,N,N diff --git a/providers/oqs/compatMatrices/oqsprovider_OQS b/providers/oqs/compatMatrices/oqsprovider_OQS new file mode 100644 index 00000000..c2cccfda --- /dev/null +++ b/providers/oqs/compatMatrices/oqsprovider_OQS @@ -0,0 +1,19 @@ +key_algorithm_oid,ta,ca,ee,csr,crl_ta,crl_ca +1.3.101.113,Y,Y,Y,Y,Y,Y +1.3.6.1.4.1.2.267.7.4.4,Y,Y,Y,Y,Y,Y +1.3.6.1.4.1.2.267.7.6.5,Y,Y,Y,Y,Y,Y +1.3.6.1.4.1.2.267.7.8.7,Y,Y,Y,Y,Y,Y +1.3.9999.3.6,Y,Y,Y,Y,Y,Y +1.3.9999.3.9,Y,Y,Y,Y,Y,Y +1.3.9999.6.4.13,Y,Y,Y,Y,Y,Y +1.3.9999.6.4.16,Y,Y,Y,Y,Y,Y +1.3.9999.6.5.10,Y,Y,Y,Y,Y,Y +1.3.9999.6.5.12,Y,Y,Y,Y,Y,Y +1.3.9999.6.6.10,Y,Y,Y,Y,Y,Y +1.3.9999.6.6.12,Y,Y,Y,Y,Y,Y +1.3.9999.6.7.13,Y,Y,Y,Y,Y,Y +1.3.9999.6.7.16,Y,Y,Y,Y,Y,Y +1.3.9999.6.8.10,Y,Y,Y,Y,Y,Y +1.3.9999.6.8.12,Y,Y,Y,Y,Y,Y +1.3.9999.6.9.10,Y,Y,Y,Y,Y,Y +1.3.9999.6.9.12,Y,Y,Y,Y,Y,Y diff --git a/providers/oqs/ee.cnf b/providers/oqs/ee.cnf new file mode 100644 index 00000000..efb0eb4b --- /dev/null +++ b/providers/oqs/ee.cnf @@ -0,0 +1,232 @@ +# +# OpenSSL example configuration file. +# See doc/man5/config.pod for more info. +# +# This is mostly being used for generation of certificate requests, +# but may be used for auto loading of providers + +# Note that you can include other files from the main configuration +# file using the .include directive. +#.include filename + +# This definition stops the following lines choking if HOME isn't +# defined. +HOME = . +DEFAULT_GROUPS = kyber768 + +# Use this in order to automatically load providers. +openssl_conf = openssl_init + +[openssl_init] +providers = provider_sect +ssl_conf = ssl_sect + +[ssl_sect] +system_default = system_default_sect + +[system_default_sect] +Groups = $ENV::DEFAULT_GROUPS + + +# List of providers to load +[provider_sect] +default = default_sect +oqsprovider = oqsprovider_sect + +[default_sect] +activate = 1 +[oqsprovider_sect] +activate = 1 + +# activate = 1 + + +#################################################################### +[ ca ] +default_ca = CA_default # The default ca section + +#################################################################### +[ CA_default ] + +dir = ./demoCA # Where everything is kept +certs = $dir/certs # Where the issued certs are kept +crl_dir = $dir/crl # Where the issued crl are kept +database = $dir/index.txt # database index file. +#unique_subject = no # Set to 'no' to allow creation of + # several certs with same subject. +new_certs_dir = $dir/newcerts # default place for new certs. + +certificate = $dir/cacert.pem # The CA certificate +serial = $dir/serial # The current serial number +crlnumber = $dir/crlnumber # the current crl number + # must be commented out to leave a V1 CRL +crl = $dir/crl.pem # The current CRL +private_key = $dir/private/cakey.pem # The private key + +x509_extensions = usr_cert # The extensions to add to the cert + +# Comment out the following two lines for the "traditional" +# (and highly broken) format. +name_opt = ca_default # Subject Name options +cert_opt = ca_default # Certificate field options + +# Extension copying option: use with caution. +# copy_extensions = copy + +# Extensions to add to a CRL. Note: Netscape communicator chokes on V2 CRLs +# so this is commented out by default to leave a V1 CRL. +# crlnumber must also be commented out to leave a V1 CRL. +# crl_extensions = crl_ext + +default_days = 365 # how long to certify for +default_crl_days= 30 # how long before next CRL +default_md = default # use public key default MD +preserve = no # keep passed DN ordering + +# A few difference way of specifying how similar the request should look +# For type CA, the listed attributes must be the same, and the optional +# and supplied fields are just that :-) +policy = policy_match + +# For the CA policy +[ policy_match ] +countryName = match +stateOrProvinceName = match +organizationName = match +organizationalUnitName = optional +commonName = supplied +emailAddress = optional + +# For the 'anything' policy +# At this point in time, you must list all acceptable 'object' +# types. +[ policy_anything ] +countryName = optional +stateOrProvinceName = optional +localityName = optional +organizationName = optional +organizationalUnitName = optional +commonName = supplied +emailAddress = optional + +#################################################################### +[ req ] +default_bits = 2048 +default_keyfile = privkey.pem +distinguished_name = req_distinguished_name +attributes = req_attributes +x509_extensions = v3_ca # The extensions to add to the self signed cert + +string_mask = utf8only + +#req_extensions = v3_req # The extensions to add to a certificate request + +[ req_distinguished_name ] +countryName = Country Name (2 letter code) +countryName_default = AU +countryName_min = 2 +countryName_max = 2 + +stateOrProvinceName = State or Province Name (full name) +stateOrProvinceName_default = Some-State + +localityName = Locality Name (eg, city) + +0.organizationName = Organization Name (eg, company) +0.organizationName_default = Internet Widgits Pty Ltd + +# we can do this but it is not needed normally :-) +#1.organizationName = Second Organization Name (eg, company) +#1.organizationName_default = World Wide Web Pty Ltd + +organizationalUnitName = Organizational Unit Name (eg, section) +#organizationalUnitName_default = + +commonName = Common Name (e.g. server FQDN or YOUR name) +commonName_max = 64 + +emailAddress = Email Address +emailAddress_max = 64 + +# SET-ex3 = SET extension number 3 + +[ req_attributes ] +challengePassword = A challenge password +challengePassword_min = 4 +challengePassword_max = 20 + +unstructuredName = An optional company name + +[ usr_cert ] + +# These extensions are added when 'ca' signs a request. + +# This goes against PKIX guidelines but some CAs do it and some software +# requires this to avoid interpreting an end user certificate as a CA. + +basicConstraints=CA:FALSE + +# This is typical in keyUsage for a client certificate. +# keyUsage = nonRepudiation, digitalSignature, keyEncipherment + +# PKIX recommendations harmless if included in all certificates. +subjectKeyIdentifier=hash +authorityKeyIdentifier=keyid,issuer + +# This stuff is for subjectAltName and issuerAltname. +# Import the email address. +# subjectAltName=email:copy +# An alternative to produce certificates that aren't +# deprecated according to PKIX. +# subjectAltName=email:move + +# Copy subject details +# issuerAltName=issuer:copy + +# This is required for TSA certificates. +# extendedKeyUsage = critical,timeStamping + +[ v3_req ] + +# Extensions to add to a certificate request + +basicConstraints = CA:FALSE +keyUsage = nonRepudiation, digitalSignature, keyEncipherment + +[ v3_ca ] + + +# Extensions for a typical CA + + +# PKIX recommendation. + +subjectKeyIdentifier=hash + +authorityKeyIdentifier=keyid:always,issuer + +basicConstraints = critical,CA:true,pathlen:1 + +# Key usage: this is typical for a CA certificate. However since it will +# prevent it being used as an test self-signed certificate it is best +# left out by default. +keyUsage = cRLSign, keyCertSign + +# Include email address in subject alt name: another PKIX recommendation +# subjectAltName=email:copy +# Copy issuer details +# issuerAltName=issuer:copy + +# DER hex encoding of an extension: beware experts only! +# obj=DER:02:03 +# Where 'obj' is a standard or added object +# You can even override a supported extension: +# basicConstraints= critical, DER:30:03:01:01:FF + +[ crl_ext ] + +# CRL extensions. +# Only issuerAltName and authorityKeyIdentifier make any sense in a CRL. + +# issuerAltName=issuer:copy +authorityKeyIdentifier=keyid:always diff --git a/providers/oqs/gen.sh b/providers/oqs/gen.sh index d1736c26..8064b253 100755 --- a/providers/oqs/gen.sh +++ b/providers/oqs/gen.sh @@ -1,26 +1,57 @@ #!/bin/bash +set -e + # be sure to not add wrapped pubkeys: unset DRAFT_MASSIMO_LAMPS_PQ_SIG_CERTIFICATES_00 -gen_dirs() { - - local dir - # Generates the internal directories - # An argument is expected for the name of - # the OID/Parent directory - _BASE_DIR=$1 - - # Creates the Main Dir - [ -d "$_BASE_DIR" ] || mkdir -p "$_BASE_DIR" - - # Default folders - SUBDIRS="ta ca ee crl ocsp" - - # Creates the Directory and the SubDirs - for dir in ${SUBDIRS} ; do - mkdir -p "${_BASE_DIR}/${dir}" - done +# Parameter1: Name of algorithm to create a CA hierarchy for +# Parameter2: Directory containing cnf files +do_cas() { + # clean up: + rm -rf ~/oqsCA + # Prepare persistent data structures + # For rootCA (TA) + mkdir -p ~/oqsCA/rootCA/{certs,crl,newcerts,private,csr} + echo 1000 > ~/oqsCA/rootCA/serial + echo 0100 > ~/oqsCA/rootCA/crlnumber + touch ~/oqsCA/rootCA/index.txt + + # For intermediate CA (CA) + mkdir -p ~/oqsCA/intermediateCA/{certs,crl,newcerts,private,csr} + echo 1000 > ~/oqsCA/intermediateCA/serial + echo 0100 > ~/oqsCA/intermediateCA/crlnumber + touch ~/oqsCA/intermediateCA/index.txt + + # Create TA keys and cert + openssl req -x509 -config $2/ta.cnf -new -newkey $1 -extensions v3_ca -keyout ~/oqsCA/rootCA/private/ca.key.pem -out ~/oqsCA/rootCA/certs/ca.cert.pem -nodes -subj "/CN=OQS TA" + + # Create CA keys and cert + openssl req -config $2/ca.cnf -new -newkey $1 -keyout ~/oqsCA/intermediateCA/private/intermediate.key.pem -out ~/oqsCA/intermediateCA/certs/intermediate.csr.pem -nodes -subj "/CN=OQS CA" + openssl ca -batch -config $2/ta.cnf -extensions v3_intermediate_ca -days 365 -notext -in ~/oqsCA/intermediateCA/certs/intermediate.csr.pem -out ~/oqsCA/intermediateCA/certs/intermediate.cert.pem + chmod 444 ~/oqsCA/intermediateCA/certs/intermediate.cert.pem + openssl verify -CAfile ~/oqsCA/rootCA/certs/ca.cert.pem ~/oqsCA/intermediateCA/certs/intermediate.cert.pem + + # Create cert bundle for EE cert verification + cat ~/oqsCA/intermediateCA/certs/intermediate.cert.pem ~/oqsCA/rootCA/certs/ca.cert.pem > ~/oqsCA/intermediateCA/certs/ca-chain.cert.pem + openssl verify -CAfile ~/oqsCA/intermediateCA/certs/ca-chain.cert.pem ~/oqsCA/intermediateCA/certs/intermediate.cert.pem + + # Create server keys and cert (EE) + openssl req -config $2/ca.cnf -new -newkey $1 -keyout ~/oqsCA/intermediateCA/private/ee.key.pem -out ~/oqsCA/intermediateCA/csr/ee.csr.pem -nodes -subj "/CN=OQS EE" + openssl ca -batch -config $2/ca.cnf -extensions server_cert -days 375 -notext -in ~/oqsCA/intermediateCA/csr/ee.csr.pem -out ~/oqsCA/intermediateCA/certs/ee.cert.pem + + # Verify server cert + openssl verify -CAfile ~/oqsCA/intermediateCA/certs/ca-chain.cert.pem ~/oqsCA/intermediateCA/certs/ee.cert.pem + # Revoke cert + openssl ca -batch -config $2/ca.cnf -revoke ~/oqsCA/intermediateCA/certs/ee.cert.pem + + # Create CRLS for TA and CA + openssl ca -batch -config $2/ca.cnf -gencrl -out ~/oqsCA/intermediateCA/crl/intermediate.crl.pem + openssl ca -batch -config $2/ta.cnf -gencrl -out ~/oqsCA/rootCA/crl/root.crl.pem + + # Create OSCP keys and cert + openssl req -config $2/ca.cnf -new -newkey $1 -keyout ~/oqsCA/intermediateCA/private/ocsp.key.pem -out ~/oqsCA/intermediateCA/csr/ocsp.csr.pem -nodes -subj "/CN=ocsp.openquantumsafe.org" + openssl ca -batch -config $2/ca.cnf -extensions ocsp -days 375 -notext -in ~/oqsCA/intermediateCA/csr/ocsp.csr.pem -out ~/oqsCA/intermediateCA/certs/ocsp.cert.pem } gen() { @@ -32,154 +63,85 @@ gen() { # ocsp/ directories. ALGORITHM=$1 BASE_DIR=$2 - - # Generates the directories - gen_dirs "$BASE_DIR" - - # Change to the newly created directory - cd "$BASE_DIR" - echo "Operating in $(pwd)" - - # Root/TA: - # ======== - - # Generate key pair - openssl req -x509 -new -newkey $1 -keyout ta/ta_priv.pem -out ta/ta.pem -nodes -subj "/CN=TA" - if [ $? -ne 0 ]; then - echo "Failure to generate TA key pair" - exit -1 - fi + ROOT_DIR=$3 + + do_cas $ALGORITHM $ROOT_DIR + # Generates the artifact directories + mkdir -p $BASE_DIR/{ta,ca,ee,crl,ocsp} + + # Extract the artifacts to the correct locations + + # TA: + cp ~/oqsCA/rootCA/certs/ca.cert.pem $BASE_DIR/ta/ta.pem + cp ~/oqsCA/rootCA/private/ca.key.pem $BASE_DIR/ta/ta_priv.pem + # Also generate DER for private key - openssl pkcs8 -topk8 -inform PEM -outform DER -in ta/ta_priv.pem -out ta/ta_priv.der -nocrypt - if [ $? -ne 0 ]; then - echo "Failure to generate TA private key DER" - exit -1 - fi + openssl pkcs8 -topk8 -inform PEM -outform DER -in $BASE_DIR/ta/ta_priv.pem -out $BASE_DIR/ta/ta_priv.der -nocrypt # Also generate cert in DER - openssl x509 -in ta/ta.pem -out ta/ta.der -outform DER - if [ $? -ne 0 ]; then - echo "Failure to generate TA cert DER" - exit -1 - fi - - # Intermediate CA: - # ================ - - # Generate key pair in PEM format - openssl req -new -newkey $1 -keyout ca/ca_priv.pem -out ca/ca.csr -nodes -subj "/CN=CA" - if [ $? -ne 0 ]; then - echo "Failure to generate CA key pair" - exit -1 - fi + openssl x509 -in $BASE_DIR/ta/ta.pem -out $BASE_DIR/ta/ta.der -outform DER + + # CA: + cp ~/oqsCA/intermediateCA/certs/intermediate.cert.pem $BASE_DIR/ca/ca.pem + cp ~/oqsCA/intermediateCA/private/intermediate.key.pem $BASE_DIR/ca/ca_priv.pem + # Also generate DER for private key - openssl pkcs8 -topk8 -inform PEM -outform DER -in ca/ca_priv.pem -out ca/ca_priv.der -nocrypt - if [ $? -ne 0 ]; then - echo "Failure to generate CA key DER" - exit -1 - fi - # Generate CSR in PEM - openssl x509 -req -in ca/ca.csr -out ca/ca.pem -CA ta/ta.pem -CAkey ta/ta_priv.pem -CAcreateserial -days 365 - if [ $? -ne 0 ]; then - echo "Failure to generate CA CSR" - exit -1 - fi - # Generate cert in DER format - openssl x509 -outform der -req -in ca/ca.csr -out ca/ca.der -CA ta/ta.pem -CAkey ta/ta_priv.pem -CAcreateserial -days 365 - if [ $? -ne 0 ]; then - echo "Failure to generate CA cert" - exit -1 - fi - # Also generate cert in PEM format - openssl x509 -req -in ca/ca.csr -out ca/ca.pem -CA ta/ta.pem -CAkey ta/ta_priv.pem -CAcreateserial -days 365 - if [ $? -ne 0 ]; then - echo "Failure to generate CA PEM" - exit -1 - fi - - # End Entity cert: - # ================ - - # Generate key pair in PEM format - openssl req -new -newkey $1 -keyout ee/cert_priv.pem -out ee/cert.csr -nodes -subj "/CN=EE" - if [ $? -ne 0 ]; then - echo "Failure to generate EE key pair" - exit -1 - fi + openssl pkcs8 -topk8 -inform PEM -outform DER -in $BASE_DIR/ca/ca_priv.pem -out $BASE_DIR/ca/ca_priv.der -nocrypt + # Also generate cert in DER + openssl x509 -in $BASE_DIR/ca/ca.pem -out $BASE_DIR/ca/ca.der -outform DER + + # EE: + cp ~/oqsCA/intermediateCA/certs/ee.cert.pem $BASE_DIR/ee/cert.pem + cp ~/oqsCA/intermediateCA/private/ee.key.pem $BASE_DIR/ee/cert_priv.pem + cp ~/oqsCA/intermediateCA/csr/ee.csr.pem $BASE_DIR/ee/cert.csr + # Also generate DER for private key - openssl pkcs8 -topk8 -inform PEM -outform DER -in ee/cert_priv.pem -out ee/cert_priv.der -nocrypt - if [ $? -ne 0 ]; then - echo "Failure to generate EE privkey PEM" - exit -1 - fi - # Generate CSR in PEM - openssl x509 -req -in ee/cert.csr -out ee/cert.pem -CA ca/ca.pem -CAkey ca/ca_priv.pem -CAcreateserial -days 365 - if [ $? -ne 0 ]; then - echo "Failure to generate EE CSR" - exit -1 - fi - # Generate cert in DER format - openssl x509 -outform der -req -in ee/cert.csr -out ee/cert.der -CA ca/ca.pem -CAkey ca/ca_priv.pem -CAcreateserial -days 365 - if [ $? -ne 0 ]; then - echo "Failure to generate EE cert" - exit -1 - fi - # Also generate cert in PEM format - openssl x509 -req -in ee/cert.csr -out ee/cert.pem -CA ca/ca.pem -CAkey ca/ca_priv.pem -CAcreateserial -days 365 - if [ $? -ne 0 ]; then - echo "Failure to generate EE PEM" - exit -1 - fi - - cd .. + openssl pkcs8 -topk8 -inform PEM -outform DER -in $BASE_DIR/ee/cert_priv.pem -out $BASE_DIR/ee/cert_priv.der -nocrypt + # Also generate cert in DER + openssl x509 -in $BASE_DIR/ee/cert.pem -out $BASE_DIR/ee/cert.der -outform DER + + # CRLs + openssl crl -inform PEM -in ~/oqsCA/rootCA/crl/root.crl.pem -outform DER -out $BASE_DIR/crl/crl_ta.crl + openssl crl -inform PEM -in ~/oqsCA/intermediateCA/crl/intermediate.crl.pem -outform DER -out $BASE_DIR/crl/crl_ca.crl + + # Start OCSP responder and retrieve response + openssl ocsp -port 2560 -text -index ~/oqsCA/intermediateCA/index.txt -CA ~/oqsCA/intermediateCA/certs/ca-chain.cert.pem -rkey ~/oqsCA/intermediateCA/private/ocsp.key.pem -rsigner ~/oqsCA/intermediateCA/certs/ocsp.cert.pem -nrequest 1 & + sleep 1 + openssl ocsp -CAfile ~/oqsCA/intermediateCA/certs/ca-chain.cert.pem -url http://127.0.0.1:2560 -respout $BASE_DIR/ocsp/ocsp_cert.der -issuer ~/oqsCA/intermediateCA/certs/intermediate.cert.pem -cert ~/oqsCA/intermediateCA/certs/ee.cert.pem } runandlog() { - cd $1/artifacts && gen $2 $3 >> ../../log 2>&1 && cd ../.. + cd oqsprovider/artifacts && gen $1 $2 ../.. >> ../../log 2>&1 && cd ../.. + echo "$1 done..." } - -rm -rf log -# Sub folders for the provider -SUBDIRS="oqsprovider" - -for dir in ${SUBDIRS} ; do - - if [ $dir == "oqsprovider" ]; then - # check openssl actually supports providers - openssl list --providers | grep oqsprovider > /dev/null - if [ $? -ne 0 ]; then - echo "oqsprovider not available" - continue - fi - fi - # Generates the LibPKI directory - [ -d "${dir}" ] || mkdir -p "${dir}" - [ -d "${dir}/artifacts" ] || mkdir -p "${dir}/artifacts" - - # Classic/baseline test: - gen ed448 1.3.101.113 >> log 2>&1 + + rm -rf log + + mkdir -p oqsprovider/artifacts + + # Classic/baseline test: + runandlog ed448 1.3.101.113 # Dilithium - runandlog ${dir} dilithium2 1.3.6.1.4.1.2.267.7.4.4 - runandlog ${dir} dilithium3 1.3.6.1.4.1.2.267.7.6.5 - runandlog ${dir} dilithium5 1.3.6.1.4.1.2.267.7.8.7 + runandlog dilithium2 1.3.6.1.4.1.2.267.7.4.4 + runandlog dilithium3 1.3.6.1.4.1.2.267.7.6.5 + runandlog dilithium5 1.3.6.1.4.1.2.267.7.8.7 # Falcon - runandlog ${dir} falcon512 1.3.9999.3.6 - runandlog ${dir} falcon1024 1.3.9999.3.9 + runandlog falcon512 1.3.9999.3.6 + runandlog falcon1024 1.3.9999.3.9 # Sphincs+ - runandlog ${dir} sphincssha2128fsimple 1.3.9999.6.4.13 - runandlog ${dir} sphincssha2128ssimple 1.3.9999.6.4.16 - runandlog ${dir} sphincssha2192fsimple 1.3.9999.6.5.10 - runandlog ${dir} sphincssha2192ssimple 1.3.9999.6.5.12 - runandlog ${dir} sphincssha2256fsimple 1.3.9999.6.6.10 - runandlog ${dir} sphincssha2256ssimple 1.3.9999.6.6.12 - runandlog ${dir} sphincsshake128fsimple 1.3.9999.6.7.13 - runandlog ${dir} sphincsshake128ssimple 1.3.9999.6.7.16 - runandlog ${dir} sphincsshake192fsimple 1.3.9999.6.8.10 - runandlog ${dir} sphincsshake192ssimple 1.3.9999.6.8.12 - runandlog ${dir} sphincsshake256fsimple 1.3.9999.6.9.10 - runandlog ${dir} sphincsshake256ssimple 1.3.9999.6.9.12 - -done + runandlog sphincssha2128fsimple 1.3.9999.6.4.13 + runandlog sphincssha2128ssimple 1.3.9999.6.4.16 + runandlog sphincssha2192fsimple 1.3.9999.6.5.10 + runandlog sphincssha2192ssimple 1.3.9999.6.5.12 + runandlog sphincssha2256fsimple 1.3.9999.6.6.10 + runandlog sphincssha2256ssimple 1.3.9999.6.6.12 + runandlog sphincsshake128fsimple 1.3.9999.6.7.13 + runandlog sphincsshake128ssimple 1.3.9999.6.7.16 + runandlog sphincsshake192fsimple 1.3.9999.6.8.10 + runandlog sphincsshake192ssimple 1.3.9999.6.8.12 + runandlog sphincsshake256fsimple 1.3.9999.6.9.10 + runandlog sphincsshake256ssimple 1.3.9999.6.9.12 + echo "All data successfully generated." diff --git a/providers/oqs/openssl111/artifacts.zip b/providers/oqs/openssl111/artifacts-ietf115.zip similarity index 100% rename from providers/oqs/openssl111/artifacts.zip rename to providers/oqs/openssl111/artifacts-ietf115.zip diff --git a/providers/oqs/oqsprovider/artifacts-ietf115.zip b/providers/oqs/oqsprovider/artifacts-ietf115.zip new file mode 100644 index 00000000..632a96f9 Binary files /dev/null and b/providers/oqs/oqsprovider/artifacts-ietf115.zip differ diff --git a/providers/oqs/oqsprovider/artifacts-ietf116-qsc-encoding.zip b/providers/oqs/oqsprovider/artifacts-ietf116-qsc-encoding.zip new file mode 100644 index 00000000..d11c628f Binary files /dev/null and b/providers/oqs/oqsprovider/artifacts-ietf116-qsc-encoding.zip differ diff --git a/providers/oqs/oqsprovider/artifacts-oqs-encoding-ietf116.zip b/providers/oqs/oqsprovider/artifacts-ietf116.zip similarity index 100% rename from providers/oqs/oqsprovider/artifacts-oqs-encoding-ietf116.zip rename to providers/oqs/oqsprovider/artifacts-ietf116.zip diff --git a/providers/oqs/oqsprovider/artifacts-ietf117.tgz b/providers/oqs/oqsprovider/artifacts-ietf117.tgz deleted file mode 100644 index 04fb50a0..00000000 Binary files a/providers/oqs/oqsprovider/artifacts-ietf117.tgz and /dev/null differ diff --git a/providers/oqs/oqsprovider/artifacts-ietf117.zip b/providers/oqs/oqsprovider/artifacts-ietf117.zip new file mode 100644 index 00000000..2f6faf7f Binary files /dev/null and b/providers/oqs/oqsprovider/artifacts-ietf117.zip differ diff --git a/providers/oqs/oqsprovider/artifacts.zip b/providers/oqs/oqsprovider/artifacts.zip index 632a96f9..b746e8d3 100644 Binary files a/providers/oqs/oqsprovider/artifacts.zip and b/providers/oqs/oqsprovider/artifacts.zip differ diff --git a/providers/oqs/ta.cnf b/providers/oqs/ta.cnf new file mode 100644 index 00000000..ba3eabb0 --- /dev/null +++ b/providers/oqs/ta.cnf @@ -0,0 +1,63 @@ +[ ca ] # The default CA section +default_ca = CA_default # The default CA name + +[ CA_default ] # Default settings for the CA +dir = /root/oqsCA/rootCA # CA directory +certs = $dir/certs # Certificates directory +crl_dir = $dir/crl # CRL directory +new_certs_dir = $dir/newcerts # New certificates directory +database = $dir/index.txt # Certificate index file +serial = $dir/serial # Serial number file +RANDFILE = $dir/private/.rand # Random number file +private_key = $dir/private/ca.key.pem # Root CA private key +certificate = $dir/certs/ca.cert.pem # Root CA certificate +crl = $dir/crl/ca.crl.pem # Root CA CRL +crlnumber = $dir/crlnumber # Root CA CRL number +crl_extensions = crl_ext # CRL extensions +default_crl_days = 30 # Default CRL validity days +default_md = sha256 # Default message digest +preserve = no # Preserve existing extensions +email_in_dn = no # Exclude email from the DN +name_opt = ca_default # Formatting options for names +cert_opt = ca_default # Certificate output options +policy = policy_strict # Certificate policy +unique_subject = no # Allow multiple certs with the same DN + +[ policy_strict ] # Policy for stricter validation +countryName = optional # Must match the issuer's country +stateOrProvinceName = optional # Must match the issuer's state +organizationName = optional # Must match the issuer's organization +organizationalUnitName = optional # Organizational unit is optional +commonName = supplied # Must provide a common name +emailAddress = optional # Email address is optional + +[ req ] # Request settings +default_bits = 2048 # Default key size +distinguished_name = req_distinguished_name # Default DN template +string_mask = utf8only # UTF-8 encoding +default_md = sha256 # Default message digest +prompt = no # Non-interactive mode + +[ req_distinguished_name ] # Template for the DN in the CSR +countryName = Country Name (2 letter code) +stateOrProvinceName = State or Province Name (full name) +localityName = Locality Name (city) +0.organizationName = Organization Name (company) +organizationalUnitName = Organizational Unit Name (section) +commonName = Common Name (your domain) +emailAddress = Email Address + +[ v3_ca ] # Root CA certificate extensions +subjectKeyIdentifier = hash # Subject key identifier +authorityKeyIdentifier = keyid:always,issuer # Authority key identifier +basicConstraints = critical, CA:true, pathlen:1 # Basic constraints for a CA +keyUsage = critical, keyCertSign, cRLSign # Key usage for a CA + +[ crl_ext ] # CRL extensions +authorityKeyIdentifier = keyid:always,issuer # Authority key identifier + +[ v3_intermediate_ca ] +subjectKeyIdentifier = hash +authorityKeyIdentifier = keyid:always,issuer +basicConstraints = critical, CA:true, pathlen:0 +keyUsage = critical, digitalSignature, cRLSign, keyCertSign