Priority 3 - For existing PKI infrastructures
Target audience: PKI Administrators, Security Architects
Strategies and runbooks for migrating from classic to post-quantum-capable PKI infrastructures.
| Path | Description | Risk | Duration |
| —— | ————- | —— | ———- |
| Classic → Hybrid | Gradual migration with backward compatibility | Low | 6-12 months |
| Parallel Operation | Two PKIs simultaneously | Medium | 3-6 months |
| Big Bang | Complete switchover | High | 1-3 months |
| Scenario | Description | Risk |
|---|---|---|
| Classic -> Hybrid | Migrate RSA/ECDSA to hybrid mode | Medium |
| Parallel Operation | Operate classic + PQ simultaneously | Low |
| Rollback Strategy | Plan and test emergency fallback | - |
| Certificate Inventory | Inventory of all certificates | Low |
| Component | Requirement |
| ———– | ————- |
| OpenSSL | 3.6+ (PQ support) |
| Clients | Hybrid-capable TLS stacks |
| HSM | PQ algorithms supported |
| Monitoring | Dual-mode alerting |
« <- Operator Scenarios | -> Classic -> Hybrid »
Wolfgang van der Stille @ EMSR DATA d.o.o. - Post-Quantum Cryptography Professional