Definition

Key establishment creates shared key material. Certificate-based authentication establishes peer identity through separate keys, signatures and trust-chain checks. Evidence for one role does not establish the properties of the other.

Read the cryptographic roles separately

TLS separates key establishment from authentication. ML-KEM is a key-encapsulation mechanism, not a certificate-signing algorithm. Observing a PQ component in key establishment therefore does not establish a PQ certificate or handshake signature.

PropertyWhat to record
Negotiated key-establishment groupExact observed identifier, handshake method and timestamp
Certificate public keySubject key algorithm, key size or parameter set
Certificate signatureIssuer signature algorithm for each presented certificate
Handshake authenticationObserved signature scheme, or unknown when not collected
Symmetric protectionNegotiated cipher suite, without inferring the key exchange from its name
Official sourcesNIST FIPS 203: ML-KEM ↗

Example: a hybrid group and a classical certificate

Consider a hypothetical endpoint whose report records a hybrid key-establishment group and an RSA certificate public key. The useful conclusion is that this particular connection used the recorded group while the presented certificate retained a classical key. It is not a contradiction, and it is not an end-to-end quantum-safety guarantee.

The certificate's issuer signature is another property. It must not be substituted for the handshake signature scheme. If a scanner does not collect the latter, report unknown rather than deriving it from a certificate field.

  • Keep the example separate from real customer observations.
  • Attach exact evidence and confidence to each property.
  • Do not treat an advertised group as a negotiated group.
  • Do not turn one successful connection into complete endpoint capability.

How to use a public exposure report

Start with a hostname you are authorized to assess. Review the selected service, inspection time, negotiated parameters and presented chain. Then read coverage: unsupported or untested properties are as important as the successful observations.

Cipher Discovery's bounded public scan is a starting point for external exposure analysis, not internal infrastructure discovery. Certificate migration verification compares supported certificate expectations against newer evidence; it does not automatically verify every PQ authentication or key-establishment requirement.

Run an authorized public scan →Inspect public cryptographic observations and their exact coverage.Review discovery methodology →Understand observed, inferred and unknown evidence states.

Frequently asked questions

Does an RSA certificate rule out hybrid key exchange?

No. Certificate authentication and negotiated key establishment are separate roles. Inspect evidence for both.

Does a hybrid handshake prove PQ authentication?

No. Review certificate-chain and handshake-signature evidence separately, retaining unknowns when not collected.

Is a PQ algorithm label enough for migration verification?

No. Verification needs an explicit expectation, newer evidence, exact scope and a clear distinction between observed and untested properties.