Key establishment creates shared key material. Certificate-based authentication establishes peer identity through separate keys, signatures and trust-chain checks. Evidence for one role does not establish the properties of the other.
Read the cryptographic roles separately
TLS separates key establishment from authentication. ML-KEM is a key-encapsulation mechanism, not a certificate-signing algorithm. Observing a PQ component in key establishment therefore does not establish a PQ certificate or handshake signature.
| Property | What to record |
|---|---|
| Negotiated key-establishment group | Exact observed identifier, handshake method and timestamp |
| Certificate public key | Subject key algorithm, key size or parameter set |
| Certificate signature | Issuer signature algorithm for each presented certificate |
| Handshake authentication | Observed signature scheme, or unknown when not collected |
| Symmetric protection | Negotiated cipher suite, without inferring the key exchange from its name |
Example: a hybrid group and a classical certificate
Consider a hypothetical endpoint whose report records a hybrid key-establishment group and an RSA certificate public key. The useful conclusion is that this particular connection used the recorded group while the presented certificate retained a classical key. It is not a contradiction, and it is not an end-to-end quantum-safety guarantee.
The certificate's issuer signature is another property. It must not be substituted for the handshake signature scheme. If a scanner does not collect the latter, report unknown rather than deriving it from a certificate field.
- Keep the example separate from real customer observations.
- Attach exact evidence and confidence to each property.
- Do not treat an advertised group as a negotiated group.
- Do not turn one successful connection into complete endpoint capability.
How to use a public exposure report
Start with a hostname you are authorized to assess. Review the selected service, inspection time, negotiated parameters and presented chain. Then read coverage: unsupported or untested properties are as important as the successful observations.
Cipher Discovery's bounded public scan is a starting point for external exposure analysis, not internal infrastructure discovery. Certificate migration verification compares supported certificate expectations against newer evidence; it does not automatically verify every PQ authentication or key-establishment requirement.
Frequently asked questions
Does an RSA certificate rule out hybrid key exchange?
No. Certificate authentication and negotiated key establishment are separate roles. Inspect evidence for both.
Does a hybrid handshake prove PQ authentication?
No. Review certificate-chain and handshake-signature evidence separately, retaining unknowns when not collected.
Is a PQ algorithm label enough for migration verification?
No. Verification needs an explicit expectation, newer evidence, exact scope and a clear distinction between observed and untested properties.