Back to DashboardProtocolsPhase 5 · Pilots & Migrationadvanced50 min

PKI Enrollment Protocols (EST & CMP)

RFC 7030 (EST) and RFC 9810 (CMP, obsoletes RFC 4210) — hands-on PQC certificate enrollment with real OpenSSL 3.6 WASM crypto + an in-browser mock CA.

Why this matters: EST and CMP are how certificates actually get issued at scale in the real world — a PQC algorithm with no working enrollment protocol is a lab demo, not a deployable migration.

Start here: Pick an ML-DSA or ML-KEM parameter set and press Generate keypair: OpenSSL in the browser produces the end-entity key the CMP and EST enrollment steps use next, with the PEM available to inspect.

For your role

Developer / Engineer
EST (RFC 7030) and CMP (RFC 9810) enrollment with real OpenSSL 3.6 WASM crypto against an in-browser mock CA, including the KEM key update: the exchanges a client library implements.
Security Architect
The CMP KEM key update with an encrypted-certificate proof of possession is how enrollment works when the key cannot sign; the module shows both protocols against the same CA.
Researcher / Academic
Compare the EST and CMP enrollments of the same key against the RFCs, with the composite enrollment and certificate inspection steps the tool page defers to here.
IT Ops / DevOps
EST and CMP are how certificates get issued at scale; the module shows the requests and responses your enrollment endpoints will exchange with devices after the switch.
Practice in the Simulation

PKI Enrollment Protocols

When an end-entity needs an X.509 certificate, it doesn't just hand a self-signed key to the CA — the request is wrapped in a structured enrollment protocolthat carries the public key, attribute requests, proof-of-possession, and authentication. Two enrollment protocols matter for post-quantum PKI: EST (RFC 7030) and CMP (RFC 9810, July 2025, which obsoleted RFC 4210 and added certificate management for KEM keys).

EST — RFC 7030

Enrollment over Secure Transport — HTTPS-based, designed to be simple. Client POSTs a base64-encoded PKCS#10 CSR to /.well-known/est/simpleenroll; server returns a base64-encoded PKCS#7 degenerate SignedData containing the issued cert.

  • Transport: HTTPS (TLS 1.2+)
  • Request: PKCS#10 (Certification Request)
  • Response: PKCS#7 SignedData (single cert)
  • POP: signed CSR (works for ML-DSA; not for ML-KEM)
  • 2013 standard; PQC-aware only via inherited X.509 OIDs (no PQC-specific update)

CMP — RFC 4210 + RFC 9810

Certificate Management Protocol — richer state machine, supports initial request (ir), cert request (cr), key update (kur), revocation (rr), and more. RFC 9810 added KEM-specific proof-of-possession (encrCert POP) so ML-KEM keys can be enrolled even though they can't sign.

  • Transport: HTTP (application/pkixcmp, RFC 9811, obsoletes RFC 6712)
  • Request: CMP PKIMessage (CRMF inside)
  • Response: PKIMessage with CertResponse
  • POP: signature, encrCert (RFC 9810), or RA-verified
  • Active IETF track — EJBCA 9.1+ ships ML-DSA + ML-KEM via CMP

Why this matters for PQC

PQC migration adds two new requirements to enrollment:

  1. ML-DSA support. The CSR / CRMF must carry the new ML-DSA OIDs (RFC 9881) and the request must be signed under the new algorithm. EST handles this transparently via PKCS#10; CMP needs no protocol changes for pure-sig flows.
  2. ML-KEM enrollment. KEM keys can't sign the request, so signature-POP doesn't apply. RFC 9810 introduces encrCert POP: the CA encapsulates the new cert under the EE's KEM pubkey; the EE proves possession by decapsulating. EST has no KEM-aware update yet. (Checked 2026-08-22 against the three RFCs that update RFC 7030 — 8951, 8996 and 9908. RFC 9908, the most recent, clarifies CSR Attributes Response encoding and contains no mention of KEMs at all, so this still holds.)
  3. Composite enrollment. Hybrid PKI (one cert carrying both classical and PQC pubkeys) is currently a draft track — draft-ietf-lamps-pq-composite-sigs-19 and draft-ietf-lamps-pq-composite-kem. Both EST and CMP can carry composite requests once the OIDs stabilize.

Workshop tools

The Workshop tab drives real cryptographic operations in your browser using OpenSSL 3.6 WASM and our softHSM v3 (PKCS#11 v3.2). You'll:

  • Generate an ML-DSA-65 keypair (or ML-KEM-768) via OpenSSL genpkey
  • Send a real CMP Initial Request to an in-WASM mock CA
  • POST a PKCS#10 CSR through a simulated EST simpleenroll endpoint
  • Exercise ML-KEM encapsulation/decapsulation for the RFC 9810 KUR POP
  • Decode and chain-verify the issued certificate

Further reading

In the Industry Landscape

Check your understanding

5 questions on PKI Enrollment Protocols (EST & CMP), each with its answer and the reason.

Take the quiz

Next step

Practice it: PKI Enrollment (EST + CMP)

PKI Enrollment (EST + CMP) is the hands-on version of this module: the same ideas, run in your browser.

Learning module content can be inaccurate. Please double-check its information. Report inaccuracies in PQC Today GitHub Discussions.