PKI Enrollment Protocols (EST & CMP)
RFC 7030 (EST) and RFC 9810 (CMP, obsoletes RFC 4210) — hands-on PQC certificate enrollment with real OpenSSL 3.6 WASM crypto + an in-browser mock CA.
Why this matters: EST and CMP are how certificates actually get issued at scale in the real world — a PQC algorithm with no working enrollment protocol is a lab demo, not a deployable migration.
Start here: Pick an ML-DSA or ML-KEM parameter set and press Generate keypair: OpenSSL in the browser produces the end-entity key the CMP and EST enrollment steps use next, with the PEM available to inspect.
For your role
- Developer / Engineer
- EST (RFC 7030) and CMP (RFC 9810) enrollment with real OpenSSL 3.6 WASM crypto against an in-browser mock CA, including the KEM key update: the exchanges a client library implements.
- Security Architect
- The CMP KEM key update with an encrypted-certificate proof of possession is how enrollment works when the key cannot sign; the module shows both protocols against the same CA.
- Researcher / Academic
- Compare the EST and CMP enrollments of the same key against the RFCs, with the composite enrollment and certificate inspection steps the tool page defers to here.
- IT Ops / DevOps
- EST and CMP are how certificates get issued at scale; the module shows the requests and responses your enrollment endpoints will exchange with devices after the switch.
PKI Enrollment Protocols
When an end-entity needs an X.509 certificate, it doesn't just hand a self-signed key to the CA — the request is wrapped in a structured enrollment protocolthat carries the public key, attribute requests, proof-of-possession, and authentication. Two enrollment protocols matter for post-quantum PKI: EST (RFC 7030) and CMP (RFC 9810, July 2025, which obsoleted RFC 4210 and added certificate management for KEM keys).
EST — RFC 7030
Enrollment over Secure Transport — HTTPS-based, designed to be simple. Client POSTs a base64-encoded PKCS#10 CSR to /.well-known/est/simpleenroll; server returns a base64-encoded PKCS#7 degenerate SignedData containing the issued cert.
- Transport: HTTPS (TLS 1.2+)
- Request: PKCS#10 (Certification Request)
- Response: PKCS#7 SignedData (single cert)
- POP: signed CSR (works for ML-DSA; not for ML-KEM)
- 2013 standard; PQC-aware only via inherited X.509 OIDs (no PQC-specific update)
CMP — RFC 4210 + RFC 9810
Certificate Management Protocol — richer state machine, supports initial request (ir), cert request (cr), key update (kur), revocation (rr), and more. RFC 9810 added KEM-specific proof-of-possession (encrCert POP) so ML-KEM keys can be enrolled even though they can't sign.
- Transport: HTTP (application/pkixcmp, RFC 9811, obsoletes RFC 6712)
- Request: CMP PKIMessage (CRMF inside)
- Response: PKIMessage with CertResponse
- POP: signature, encrCert (RFC 9810), or RA-verified
- Active IETF track — EJBCA 9.1+ ships ML-DSA + ML-KEM via CMP
Why this matters for PQC
PQC migration adds two new requirements to enrollment:
- ML-DSA support. The CSR / CRMF must carry the new ML-DSA OIDs (RFC 9881) and the request must be signed under the new algorithm. EST handles this transparently via PKCS#10; CMP needs no protocol changes for pure-sig flows.
- ML-KEM enrollment. KEM keys can't sign the request, so signature-POP doesn't apply. RFC 9810 introduces encrCert POP: the CA encapsulates the new cert under the EE's KEM pubkey; the EE proves possession by decapsulating. EST has no KEM-aware update yet. (Checked 2026-08-22 against the three RFCs that update RFC 7030 — 8951, 8996 and 9908. RFC 9908, the most recent, clarifies CSR Attributes Response encoding and contains no mention of KEMs at all, so this still holds.)
- Composite enrollment. Hybrid PKI (one cert carrying both classical and PQC pubkeys) is currently a draft track —
draft-ietf-lamps-pq-composite-sigs-19anddraft-ietf-lamps-pq-composite-kem. Both EST and CMP can carry composite requests once the OIDs stabilize.
Workshop tools
The Workshop tab drives real cryptographic operations in your browser using OpenSSL 3.6 WASM and our softHSM v3 (PKCS#11 v3.2). You'll:
- Generate an ML-DSA-65 keypair (or ML-KEM-768) via OpenSSL
genpkey - Send a real CMP Initial Request to an in-WASM mock CA
- POST a PKCS#10 CSR through a simulated EST
simpleenrollendpoint - Exercise ML-KEM encapsulation/decapsulation for the RFC 9810 KUR POP
- Decode and chain-verify the issued certificate
Further reading
Related modules
- ACVP Lab Workflow: From Vector Set to EvidenceSame track · Protocols · Shares ML-KEM, ML-DSA, FIPS 203
- Aerospace PQCSame migration phase · Shares ML-DSA, ML-KEM, FIPS 203
- Healthcare PQCSame migration phase · Shares ML-DSA, ML-KEM, FIPS 203
- IoT & Embedded Device PQCSame migration phase · Shares ML-DSA, ML-KEM, FIPS 203
In the Industry Landscape
Check your understanding
5 questions on PKI Enrollment Protocols (EST & CMP), each with its answer and the reason.
Take the quizNext step
Practice it: PKI Enrollment (EST + CMP)PKI Enrollment (EST + CMP) is the hands-on version of this module: the same ideas, run in your browser.
Learning module content can be inaccurate. Please double-check its information. Report inaccuracies in PQC Today GitHub Discussions.