OpenSSL Studio

Interactive OpenSSL v3.6.3 environment running entirely in your browser via WebAssembly. Educational use only — not a FIPS-validated module; the pending FIPS 140-3 validation submission covers the OpenSSL 3.5.4 provider (2025), not the 3.6.x line.

What this means for you

Executive / Business Leader
This is a hands-on engineering tool — a real OpenSSL 3.6.3 running in your browser, not a FIPS-validated module; the banner at the top links you to the Compliance landscape and Migration framework instead.
GRC / Risk & Compliance
The header states plainly that this build is educational and not FIPS-validated; the Explore tab's "Query this build" lists which providers are self-reported versus actually verified, and the banner links to the Compliance landscape.
Developer / Engineer
The "Quick jump" strip drops you straight into genpkey, req, x509, dgst, kem or enc on the Workbench tab — the same binary and flags you would put in a script; "Recent Commands" keeps what you ran.
Security Architect
The Learn tab walks from a first keypair through certificates, key establishment without classical exchange, and packaging keys for the real world; the Workbench tab then runs each step against real files.
Researcher / Academic
The "Related specs" strip links ML-KEM, ML-DSA, TLS 1.3, PKCS#12 and X.509 to their source documents; on the Explore tab, "Query this build" lists the algorithms and providers this exact binary reports.
Certification & Validation Engineer
The header states that this build is educational and not FIPS-validated; on the Explore tab, "Query this build" lists which providers are self-reported and which are actually verified.
IT Ops / DevOps
The "Rotation & inspection" strip is a rotation rehearsal — genpkey to mint the new key, req for the CSR, x509 to inspect issuer, expiry and algorithm, pkcs12 to bundle key and chain; nothing touches your estate.
Curious Explorer
A banner names the roles this page is built for; the Learn tab starts with "Your first keypair — classical, then post-quantum", and the Workbench terminal offers one-click starters such as "Check OpenSSL version".
Best experienced on desktop — scroll down for terminal and file manager.
Core

Your first keypair — classical, then post-quantum

genpkey generates both eras of key with the same command shape — only the -algorithm value changes. Watch what changes (and what stays the same) between an RSA-2048 key and an ML-DSA-65 key.

ML-DSA (FIPS 204) and ML-KEM (FIPS 203) have been native in OpenSSL's default provider since 3.5 (this Studio runs 3.6.3) — no external provider needed. The PQC variant name (e.g. ml-dsa-65) IS the -algorithm value; it is not a -pkeyopt. That trips up first-time users coming from RSA, where key size is a separate -pkeyopt.

Steps

  1. genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out learn-l1-rsa.key

    1. Generate a classical RSA-2048 private key

  2. genpkey -algorithm ML-DSA-65 -out learn-l1-mldsa.key

    2. Generate a post-quantum ML-DSA-65 private key

Try it

Which OpenSSL command generates an ML-DSA-65 private key — a post-quantum signature key?

Next step

More hands-on tools

The Playground holds the other in-browser tools, grouped by what each one exercises.