OpenSSL Studio
Interactive OpenSSL v3.6.3 environment running entirely in your browser via WebAssembly. Educational use only — not a FIPS-validated module; the pending FIPS 140-3 validation submission covers the OpenSSL 3.5.4 provider (2025), not the 3.6.x line.
Interactive OpenSSL v3.6.3 environment running entirely in your browser via WebAssembly. Educational use only — not a FIPS-validated module; the pending FIPS 140-3 validation submission covers the OpenSSL 3.5.4 provider (2025), not the 3.6.x line.
What this means for you
- Executive / Business Leader
- This is a hands-on engineering tool — a real OpenSSL 3.6.3 running in your browser, not a FIPS-validated module; the banner at the top links you to the Compliance landscape and Migration framework instead.
- GRC / Risk & Compliance
- The header states plainly that this build is educational and not FIPS-validated; the Explore tab's "Query this build" lists which providers are self-reported versus actually verified, and the banner links to the Compliance landscape.
- Developer / Engineer
- The "Quick jump" strip drops you straight into genpkey, req, x509, dgst, kem or enc on the Workbench tab — the same binary and flags you would put in a script; "Recent Commands" keeps what you ran.
- Security Architect
- The Learn tab walks from a first keypair through certificates, key establishment without classical exchange, and packaging keys for the real world; the Workbench tab then runs each step against real files.
- Researcher / Academic
- The "Related specs" strip links ML-KEM, ML-DSA, TLS 1.3, PKCS#12 and X.509 to their source documents; on the Explore tab, "Query this build" lists the algorithms and providers this exact binary reports.
- Certification & Validation Engineer
- The header states that this build is educational and not FIPS-validated; on the Explore tab, "Query this build" lists which providers are self-reported and which are actually verified.
- IT Ops / DevOps
- The "Rotation & inspection" strip is a rotation rehearsal — genpkey to mint the new key, req for the CSR, x509 to inspect issuer, expiry and algorithm, pkcs12 to bundle key and chain; nothing touches your estate.
- Curious Explorer
- A banner names the roles this page is built for; the Learn tab starts with "Your first keypair — classical, then post-quantum", and the Workbench terminal offers one-click starters such as "Check OpenSSL version".
Your first keypair — classical, then post-quantum
genpkey generates both eras of key with the same command shape — only the -algorithm value changes. Watch what changes (and what stays the same) between an RSA-2048 key and an ML-DSA-65 key.
ML-DSA (FIPS 204) and ML-KEM (FIPS 203) have been native in OpenSSL's default provider since 3.5 (this Studio runs 3.6.3) — no external provider needed. The PQC variant name (e.g. ml-dsa-65) IS the -algorithm value; it is not a -pkeyopt. That trips up first-time users coming from RSA, where key size is a separate -pkeyopt.
Steps
genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out learn-l1-rsa.key
1. Generate a classical RSA-2048 private key
genpkey -algorithm ML-DSA-65 -out learn-l1-mldsa.key
2. Generate a post-quantum ML-DSA-65 private key
Try it
Which OpenSSL command generates an ML-DSA-65 private key — a post-quantum signature key?
Related content
Next step
More hands-on toolsThe Playground holds the other in-browser tools, grouped by what each one exercises.