KMIP Control Plane
What this means for you
- Executive / Business Leader
- In the guided view, the Learn tab opens with "Crypto agility in three steps" — set the policy, watch a request be refused, watch the estate rekey; the Dev tab is not shown for your role.
- GRC / Risk & Compliance
- On the Policy tab, "Which regime governs you?" loads a policy by regulator — US · NSA CNSA 2.0, US · FIPS 140-3, Germany · BSI — and the Inspect tab's Activity trail records every allow, deny or rekey decision.
- Developer / Engineer
- The Dev tab is a pipeline builder with Builder and Code views, a "Corpus (OASIS conformance)" palette, Run, and "Export .py"; switch View to expert and Inspect adds a "KMIP Wire" view of the TTLV bytes.
- Security Architect
- On Operate, "Plane 2 · KMIP Lifecycle" sends a real KMIP 3.0 request per button, with the algorithm set to "Auto — let the policy decide" or a named set; the Policy tab's Compare and Timeline ("As of" slider) show rules over time.
- Researcher / Academic
- The "CSD02" chip states that KMIP 3.0 is an OASIS committee draft, not a ratified standard; in expert view the Policy tab adds a YAML view of the exact rules and Inspect adds the raw "KMIP Wire" response.
- Certification & Validation Engineer
- On the Policy tab, "Which regime governs you?" includes US · FIPS 140-3; KMIP 3.0 is an OASIS committee draft (the "CSD02" chip), so nothing here is a validated configuration.
- IT Ops / DevOps
- The "Migration Estate" tab asks for keys by business label and lets the policy pick the algorithm; move from classical to hybrid to full PQC and "Key objects on this engine" shows rekeyed successors linked to deactivated predecessors.
- Curious Explorer
- Keep View on "guided" and press "Guided Tour" for step-by-step lessons; everything runs in this tab — no server, no Docker.
A real KMIP 3.0 control plane + PKCS#11 HSM, compiled to WebAssembly and running entirely in this tab — no server, no Docker. Every operation is a genuine KMIP request answered by the same Rust engine the appliance ships.
In scopecontrol plane + key management at rest · TLS handshake & persistence → full Docker sandbox
Spec statusKMIP 3.0 is an OASIS committee draft (CSD02, May 2026), not yet a ratified Standard —
Why crypto-agility, not just "post-quantum"
Data encrypted today with classical algorithms can be harvested now and decrypted later, once a cryptographically-relevant quantum computer exists — harvest-now, decrypt-later. The fix isn't swapping in a PQC algorithm once; it's a control plane that can migrate keys again whenever the roadmap changes, with no flag day and no application code change. Everything below is that idea made hands-on — flip the policy strip and watch the same request behave differently.
Want the full-fidelity version with TLS transport and the REST control plane? Run the real pqctoday-kmip server from the Docker sandbox.
Related content
Next step
Run the KMIP control planeThe control-plane tool runs KMIP 3.0 operations against a live key store, step by step.