HSM / PKCS#11 / KMIP Control Plane
What you will do: Load a policy (Classical, PQC or auto-migrate-on-use), pick an algorithm or Auto — let the policy decide, then step through Create, Activate, Sign, Verify and Revoke on an in-browser KMIP 3.0 engine and WebAssembly HSM.
Worked example: Create an ECDSA-P256 signing key under Classical, switch to auto-migrate-on-use and press Sign: the result shows policy: Rekey → ML-DSA-65 as the legacy key is superseded, and Inspect records every step.
Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.
For your role
- Developer / Engineer
- Take the Guided Tour's ten steps in the Learn tab, from Provisioning a key through Certificate Services, then switch to Operate and Dev: every operation is a genuine KMIP 3.0 request answered by the Rust engine, and Inspect decodes the response tree.
- Security Architect
- Open the Policy tab, change one line of the Permissive (default) policy's algorithm disposition, and watch Operate switch operations from RSA-3072 to ML-DSA-65: crypto agility as a policy decision rather than a code change, with the Migration Estate tab showing which labels move.
- Researcher / Academic
- The spec status banner says KMIP 3.0 is an OASIS committee draft (CSD02); step 9, An honest HSM, lets you check that Destroy scrubs, read-only refuses and Locate filters, and Inspect shows the raw protocol version and correlation values.
KMIP Control Plane
What this means for you
- Executive / Business Leader
- In the guided view, the Learn tab opens with "Crypto agility in three steps" — set the policy, watch a request be refused, watch the estate rekey; the Dev tab is not shown for your role.
- GRC / Risk & Compliance
- On the Policy tab, "Which regime governs you?" loads a policy by regulator — US · NSA CNSA 2.0, US · FIPS 140-3, Germany · BSI — and the Inspect tab's Activity trail records every allow, deny or rekey decision.
- Developer / Engineer
- The Dev tab is a pipeline builder with Builder and Code views, a "Corpus (OASIS conformance)" palette, Run, and "Export .py"; switch View to expert and Inspect adds a "KMIP Wire" view of the TTLV bytes.
- Security Architect
- On Operate, "Plane 2 · KMIP Lifecycle" sends a real KMIP 3.0 request per button, with the algorithm set to "Auto — let the policy decide" or a named set; the Policy tab's Compare and Timeline ("As of" slider) show rules over time.
- Researcher / Academic
- The "CSD02" chip states that KMIP 3.0 is an OASIS committee draft, not a ratified standard; in expert view the Policy tab adds a YAML view of the exact rules and Inspect adds the raw "KMIP Wire" response.
- Certification & Validation Engineer
- On the Policy tab, "Which regime governs you?" includes US · FIPS 140-3; KMIP 3.0 is an OASIS committee draft (the "CSD02" chip), so nothing here is a validated configuration.
- IT Ops / DevOps
- The "Migration Estate" tab asks for keys by business label and lets the policy pick the algorithm; move from classical to hybrid to full PQC and "Key objects on this engine" shows rekeyed successors linked to deactivated predecessors.
- Curious Explorer
- Keep View on "guided" and press "Guided Tour" for step-by-step lessons; everything runs in this tab — no server, no Docker.
A real KMIP 3.0 control plane + PKCS#11 HSM, compiled to WebAssembly and running entirely in this tab — no server, no Docker. Every operation is a genuine KMIP request answered by the same Rust engine the appliance ships.
In scopecontrol plane + key management at rest · TLS handshake & persistence → full Docker sandbox
Spec statusKMIP 3.0 is an OASIS committee draft (CSD02, May 2026), not yet a ratified Standard —
Why crypto-agility, not just "post-quantum"
Data encrypted today with classical algorithms can be harvested now and decrypted later, once a cryptographically-relevant quantum computer exists — harvest-now, decrypt-later. The fix isn't swapping in a PQC algorithm once; it's a control plane that can migrate keys again whenever the roadmap changes, with no flag day and no application code change. Everything below is that idea made hands-on — flip the policy strip and watch the same request behave differently.
Want the full-fidelity version with TLS transport and the REST control plane? Run the real pqctoday-kmip server from the Docker sandbox.
Try it
In the Policy tab, change the disposition for RSA-3072. Where do you see the effect?
Next step
Put it in your reportYour readiness report is where the results of the Playground tools become recommendations.
Related content
Next in HSM / PKCS#11