HSM / PKCS#11 / KMIP Control Plane

What you will do: Load a policy (Classical, PQC or auto-migrate-on-use), pick an algorithm or Auto — let the policy decide, then step through Create, Activate, Sign, Verify and Revoke on an in-browser KMIP 3.0 engine and WebAssembly HSM.

Worked example: Create an ECDSA-P256 signing key under Classical, switch to auto-migrate-on-use and press Sign: the result shows policy: Rekey → ML-DSA-65 as the legacy key is superseded, and Inspect records every step.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools

For your role

Developer / Engineer
Take the Guided Tour's ten steps in the Learn tab, from Provisioning a key through Certificate Services, then switch to Operate and Dev: every operation is a genuine KMIP 3.0 request answered by the Rust engine, and Inspect decodes the response tree.
Security Architect
Open the Policy tab, change one line of the Permissive (default) policy's algorithm disposition, and watch Operate switch operations from RSA-3072 to ML-DSA-65: crypto agility as a policy decision rather than a code change, with the Migration Estate tab showing which labels move.
Researcher / Academic
The spec status banner says KMIP 3.0 is an OASIS committee draft (CSD02); step 9, An honest HSM, lets you check that Destroy scrubs, read-only refuses and Locate filters, and Inspect shows the raw protocol version and correlation values.

KMIP Control Plane

What this means for you

Executive / Business Leader
In the guided view, the Learn tab opens with "Crypto agility in three steps" — set the policy, watch a request be refused, watch the estate rekey; the Dev tab is not shown for your role.
GRC / Risk & Compliance
On the Policy tab, "Which regime governs you?" loads a policy by regulator — US · NSA CNSA 2.0, US · FIPS 140-3, Germany · BSI — and the Inspect tab's Activity trail records every allow, deny or rekey decision.
Developer / Engineer
The Dev tab is a pipeline builder with Builder and Code views, a "Corpus (OASIS conformance)" palette, Run, and "Export .py"; switch View to expert and Inspect adds a "KMIP Wire" view of the TTLV bytes.
Security Architect
On Operate, "Plane 2 · KMIP Lifecycle" sends a real KMIP 3.0 request per button, with the algorithm set to "Auto — let the policy decide" or a named set; the Policy tab's Compare and Timeline ("As of" slider) show rules over time.
Researcher / Academic
The "CSD02" chip states that KMIP 3.0 is an OASIS committee draft, not a ratified standard; in expert view the Policy tab adds a YAML view of the exact rules and Inspect adds the raw "KMIP Wire" response.
Certification & Validation Engineer
On the Policy tab, "Which regime governs you?" includes US · FIPS 140-3; KMIP 3.0 is an OASIS committee draft (the "CSD02" chip), so nothing here is a validated configuration.
IT Ops / DevOps
The "Migration Estate" tab asks for keys by business label and lets the policy pick the algorithm; move from classical to hybrid to full PQC and "Key objects on this engine" shows rekeyed successors linked to deactivated predecessors.
Curious Explorer
Keep View on "guided" and press "Guided Tour" for step-by-step lessons; everything runs in this tab — no server, no Docker.

A real KMIP 3.0 control plane + PKCS#11 HSM, compiled to WebAssembly and running entirely in this tab — no server, no Docker. Every operation is a genuine KMIP request answered by the same Rust engine the appliance ships.

In scopecontrol plane + key management at rest · TLS handshake & persistence → full Docker sandbox

Spec statusKMIP 3.0 is an OASIS committee draft (CSD02, May 2026), not yet a ratified Standard —

Why crypto-agility, not just "post-quantum"

Data encrypted today with classical algorithms can be harvested now and decrypted later, once a cryptographically-relevant quantum computer exists — harvest-now, decrypt-later. The fix isn't swapping in a PQC algorithm once; it's a control plane that can migrate keys again whenever the roadmap changes, with no flag day and no application code change. Everything below is that idea made hands-on — flip the policy strip and watch the same request behave differently.

Crypto agility in three steps

Agility is the ability to change algorithm without changing the application. This is what that looks like when it works — three steps, about two minutes, running against a real control plane rather than a slide.

  1. 1Set the policy

    One rule, written once, in the control plane rather than in any application: this estate no longer issues classical signing keys. Nothing is rewritten and nothing is redeployed — the rule is data, not code.

    Cost: the policy itself is a few lines. What it replaces is a change request against every application that mints a key — which is the reason most estates cannot do this at all.

    In the console below: Activate a policy in the Policy plane

  2. 2Watch a request be refused

    Ask the control plane for exactly what the policy forbids. It says no, gives the rule it applied, and writes the refusal to the audit trail. This is the step that matters: the enforcement is central, so it holds for applications nobody has reviewed.

    Cost: the refusal is the control working, not an outage — the caller retries with a compliant algorithm. What you are buying is that you never have to ask each team whether they complied.

    In the console below: Run a scenario the policy refuses

  3. 3Watch the estate rekey

    Rotate the affected keys to the post-quantum algorithm. The control plane reissues them and the applications carry on against the same key names — 7 keys in this worked estate, and the same operation at any size.

    Cost, stated: signatures grow 64 B → 3,309 B, so certificate chains, tokens and firmware headers all get bigger, and an HSM that does 20,000 ECDSA P-256 signatures per second manages roughly 150 with ML-DSA-65. That is the capacity conversation this migration actually is — not whether to move, but what to buy.

    In the console below: Run the rekey in the Migration plane

That is the whole argument for agility: the algorithm changed, the applications did not, and there is a record of both. An estate that cannot do this has to repeat the whole migration the next time an algorithm is retired — and there will be a next time.

Then take it further: Command Center · Compliance landscape · Migration catalog

Every KMIP session starts the same way: ask the server to make you a key pair, then flip it live. This lesson uses that lifecycle to introduce the object model everything else in this lab builds on — including the honest limits of what "modernizing" a key actually means.

Classical

RSA-3072 (classical)

PKCS#1 v1.5 / FIPS 186-5 · Integer factorization · pub 384 B · priv 1,770 B · sig 384 B

  1. 1.Create an RSA-3072 key pair
  2. 2.Activate the private key

Provision the post-quantum equivalent

Compare

RSA-3072 (classical)ML-DSA-65 (FIPS 204)
OperationCreateKeyPairCreateKeyPair
Public key size384 B1,952 B (5.1×)
Private key sizeencoding-dependent (PKCS#1/#8)4,032 B, fixed by FIPS 204
Lifecycle states availablePre-Active → Active → … → DestroyedPre-Active → Active → … → Destroyed

"Modernizing" does not transform the RSA key in place — it is a brand-new object with its own UniqueIdentifier. The old key keeps working (e.g. to verify signatures made before the switch) until you deliberately retire it.

The request/response SHAPE is identical except the CryptographicAlgorithm value and the size of what comes back. That equivalence is crypto-agility at the protocol level.

Why it matters

If your integration code only ever reads PrivateKeyUniqueIdentifier / PublicKeyUniqueIdentifier off the response and treats them as opaque handles — never parsing key material client-side — this flip IS the entire migration for object creation. No code change, just a policy/config change (see the Agility tab).

Check your understanding

  1. 1. What does "modernizing" the RSA key to ML-DSA actually do?

  2. 2. What changed between the RSA-3072 request and the ML-DSA-65 request on the wire?

  3. 3. Why must you Activate a freshly created key before using it?

Try it yourself in Reference:

Want the full-fidelity version with TLS transport and the REST control plane? Run the real pqctoday-kmip server from the Docker sandbox.

Try it

In the Policy tab, change the disposition for RSA-3072. Where do you see the effect?

Next step

Put it in your report

Your readiness report is where the results of the Playground tools become recommendations.