OpenSSL Studio / S/MIME & CMS Workshop

What you will do: Sign, verify, encrypt and decrypt CMS messages with real OpenSSL 3.6 running in the browser, using ML-DSA, SLH-DSA and ML-KEM-768.

Worked example: An ML-DSA-65 CMS SignedData signed and verified end to end, then an ML-KEM-768 AuthEnvelopedData encrypted and decrypted; toggle the signing key through the PKCS#11 provider.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with Email & Document Signing

For your role

Developer / Engineer
Run Sign + Verify with ML-DSA-65 on a payload, then Encrypt + Decrypt with ML-KEM-768 and aes-256-gcm: the CMS SignedData and AuthEnvelopedData are produced by OpenSSL 3.6 WASM, and Use HSM key routes the signing key through softhsmv3.
Security Architect
The Dual-sign + Verify step (ML-DSA-65 with EC, marked WIP and not LAMPS composite) shows the migration-period pattern of two SignerInfos; the CMS Encryption step shows KEMRecipientInfo replacing key transport.
Researcher / Academic
Run the ML-DSA and ML-KEM steps and compare the CMS structures with and without the HSM key; the Live HSM Provider smoke test at the top shows whether the PKCS#11 provider initialised.
Full S/MIME & CMS workshop — real OpenSSL 3.6 WASM sign+verify and encrypt+decrypt with optional softhsmv3 PKCS#11 HSM routing. Open the full learn module for guided walkthroughs and quizzes.

Live HSM Provider — bundle smoke test

Loads the OpenSSL WASM bundle with pkcs11-provider + softhsmv3 statically linked, registers the provider via pqctoday_cms_init(), and confirms the round-trip works. Real CMS sign/verify/encrypt/decrypt operations land in Phase 2 once this foundation is green.

Loading openssl.wasm and registering pkcs11-provider…

What this proves

  • openssl.wasm in public/wasm/ includes both pkcs11-provider and softhsmv3 as statically-linked archives.
  • The exported _pqctoday_cms_init entry point registers the provider and loads its OPENSSL_CONF stanza.
  • From here, an openssl cms -sign -signer pkcs11:object=alice -keyform engineinvocation can route signing to softhsmv3 in-process (Phase 3).

Source: pkcs11-provider vendored at pqctoday-hsm/src/vendor/pkcs11-provider/.

Try it

Run Encrypt + Decrypt with ML-KEM-768. Which CMS structure carries the recipient key material?

Next step

Turn it into a plan: MTI Negotiator

This tool practises the Email & Document Signing module, phase 5 (Pilots & Migration); MTI Negotiator produces a deliverable of that phase.