OpenSSL Studio / OpenSSL Studio
What you will do: Pick the Learn, Explore or Workbench tab; in the Workbench choose a command category such as genpkey, req, x509, dgst, kem or enc, set its parameters, press Run Command and read the terminal output and logs.
Worked example: Choose the preset Generate ML-DSA-65 key, which runs openssl genpkey with the ML-DSA-65 algorithm and writes ml-dsa-65.key into the file manager, ready for a self-signed certificate.
Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.
For your role
- Developer / Engineer
- Run the eleven Learn lessons from Your first keypair to the Capstone, then open Workbench: the Command Preview shows the openssl invocation for each form field, and Edit OpenSSL Config exposes the openssl.cnf behind it.
- Security Architect
- Lessons L4 (key establishment without classical exchange), L7 (key derivation) and L8 (packaging keys) are the design choices; the Explore tab's Query this build lists which algorithms this OpenSSL build supports.
- Researcher / Academic
- Lesson L5, An honest LMS, is a claim you can check yourself; the Explore tab's Algorithm Explorer and the glossary's commands and flags are the reference for reproducing each lesson at a terminal.
- Certification & Validation Engineer
- Lesson L5, An honest LMS, and the Explore tab's Query this build show what this OpenSSL build actually supports; the build is educational and not FIPS-validated, so use it to reproduce a vector, not as evidence.
- IT Ops / DevOps
- Use the Workbench's Quick Start, Key Generation, CSR and Certificate forms with Command Preview open: the commands are what your scripts will run, and lesson L10 demystifies the config files they read.
Your first keypair — classical, then post-quantum
genpkey generates both eras of key with the same command shape — only the -algorithm value changes. Watch what changes (and what stays the same) between an RSA-2048 key and an ML-DSA-65 key.
ML-DSA (FIPS 204) and ML-KEM (FIPS 203) have been native in OpenSSL's default provider since 3.5 (this Studio runs 3.6.3) — no external provider needed. The PQC variant name (e.g. ml-dsa-65) IS the -algorithm value; it is not a -pkeyopt. That trips up first-time users coming from RSA, where key size is a separate -pkeyopt.
Steps
genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out learn-l1-rsa.key
1. Generate a classical RSA-2048 private key
genpkey -algorithm ML-DSA-65 -out learn-l1-mldsa.key
2. Generate a post-quantum ML-DSA-65 private key
Try it
In the Workbench, change the key algorithm and watch the Command Preview. What is the studio teaching?
Next step
Put it in your reportYour readiness report is where the results of the Playground tools become recommendations.
Related content
Next in OpenSSL Studio