Skip to content

go-composite-mldsa

go-composite-mldsa is a Go library for post-quantum composite ML-DSA signatures as specified in draft-ietf-lamps-pq-composite-sigs-19.

ML-DSA is the post-quantum signature algorithm of FIPS 204. It is new and many operators do not want to rely on it alone yet. A composite key pairs an ML-DSA key with a traditional RSA, ECDSA or Ed25519 key. Every composite signature holds one signature from each component and verifies only when both are valid. A forger has to break both algorithms, so a certificate signed this way stays trustworthy while either one holds.

To the rest of a PKI a composite key looks like any other key. It has one algorithm identifier, one SubjectPublicKeyInfo and one signature value, so certificates, certificate requests and revocation lists keep their usual structure.

What the library provides

Package Purpose
compositemldsa Generate keys, encode them as raw bytes, PKIX and PKCS #8, sign and verify
compositex509 Create and verify certificates, certificate requests and revocation lists with composite keys, passing every other key type through to crypto/x509

The module needs Go 1.27.2 or newer and imports nothing outside the standard library.

Where to go next