Enabling Post-Quantum Cryptography (PQC) Algorithms on HSMs
AppViewX supports Post-Quantum Cryptography (PQC) algorithms on selected HSM vendors, enabling quantum-safe CSR generation and code signing operations for CLM, PKI, and Code Signing workflows.
Supported HSM Vendors (v2026.3.0.0)
| HSM Vendor | PQC Algorithms Supported | CSR Generation | Code Signing | Key Generation / Encryption |
|---|---|---|---|---|
| Fortanix DSM | ML-DSA (CRYSTALS-Dilithium) | Yes | Yes | No (ML-KEM not supported via PKCS#11 in this release) |
| Utimaco SecurityServer | ML-KEM, ML-DSA, LMS, XMSS, SPHINCS+ | Planned | Planned | Planned |
Supported PQC Algorithms
| Standardized Name | Previous Name | Purpose |
|---|---|---|
| ML-DSA | CRYSTALS-Dilithium | Digital Signature |
| ML-KEM | CRYSTALS-Kyber | Key Encapsulation / Key Exchange |
Important: In this release, PQC support on
Fortanix DSM is limited to ML-DSA via the PKCS#11 interface. ML-KEM (key
generation and encryption/decryption) on Fortanix is not supported in this release.
Utimaco support is planned for a subsequent
release.
Prerequisites
Before enabling PQC algorithms on an
HSM, ensure the following prerequisites are met:
- The HSM (Fortanix DSM) is already added and configured in AppViewX. For instructions, refer to the Setting up the HSM topic.
- The IAIK cryptographic libraries are upgraded to the required versions:
- iaik-jce (Base Library) - version 1.8 or later
- iaik-pq (Post-Quantum Add-on) - compatible with iaik-jce 1.8
- iaik-pkcs11-provider (PKCS#11 Provider Add-on)
Note: The IAIK libraries require commercial licensing. Refer to the AppViewX EIS compliance ticket (EIS-18828) and the IAIK pricing page for licensing details before proceeding. - The Fortanix DSM instance is configured with ML-DSA (Dilithium) mechanism support enabled at the HSM policy level.
- The Security Administrator role is assigned to the user performing this configuration.
- Network connectivity between the AppViewX Cloud Connector and the Fortanix DSM REST API endpoint is verified.
VERIFY PQC ALGORITHM AVAILABILITY ON HSM
Verifying PQC Algorithm Availability on the HSM
-
Navigate to Menu > Settings > HSM.
The HSM Configuration page is displayed, listing all configured HSM instances.
-
Locate the Fortanix DSM instance and click the Health Check
option.
AppViewX performs a connectivity and capability check against the Fortanix DSM. A success response confirms that the HSM is reachable and operational.
-
Confirm that the PQC Algorithm Support status is shown as
Available in the HSM capability summary.
Note: If PQC Algorithm Support is not shown, verify that the IAIK libraries are correctly installed and that the Fortanix DSM policy includes ML-DSA mechanisms. Contact your HSM administrator to enable the required mechanisms.
CONFIGURE PQC ALGORITHM SELECTION
Configuring the PQC Algorithm for Cryptographic
Operations
- Navigate to Menu > Settings > HSM.
-
Click Edit on the Fortanix DSM instance.
The HSM Configuration edit panel is displayed.
-
In the Cryptographic Settings section, enter the following
values:
Table 1. Field descriptions - Cryptographic Settings Field Description *Cryptographic Mode Select Post-Quantum (PQC) to use PQC-only algorithms, or Hybrid (Classical + PQC) to use both classical and PQC algorithms in parallel. Hybrid mode maintains backward compatibility with existing workflows. *PQC Algorithm Select the PQC algorithm to use for supported operations: - ML-DSA (CRYSTALS-Dilithium) - for digital signatures, CSR generation, and code signing (supported on Fortanix DSM).
Signature Level Select the security level for ML-DSA: - ML-DSA-44 (NIST Level 2)
- ML-DSA-65 (NIST Level 3)
- ML-DSA-87 (NIST Level 5 - highest security)
*: Mandatory fields -
Click Save.
The PQC algorithm configuration is saved for the Fortanix DSM instance. Subsequent cryptographic operations on this HSM will use the selected PQC algorithm.
CSR GENERATION WITH PQC ALGORITHM
Generating a CSR Using a PQC Algorithm (Fortanix DSM)
- Navigate to the certificate enrollment or CSR generation workflow within CLM or PKI.
- In the Key Generation section, set Key Source to HSM.
- From the HSM Instance dropdown, select the configured Fortanix DSM instance.
-
In the Algorithm field, select ML-DSA (Post-Quantum).
Note: If Hybrid (Classical + PQC) mode is selected on the HSM instance, an additional Classical Algorithm field appears. Select the classical algorithm (RSA or ECC) to pair with ML-DSA for the hybrid certificate.
- Select the Signature Level matching the security level configured on the HSM (ML-DSA-44, ML-DSA-65, or ML-DSA-87).
- Complete the remaining certificate subject name fields (Common Name, Organization, SANs, etc.) as required.
-
Click Generate CSR.
AppViewX sends the CSR generation request to the Fortanix DSM via the PKCS#11 interface. The HSM generates the ML-DSA key pair and returns the signed CSR. The generated CSR is displayed and available for submission to the certificate authority.
CODE SIGNING WITH PQC ALGORITHM
Performing Code Signing Using a PQC Algorithm (Fortanix
DSM)
- Navigate to the code signing workflow within the Code Signing module.
- Select or create a code signing profile and set Key Source to HSM.
- From the HSM Instance dropdown, select the Fortanix DSM instance configured with PQC support.
- In the Signing Algorithm field, select ML-DSA.
-
Select the signing key from the HSM key inventory, ensuring the selected
key uses the ML-DSA algorithm.
Note: Only keys generated using the ML-DSA algorithm on the Fortanix DSM are available for PQC-based code signing. Keys generated using classical algorithms (RSA, ECDSA) are not listed when ML-DSA is selected as the signing algorithm.
-
Upload or specify the artifact to be signed and click Sign.
AppViewX sends the signing request to the Fortanix DSM. The HSM performs the ML-DSA signing operation and returns the signature. The signed artifact is available for download or direct deployment.
-
Verify the signed artifact by checking the Signing Audit Log to
confirm the PQC algorithm, key identifier, and timestamp are correctly
recorded.
The audit log entry confirms the PQC code signing operation for traceability and compliance.
