> Markdown version of https://docs.laavat.io/appendixes/supported-keys/ from the LAAVAT PKI and Signing Platform documentation. All pages: https://docs.laavat.io/llms.txt

# Supported keys

LAAVAT PKI and Signing Platform supports following keys and hash algorithms.

| Key Type              | Key Size/Curve | Hash Algorithm | NIST Recommended | Notes                               |
|-----------------------|----------------|----------------|------------------|-------------------------------------|
| AES                   | 128 bits       | N/A            | Yes              |                                     |
| AES                   | 256 bits       | N/A            | Yes              |                                     |
| Passphrase            | 32 bytes       | N/A            | N/A              | Used for firmware update encryption |
| RSA                   | 1024 bits      | SHA-256        | No               | Legacy, not recommended             |
| RSA                   | 1024 bits      | SHA-512        | No               | Legacy, not recommended             |
| RSA                   | 2048 bits      | SHA-256        | No               |                                     |
| RSA                   | 2048 bits      | SHA-512        | No               |                                     |
| RSA                   | 3072 bits      | SHA-256        | Yes              |                                     |
| RSA                   | 3072 bits      | SHA-512        | Yes              |                                     |
| RSA                   | 4096 bits      | SHA-256        | Yes              |                                     |
| RSA                   | 4096 bits      | SHA-512        | Yes              |                                     |
| EC                    | secp224r1      | SHA-256        | No               |                                     |
| EC                    | secp224r1      | SHA-512        | No               |                                     |
| EC                    | secp256r1      | SHA-256        | Yes              |                                     |
| EC                    | secp256r1      | SHA-512        | Yes              |                                     |
| EC                    | secp384r1      | SHA-256        | No               |                                     |
| EC                    | secp384r1      | SHA-512        | Yes              |                                     |
| EC                    | secp521r1      | SHA-256        | No               |                                     |
| EC                    | secp521r1      | SHA-512        | Yes              |                                     |
| ML-DSA                | ML-DSA-44      | None           | Yes              | Post-quantum (FIPS 204), see below  |
| ML-DSA                | ML-DSA-65      | None           | Yes              | Post-quantum (FIPS 204), see below  |
| ML-DSA                | ML-DSA-87      | None           | Yes              | Post-quantum (FIPS 204), see below  |

## Post-quantum: ML-DSA

ML-DSA (FIPS 204) is the NIST post-quantum signature standard. The platform supports the three parameter sets as the key
types `MLDSA44`, `MLDSA65` and `MLDSA87`.

| Key type  | Security category | Public key | Signature  |
|-----------|-------------------|------------|------------|
| `MLDSA44` | 2                 | 1312 bytes | 2420 bytes |
| `MLDSA65` | 3                 | 1952 bytes | 3309 bytes |
| `MLDSA87` | 5                 | 2592 bytes | 4627 bytes |

What an ML-DSA key can do:

- **Certificates**: CA and end-entity keys in a PKI hierarchy, and the certificates, CSRs and CRLs they sign. A CA with an
  ML-DSA key can also issue certificates for RSA and EC keys. See
  [the PKI guide](https://docs.laavat.io/usage/productguide/pki/#supported-algorithms).
- **Message signing**: a `DigestSigning` operation with an ML-DSA key signs the message itself instead of a digest. See
  [Signing with ML-DSA keys](https://docs.laavat.io/usage/signing-encryption/signing-encryption/#signing-with-ml-dsa-keys).
- **NXP AHAB**: `MLDSA65` and `MLDSA87` SRK keys with SPSDK signing. See
  [SPSDK signing](https://docs.laavat.io/usage/signing-encryption/spsdksigning/#ml-dsa-keys).

What differs from RSA and EC keys:

- There is no separate hash algorithm. ML-DSA signs the whole message, so the hash algorithm is `NONE` and the signature
  padding is `NONE`.
- ML-DSA keys are HSM keys only. They cannot be software-protected, and they are not available as an
  [exportable token](https://docs.laavat.io/usage/productguide/product/#exportable-tokens).
- The signature format is the raw FIPS 204 signature. The CMS format is not available.
- Verifying needs a library that implements FIPS 204, for example OpenSSL 3.5 or later.

> **Note: Hash algorithms**
> The platform schema defines SHA-256 and SHA-512 as supported hash algorithms. SHA-384 may be available at the implementation level for specific signing operations (CMS, JAR, Windows signing) but is not part of the core schema enum.
