Migrate key exchange and signatures separately
ML-KEM is used for key establishment through an encapsulation mechanism; ML-DSA and SLH-DSA are signature schemes. These tasks are not interchangeable. A specific protocol integration must be supported by the components involved. We therefore check connection setup, authentication and stored artifacts separately. In hybrid schemes, classical and post-quantum building blocks are combined according to the respective protocol. A permitted classical fallback is made visible, so that a working connection is not mistakenly treated as already migrated.


