Paper 2026/2297
An Analysis of the ITU-T Multiple Cryptographic Algorithms X.509 Extensions for PQC Migration
Abstract
The 2019 edition of ITU-T X.509 adds three certificate extensions, colloquially called the Catalyst extensions, that let a single certificate carry a second, alternative public key and issuer signature beside the native ones, as a backwards-compatible path for migrating a public-key infrastructure to post-quantum cryptography (PQC). This paper collects the known problems of this multiple cryptographic algorithms (MCA) mechanism and adds several findings of its own. The central and previously known weakness is that a quantum attacker who recovers a single traditional certification-authority key can replace any certificate in a chain by a traditional-only one that a relying party still accepts. We give a precise attack model with a sub-CA and an end-entity-forgery variant to emphasize the inherent problem. As an example, we verify empirically that the susceptibility to this downgrade attack is present in the wolfSSL cryptographic library as a natural consequence. Our further findings concern the construction itself and details of the specification. For one, we analyze the formal violations of EUF-CMA that arise due to the possibility of re-purposing the extension signature to the established signed data format in X.509, which is formally manifest as soon as the alternative key in the extension is also certified as a native key. We show that several further aspects in the ITU-T mechanism remain undefined, which potentially leads to divergent behaviour of clients, and point out that a certificate accepted on its alternative signature alone, as allowed per ITU-T specification, can be invalid under RFC~5280 and potentially exposes an application to arbitrary injected data and even modified signatures chaining it to a certificate chosen by a non-quantum attacker in the positively validated certificate chain.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- PQCX.509multi-algorithmdigital signature
- Contact author(s)
- falko strenzke @ mtg de
- History
- 2026-10-04: approved
- 2026-10-01: received
- See all versions
- Short URL
- https://ia.cr/2026/2297
- License
-
CC BY-SA
BibTeX
@misc{cryptoeprint:2026/2297,
author = {Falko Strenzke},
title = {An Analysis of the {ITU}-T Multiple Cryptographic Algorithms X.509 Extensions for {PQC} Migration},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2297},
year = {2026},
url = {https://eprint.iacr.org/2026/2297}
}