Station 07 · FIPS 204
ML-DSA lane
Lab exercise B: canonical JSON + SHA-384 of a telemetry envelope. This desk does not hold secret keys and does not sign. FIPS 204 is an algorithm standard — not FIPS 140, not HNDL, not a device.
ML-DSA-87
Pure · id-ml-dsa-87
- OID
- 2.16.840.1.101.3.4.3.19
- Public key
- 2592 bytes
- Secret key
- 4896 bytes (not shipped)
- Signature
- 4627 bytes
- Ledger hash
- SHA-384
- Self-check
- 18/18 PASS
- Lane
- PRODUCTION_REVIEW_CANDIDATE
Ed25519
CLASSICAL_BASELINE_ONLY
- Post-quantum
- false
- Public key
- 32 bytes
- Seed
- 32 bytes
- Signature
- 64 bytes
Classical baseline only. Silent PQ labeling is a frozen reject.
Canonical bytes
Envelope lab
Method: JSON keys sorted, separators (',', ':'), UTF-8. Sign-the-bytes in the Python lane — never the SHA-384 digest as Pure input. Here we only hash.
{"alg":"ML-DSA-87","body":"educational telemetry; no secrets","ed25519_is_post_quantum":false,"hndl_claim_allowed":false,"mode":"Pure","subject":"lab-envelope","ts":"2026-09-20T17:37:30Z"}PQ gate
Refuse codes (frozen)
REJECT_ED25519_AS_PQ
ALWAYS_REJECTEd25519 is classical. Silent PQ labeling is illegal.
REJECT_HNDL_ON_SIGNATURE_ONLY
ALWAYS_REJECTHarvest-now / decrypt-later is forbidden on this package.
REJECT_FOLD_MATH_IN_CRYPTO
ALWAYS_REJECTDo not mix Fold Hunt math into the telemetry lane.
REJECT_FIPS140_MODULE_CLAIM
ALWAYS_REJECTFIPS 204 is an algorithm standard, not a FIPS 140 module certificate.
REJECT_PRODUCTION_CERTIFIED
ALWAYS_REJECT until a separate cert pathPRODUCTION_REVIEW_CANDIDATE is not production certified.
REJECT_OID_ONLY_INTEROP
ALWAYS_REJECTOID name-dropping is not interop.
REJECT_HASHMLDSA_MISLABEL
ALWAYS_REJECTThis lane is Pure ML-DSA. Do not call it HashML-DSA.