Classical Acceptance Is Not Hybrid Authentication: Measuring X.509 Verifier
19 hours ago
- Hybrid X.509 certificates with separable designs risk relying solely on classical authentication, ignoring post-quantum evidence.
- Experiments across eight validation stacks show most accept hybrid certificates based only on classical paths, not evaluating post-quantum credentials.
- When post-quantum credentials are revoked but classical certificates remain valid, default paths still accept due to credential exclusion from decision scope.
- The gap is structural, not due to missing primitive capabilities, and stems from standards not requiring verifiers to make post-quantum evidence outcome-bearing.
- A verifier model and policy-parametric contract are proposed to enforce proper hybrid authentication checks.