Integration Steps on ZetaCA

After HSM slot initialization, configure ZetaCA via the SysAdmin UI: 

  1. HSM Configuration: Navigate to HSM > Add HSM and enter the PKCS#11 parameters. 

  2. Root CA (Classical): Navigate to CA > Create Root CA. Select Algorithm: RSA-4096 (or ECDSA-P384), Key Storage: HSM, select the Utimaco config, set a key label. 

image-20260719-115820.png

ZetaCA Sysadmin: Create Root CA form with HSM-based Key Storage

image-20260719-173644.png

Resulting Root CA in ZetaCA using HSM-based Key Storage

  1. Root CA (PQC): Select Algorithm: ML-DSA-65, Key Storage: HSM. ZetaCA uses QuantumProtect VDM mechanisms for key generation and signing.

image-20260719-174048.png

ZetaCA PQC Issuing CA details

  1. Issue Certificate: navigate to Issue Certificate, select the HSM-backed CA, fill CN/template/validity, submit. Signing is performed within the HSM via C_Sign.

image-20260719-174316.png

ZetaCA Demo Root CA v6.4 Statistics after certificate issuance

  1. Hybrid/Composite: create a dual sub-CA pair (ECDSA P-384 + ML-DSA-65) for composite certificates combining classical and PQC signatures.