Re: Hybrid PQC: x25519-mlkem fails in openssl 3.5.5 with default provider

"'Tomas Mraz' via openssl-users" <[email protected]> Fri, 27 Mar 2026 16:51:40 +0100
Newsgroups gmane.comp.encryption.openssl.user,gmane.comp.encryption.openssl.devel
Message-ID <df5a3d02ed9e077b03be13a5c5992f2d0398d52d.camel@openssl.foundation>
Hi,

Yes, the X25519MLKEM768 does NOT have any defined private key format
and for that reason it is usable only for ephemeral keys.

Regards,

Tomas Mraz, CTO, OpenSSL Foundation


On Fri, 2026-03-27 at 20:55 +0530, murugesh pitchaiah wrote:
> Hi All,
>=20
> I have downloaded the openssl 3.5.5 code base and built the library.
> While trying to generate the hybrid ml-kem keypair see below error:
>=20
> (snip)
>=20
> $ openssl genpkey -algorithm X25519MLKEM768 -out
> x25519_mlkem_768_key.pem
> Error writing key(s)
> 80CB0C248B760000:error:1D800065:ENCODER
> routines:OSSL_ENCODER_to_bio:reason(101):crypto/encode_decode/encoder
> _lib.c:78:No encoders were found. For standard encoders you need at
> least one of the default or base providers available. Did you forget
> to load them?
> 80CB0C248B760000:error:04800073:PEM routines:do_pk8pkey:error
> converting private key:crypto/pem/pem_pk8.c:132:
>=20
> $ openssl list -providers
> Providers:
> =C2=A0 default
> =C2=A0 =C2=A0 name: OpenSSL Default Provider
> =C2=A0 =C2=A0 version: 3.5.5
> =C2=A0 =C2=A0 status: active
> $=C2=A0
>=20
> $ openssl list -kem-algorithms | grep -i mlkem
> =C2=A0 { 2.16.840.1.101.3.4.4.1, id-alg-ml-kem-512, ML-KEM-512, MLKEM512 =
}
> @ default
> =C2=A0 { 2.16.840.1.101.3.4.4.2, id-alg-ml-kem-768, ML-KEM-768, MLKEM768 =
}
> @ default
> =C2=A0 { 2.16.840.1.101.3.4.4.3, id-alg-ml-kem-1024, ML-KEM-1024,
> MLKEM1024 } @ default
> =C2=A0 X25519MLKEM768 @ default
> =C2=A0 X448MLKEM1024 @ default
> =C2=A0 SecP256r1MLKEM768 @ default
> =C2=A0 SecP384r1MLKEM1024 @ default
> $=C2=A0
>=20
> (snip)
>=20
> I assume the support is added by default and no provider load is
> needed. Can anyone please share what am i missing ? Thanks in
> advance.
>=20
> Regards,
> Murugesh
> --=20
> You received this message because you are subscribed to the Google
> Groups "openssl-users" group.
> To unsubscribe from this group and stop receiving emails from it,
> send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
> To view this discussion visit
> https://groups.google.com/a/openssl.org/d/msgid/openssl-users/CAOu9RAdFHf=
B4_RtCsD79tNTCuE3PiUtOn31Ora82dE_LYgPzcw%40mail.gmail.com
> .

--=20
Tom=C3=A1=C5=A1 Mr=C3=A1z, Chief Technology Officer, OpenSSL Foundation
We need your support! Help us protect digital privacy=E2=80=A6 everywhere.
https://openssl.foundation/donate/ways-to-give

--=20
You received this message because you are subscribed to the Google Groups "=
openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msg=
id/openssl-users/df5a3d02ed9e077b03be13a5c5992f2d0398d52d.camel%40openssl.f=
oundation.