Example Create, backup and restore ML-DSA keys on a V1 partition

Create some ML-DSA keys

1.To get started, launch CKDemo and open a session.

For this example, we show the full CKDemo menu once, for orientation, and thereafter, we show just the specific commands for brevity.

ckdemo (64-bit) v10.9.0-65. Copyright (c) 2025 Thales Group. All rights reserved.

ckdemo is the property of Thales Group and is provided to our customers for
diagnostic and development purposes only.  It is not intended for use in
production installations.  Any re-distribution of this program in whole or
in part is a violation of the license agreement.

Modified on Jun 11 2025 at 13:22:01

Starting CHRYSTOKI DEMO - SIMULATION LAB

Status: Doing great, no errors (CKR_OK)
TOKEN:
    ( 1) Open Session  ( 2) Close Session  ( 3) Login
    ( 4) Logout        ( 5) Change PIN     ( 6) Init Token
    ( 7) Init Pin      ( 8) Mechanism List ( 9) Mechanism Info
    (10) Get Info      (11) Slot Info      (12) Token Info
    (13) Session Info  (14) Get Slot List  (15) Wait for Slot Event
    (16) Token Status  (17) SessionCancel  (18) Factory Reset
    (19) CloneMofN     (33) Token Insert   (34) Token Delete
    (36) Show Roles    (37) Show Role Configuration Policies
    (38) Show Role State   (39) Get OUID   (140) Get Handle
    (58) HSM Zeroize       (59) Token Zeroize
    (160) Show License List   (161) QueryLicense   (162) HSM Stats
    (163) LogoutOther
OBJECT MANAGEMENT:
    (20) Create object (21) Copy object    (22) Destroy object
    (23) Object size   (24) Get attribute  (25) Set attribute
                       (26) Find object    (27) Display Object
    (30) Modify Usage Count         (31) Destroy Multiple Objects
    (32) Extract Public Key         (35) Import Public Key
SECURITY:
    (40) Encrypt file  (41) Decrypt file   (42) Sign
    (43) Verify        (44) Hash file      (45) Simple Generate Key
    (46) Digest Key
HIGH AVAILABILITY RECOVERY :
    (49) HA Current Status       (50) HA Recovery Init       (51) HA Recovery Login
    (52) HA Group Status
POLICY:
   (53) Show Partition Policies     (54) Set Partition Policies
   (55) Show HSM Policies (56) Set HSM Policies (57) Set Destructive HSM Policies
KEY:
    (60)  Wrap key      (61) Unwrap key     (62) Generate random number
    (63)  Derive Key    (64) PBE Key Gen    (65) Create known keys
    (66)  Seed RNG      (67) EC User Defined Curves
    (68)  SM2 User Defined Curves
    (69)  Translate key
    (150) Encapsulate key
    (151) Decapsulate key
CA:
    (70) Set Domain    (71) Clone Key      (72) Set MofN
    (73) Generate MofN (74) Activate MofN  (75) Generate Token Keys
                                           (77) Sign Token Cert
    (78) Generate CertCo Cert              (79) Modify MofN
    (85) Put HSM Data/Parameter
    (86) Dup. MofN Keys                    (87) Deactivate MofN
    (88) Get Token Certificates            (89) Get HSM Data/Parameter
    (112) Set Legacy Cloning Domain
OTHERS:
    (90) Self Test
    (92) Get App ID
    (93) Utilization Metrics
    (94) Open Access    (95) Close Access
    (97) Set App ID     (98) Options
OFFBOARD KEY STORAGE:
   (101) Extract Masked Object            (102) Insert Masked Object
   (103) Multisign With Value             (104) Clone Object
   (105) SIMExtract                       (106) SIMInsert
   (107) SimMultiSign                     (108) SMKRollover
   (109) CPv4 MigrateKeys
   (118) Extract Object                   (119) Insert Object
CLUSTER EXECUTION:
   (111) Get Cluster State
   (113) Lock Clustered Slot              (114) Unlock Clustered Slot
PED INFO:
   (120) Set Ped Info   (121) Get Ped Info (122) Init RPV
   (123) Delete RPV
AUDIT/LOG:
   (130) Get Config     (131) Set Config   (132) Verify logs
   (133) Get Time       (134) Set Time     (135) Import Secret
   (136) Export Secret  (137) Init Audit   (138) Get Status
   (139) Log External
SRK:
   (200) SRK Get State  (201) SRK Restore  (202) SRK Resplit
   (203) SRK Zeroize    (204) SRK Enable/Disable
Per Key Authorization:
    (210) Authorize Key              (211) Set Authorization Data
    (212) Reset Authorization Data   (213) Assign Key
    (214) Increment Failed Auth Count
Cloning API:
    (215) CloneAsSourceInit          (216) CloneAsTargetInit
    (217) CloneAsSource              (218) CloneAsTarget
    (219) CPv4 MigrateKeys           (220) CPv4 Negotiate Session
    (221) CPv4 Close Session
IS6 Migration:
    (300) Set IS6 Domain             (301) Insert IS6 Group Part
    (302) Insert IS6 Member Part     (303) Insert IS6 Key
KeyRing Configurations:
    (310) Setup KeyRing              (311) Add Key to KeyRing

(TITLE) menu titles, (99 or FULL) Full Help, (NONE) No help, (0 or EXIT) Quit


Status: Doing great, no errors (CKR_OK)
Enter your choice :
 1

Slots available:
        slot#3 - User Token Slot
        slot#4 - User Token Slot
        slot#204 - Admin Token Slot


Select a slot:
3      <--- This is opening a session in the slot that you choose; must be partition type V1

Status: Doing great, no errors (CKR_OK)

2.Log into that V1 partition (for backup and restore, later in this example, this will be the source slot).

(TITLE) menu titles, (99 or FULL) Full Help, (NONE) No help, (0 or EXIT) Quit


Status: Doing great, no errors (CKR_OK)

Enter your choice :
3

Status: Doing great, no errors (CKR_OK)

3.From the Options menu (under OTHERS in CKDemo main menu), choose "input from keyboard" for sign/derive data. Then generate an ML-DSA key.

a.Input


(TITLE) menu titles, (99 or FULL) Full Help, (NONE) No help, (0 or EXIT) Quit


Status: Doing great, no errors (CKR_OK)

Enter your choice :

98

Options:
 1 - Open Session Type          : Always R/W and Serial
 2 - Display Help               : Always
 3 - PIN path                   : user supplies ASCII password
 4 - Echo input                 : Disabled
 5 - Sleep for n seconds after writing special instructions to stderr
 6 - KCV Default                : user supplies KCV Domain
 7 - MofN path                  : user supplies MofN path
 8 - Show Response Code         : SHOW_RESPONSE_BEFORE_AND_AFTER_MENU
 9 - Input data for sign/derive : input from keyboard
10 - Object Usage Counters      : disabled
11 - GCM IV Source              : external
12 - ECIES Parameters           : use default (XOR with HMAC_SHA1)
13 - X9.31 Signatures           : allow X9.31 generated keys only
14 - Multipart enc/dec/sig/ver  : use single part operations
15 - Use Old Enc/Dec Menu       : use old menu
16 - Role Support               : auto-detect
17 - OAEP Hash Params           : use default (SHA1 Digest and MGF1)
18 - Array Template Attributes  : do not use array template attributes
19 - Specify Number of Objects Handles to Find per Update call? : No
20 - Specify Number of Objects to Create/Keys to generate? : No
21 - Prompt for CKA_CHECK_VALUE during key unwrap/derive? : No
22 - Prompt for CKA_BYTES_REMAINING during 3TDES key creation: No
23 - Prompt for template editing: No
24 - Use old 64 bit App ID      : No
25 - Use low level cloning APIs : No
26 - Use default SM2DSA options : Yes
27 - Extract MIC from HOC and save as DER file: No
28 - EC Point in RAW value: No
 0 - Finished

Enter option to change:

9


Status: Doing great, no errors (CKR_OK)

b.Keygen


(TITLE) menu titles, (99 or FULL) Full Help, (NONE) No help, (0 or EXIT) Quit


Status: Doing great, no errors (CKR_OK)
Enter your choice : 45      <--- This is starting the key-generation dialog
Select type of key to generate
[ 1] DES       [ 2] DES2   [ 3] DES3               [ 5]  CAST3
[ 6] Generic   [ 7] RSA    [ 8] DSA   [ 9]   DH    [10]  CAST5
[11] RC2       [12] RC4    [13] RC5   [14]   SSL3  [15]  ECDSA
[16] AES       [17] SEED   [18] KCDSA-1024         [19] KCDSA-2048
[20] DSA Domain Param      [21] KCDSA Domain Param
[22] RSA X9.31             [23] DH X9.42           [24] ARIA
[25] DH PKCS Domain Param  [26] RSA 186-3 Aux Primes
[27] RSA 186-3 Primes      [28] DH X9.42 Domain Param
[29] ECDSA with Extra Bits [30] EC Edwards 25519
[31] EC Montgomery 25519
[32] EC Edwards 448
[33] EC Montgomery 448
[40] SM4       [41] SM2
[42] HSS       [43] ML-KEM [44] ML-DSA
>

44         <--- Choosing ML-DSA, then picking a key-size
Enter ML-DSA key set size:
[1] ML_DSA_44
[2] ML_DSA_65
[3] ML_DSA_87

Selection :
1

Enter Is Token Attribute [0-1]:
1

Enter Is Sensitive Attribute [0-1]:
1

Enter Is Private Attribute [0-1]:
1

Enter Is Modifiable Attribute [0-1]:
1

Enter Extractable Attribute [0-1]:
1

Enter Encrypt/Decrypt Attribute [0-1]:
1

Enter Sign/Verify Attribute [0-1]:
1

Enter Wrap/Unwrap Attribute [0-1]:
1

Enter Derive Attribute [0-1]:1
Generated ML-DSA Public Key:         93 (0x0000005d)
Generated ML-DSA Private Key:         97 (0x00000061)

Status: Doing great, no errors (CKR_OK)



c.Set labels for the new keypair

(TITLE) menu titles, (99 or FULL) Full Help, (NONE) No help, (0 or EXIT) Quit


Status: Doing great, no errors (CKR_OK) 


25    <--- Setting attribute - in this case a label for generated Public key


Which object do you want to modify (0 to list available objects) : 93

Edit template for set attribute operation.

(1) Add Attribute   (2) Remove Attribute   (0) Accept Template :


1

 0 - CKA_CLASS                  1 - CKA_TOKEN
 2 - CKA_PRIVATE                3 - CKA_LABEL
 4 - CKA_APPLICATION            5 - CKA_VALUE
 6 - CKA_UNKNOWN                7 - CKA_CERTIFICATE_TYPE
 8 - CKA_ISSUER                 9 - CKA_SERIAL_NUMBER
10 - CKA_KEY_TYPE              11 - CKA_SUBJECT
12 - CKA_ID                    13 - CKA_SENSITIVE
14 - CKA_ENCRYPT               15 - CKA_DECRYPT
16 - CKA_WRAP                  17 - CKA_UNWRAP
18 - CKA_SIGN                  19 - CKA_SIGN_RECOVER
20 - CKA_VERIFY                21 - CKA_VERIFY_RECOVER
22 - CKA_DERIVE                23 - CKA_START_DATE
24 - CKA_END_DATE              25 - CKA_MODULUS
26 - CKA_MODULUS_BITS          27 - CKA_PUBLIC_EXPONENT
28 - CKA_PRIVATE_EXPONENT      29 - CKA_PRIME_1
30 - CKA_PRIME_2               31 - CKA_EXPONENT_1
32 - CKA_EXPONENT_2            33 - CKA_COEFFICIENT
34 - CKA_PRIME                 35 - CKA_SUBPRIME
36 - CKA_BASE                  37 - CKA_VALUE_BITS
38 - CKA_VALUE_LEN             39 - CKA_LOCAL
40 - CKA_MODIFIABLE            41 - CKA_ECDSA_PARAMS
42 - CKA_EC_POINT              43 - CKA_EXTRACTABLE
44 - CKA_ALWAYS_SENSITIVE      45 - CKA_NEVER_EXTRACTABLE
46 - CKA_CCM_PRIVATE           47 - CKA_FINGERPRINT_SHA1
48 - CKA_OUID                  49 - CKA_X9_31_GENERATED
50 - CKA_PRIME_BITS            51 - CKA_SUBPRIME_BITS
52 - CKA_USAGE_COUNT           53 - CKA_USAGE_LIMIT
54 - CKA_EKM_UID               55 - CKA_GENERIC_1
56 - CKA_GENERIC_2             57 - CKA_GENERIC_3
58 - CKA_FINGERPRINT_SHA256    59 - CKA_WARNING_THRESHOLD
60 - CKA_HW_FEATURE_TYPE       61 - CKA_CHECK_VALUE
62 - CKA_BIP32_CHAIN_CODE      63 - CKA_BIP32_VERSION_BYTES
64 - CKA_BIP32_CHILD_INDEX     65 - CKA_BIP32_CHILD_DEPTH
66 - CKA_BIP32_ID              67 - CKA_BIP32_FINGERPRINT
68 - CKA_BIP32_PARENT_FINGERPRINT   69 - CKA_BYTES_REMAINING
70 - CKA_AUTH_DATA             71 - CKA_ASSIGNED
72 - CKA_KEY_STATUS            73 - CKA_FAILED_KEY_AUTH_COUNT
74 - CKA_KEYRING               75 - CKA_KEYRING_OUID
76 - CKA_ENCAPSULATE           77 - CKA_DECAPSULATE
78 - CKA_PARAMETER_SET         79 - CKA_PUBLIC_KEY
80 - CKA_PUBLIC_KEY_INFO       81 - CKA_SEED

Select which one: 3
Enter string value: ML-DSA-44 Public Key

CKA_LABEL=ML-DSA-44 Public Key

(1) Add Attribute   (2) Remove Attribute   (0) Accept Template :

0

Status: Doing great, no errors (CKR_OK)

(TITLE) menu titles, (99 or FULL) Full Help, (NONE) No help, (0 or EXIT) Quit


Status: Doing great, no errors (CKR_OK)
Enter your choice : 25   <--- Setting attribute - in this case a label for generated Private key


Which object do you want to modify (0 to list available objects) : 97

Edit template for set attribute operation.

(1) Add Attribute   (2) Remove Attribute   (0) Accept Template :

1

 0 - CKA_CLASS                  1 - CKA_TOKEN
 2 - CKA_PRIVATE                3 - CKA_LABEL
 4 - CKA_APPLICATION            5 - CKA_VALUE
 6 - CKA_UNKNOWN                7 - CKA_CERTIFICATE_TYPE
 8 - CKA_ISSUER                 9 - CKA_SERIAL_NUMBER
10 - CKA_KEY_TYPE              11 - CKA_SUBJECT
12 - CKA_ID                    13 - CKA_SENSITIVE
14 - CKA_ENCRYPT               15 - CKA_DECRYPT
16 - CKA_WRAP                  17 - CKA_UNWRAP
18 - CKA_SIGN                  19 - CKA_SIGN_RECOVER
20 - CKA_VERIFY                21 - CKA_VERIFY_RECOVER
22 - CKA_DERIVE                23 - CKA_START_DATE
24 - CKA_END_DATE              25 - CKA_MODULUS
26 - CKA_MODULUS_BITS          27 - CKA_PUBLIC_EXPONENT
28 - CKA_PRIVATE_EXPONENT      29 - CKA_PRIME_1
30 - CKA_PRIME_2               31 - CKA_EXPONENT_1
32 - CKA_EXPONENT_2            33 - CKA_COEFFICIENT
34 - CKA_PRIME                 35 - CKA_SUBPRIME
36 - CKA_BASE                  37 - CKA_VALUE_BITS
38 - CKA_VALUE_LEN             39 - CKA_LOCAL
40 - CKA_MODIFIABLE            41 - CKA_ECDSA_PARAMS
42 - CKA_EC_POINT              43 - CKA_EXTRACTABLE
44 - CKA_ALWAYS_SENSITIVE      45 - CKA_NEVER_EXTRACTABLE
46 - CKA_CCM_PRIVATE           47 - CKA_FINGERPRINT_SHA1
48 - CKA_OUID                  49 - CKA_X9_31_GENERATED
50 - CKA_PRIME_BITS            51 - CKA_SUBPRIME_BITS
52 - CKA_USAGE_COUNT           53 - CKA_USAGE_LIMIT
54 - CKA_EKM_UID               55 - CKA_GENERIC_1
56 - CKA_GENERIC_2             57 - CKA_GENERIC_3
58 - CKA_FINGERPRINT_SHA256    59 - CKA_WARNING_THRESHOLD
60 - CKA_HW_FEATURE_TYPE       61 - CKA_CHECK_VALUE
62 - CKA_BIP32_CHAIN_CODE      63 - CKA_BIP32_VERSION_BYTES
64 - CKA_BIP32_CHILD_INDEX     65 - CKA_BIP32_CHILD_DEPTH
66 - CKA_BIP32_ID              67 - CKA_BIP32_FINGERPRINT
68 - CKA_BIP32_PARENT_FINGERPRINT   69 - CKA_BYTES_REMAINING
70 - CKA_AUTH_DATA             71 - CKA_ASSIGNED
72 - CKA_KEY_STATUS            73 - CKA_FAILED_KEY_AUTH_COUNT
74 - CKA_KEYRING               75 - CKA_KEYRING_OUID
76 - CKA_ENCAPSULATE           77 - CKA_DECAPSULATE
78 - CKA_PARAMETER_SET         79 - CKA_PUBLIC_KEY
80 - CKA_PUBLIC_KEY_INFO       81 - CKA_SEED

Select which one: 3
Enter string value: ML-DSA-44 Private Key

CKA_LABEL=ML-DSA-44 Private Key

(1) Add Attribute   (2) Remove Attribute   (0) Accept Template :

0


Status: Doing great, no errors (CKR_OK)

d.[OPTIONAL]Repeat for ML-DSA 65 and ML-DSA 87 keypairs.

:

[trimmed for brevity]

:


(TITLE) menu titles, (99 or FULL) Full Help, (NONE) No help, (0 or EXIT) Quit


Status: Doing great, no errors (CKR_OK)
Enter your choice : Select type of key to generate
[ 1] DES       [ 2] DES2   [ 3] DES3               [ 5]  CAST3
[ 6] Generic   [ 7] RSA    [ 8] DSA   [ 9]   DH    [10]  CAST5
[11] RC2       [12] RC4    [13] RC5   [14]   SSL3  [15]  ECDSA
[16] AES       [17] SEED   [18] KCDSA-1024         [19] KCDSA-2048
[20] DSA Domain Param      [21] KCDSA Domain Param
[22] RSA X9.31             [23] DH X9.42           [24] ARIA
[25] DH PKCS Domain Param  [26] RSA 186-3 Aux Primes
[27] RSA 186-3 Primes      [28] DH X9.42 Domain Param
[29] ECDSA with Extra Bits [30] EC Edwards 25519
[31] EC Montgomery 25519
[32] EC Edwards 448
[33] EC Montgomery 448
[40] SM4       [41] SM2
[42] HSS       [43] ML-KEM [44] ML-DSA
> 44

Enter ML-DSA key set size:
[1] ML_DSA_44
[2] ML_DSA_65
[3] ML_DSA_87

Selection :

2
:
(shortened for space)
:
:

CKA_LABEL=ML-DSA-65 Public Key
:

CKA_LABEL=ML-DSA-65 Private Key

:
:

CKA_LABEL=ML-DSA-87 Public Key
:

CKA_LABEL=ML-DSA-87 Private Key

:

... resulting in

handle=111      label=ML-DSA-87 Private Key
handle=112      label=ML-DSA-87 Public Key
handle=109      label=ML-DSA-65 Private Key
handle=102      label=ML-DSA-65 Public Key
handle=97       label=ML-DSA-44 Private Key
handle=93       label=ML-DSA-44 Public Key

... for the next example.

Backup the created keys

Backup and Restore constraints

When backing-up partition contents to a Luna Backup HSM 7 at firmware version 7.7.3 or older:

>Non-PQC keys (AES, RSA, etc.) are backed up and restored.

If a PQC key cannot be backed up, an error (CKR_ATTRIBUTE_TYPE_INVALID or CKR_KEY_TYPE_INCONSISTENT) is shown and those keys are skipped.

>HSS/LMS private keys, by design (to NIST requirements), cannot be cloned or included in encrypted SKS blobs, and therefore cannot be backed-up in any way

>Other PQC keys (ML-KEM private and public, and ML-DSA private and public, and HSS/LMS public) are backed-up from V1 partitions, because V1 partition backups are stored as encrypted blobs and individual keys are not examined.

>Other PQC keys (ML-KEM, and ML-DSA, and HSS/LMS public) are not backed-up from V0 partitions, as all keys are individually examined, and Luna Backup HSM 7 Firmware 7.7.3 and older do not recognize PQC keys.

>Similarly, from pre-PQC algorithms and key-types, SLIP10 keys are not backed up from V0 partitions



lunacm (64-bit) v10.9.0-60. Copyright (c) 2025 Thales Group. All rights reserved.


        Available HSMs:

        Slot Id ->              3
        Label ->                MyPar
        Serial Number ->        2353942977384
        Model ->                Luna K7
        Firmware Version ->     7.9.0
        Bootloader Version ->   1.1.5
        Configuration ->        Luna User Partition With SO (PW) Key Export With Cloning Mode
        Slot Description ->     User Token Slot
        FM HW Status ->         FM Ready

        Slot Id ->              4
        Label ->                Par2
        Serial Number ->        2353942977385
        Model ->                Luna K7
        Firmware Version ->     7.9.0
        Bootloader Version ->   1.1.5
        Configuration ->        Luna User Partition With SO (PW) Key Export With Cloning Mode
        Slot Description ->     User Token Slot
        FM HW Status ->         FM Ready


        Slot Id ->              204
        Label ->                B700
        Serial Number ->        123321
        Model ->                Luna G7
        Firmware Version ->     7.7.3
        Bootloader Version ->   1.6.0
        Configuration ->        Luna HSM Admin Partition (PW) Backup Mode
        Slot Description ->     Admin Token Slot
        HSM Status ->           L3 Device, OK
        HSM Certificates ->     *** Test Certs ***

        Current Slot Id: 3

1.Log into the first partition (where you created the ML-DSA keypairs, above), that will be the source slot for this example.

lunacm:>role login -n co -p <your_unique_password_for_co>

Command Result : No Error


lunacm:>partition showpolicies
        Partition Capabilities
                 0: Enable private key cloning : 1
                 1: Enable private key wrapping : 1
                 2: Enable private key unwrapping : 1
                 3: Enable private key masking : 1
                 4: Enable secret key cloning : 1
                 5: Enable secret key wrapping : 1
                 6: Enable secret key unwrapping : 1
                 7: Enable secret key masking : 1
                 9: Enable digest key : 1
                10: Enable multipurpose keys : 1
                11: Enable changing key attributes : 1
                15: Allow failed challenge responses : 1
                16: Enable operation without RSA blinding : 1
                17: Enable signing with non-local keys : 1
                18: Enable raw RSA operations : 1
                20: Max failed user logins allowed : 10
                21: Enable high availability recovery : 1
                22: Enable activation : 0
                23: Enable auto-activation : 0
                25: Minimum pin length (inverted: 255 - min) : 247
                26: Maximum pin length : 255
                28: Enable Key Management Functions : 1
                29: Enable RSA signing without confirmation : 1
                31: Enable private key unmasking : 1
                32: Enable secret key unmasking : 1
                33: Enable RSA PKCS mechanism : 1
                34: Enable CBC-PAD (un)wrap keys of any size : 1
                37: Enable enforcing Secure Trusted Channel : 1
                39: Enable Start/End Date Attributes : 1
                40: Enable Per-Key Authorization Data : 1
                41: Enable Partition Version : 1
                42: Enable CPv1 : 1
                43: Enable non-FIPS algorithms : 1
                44: Enable Extended Domain Management : 1
                45: Enable ECDSA/RSA Prehash SigVer : 1

        Partition Policies
                 0: Allow private key cloning : 1
                 1: Allow private key wrapping : 0
                 2: Allow private key unwrapping : 1
                 3: Allow private key masking : 1
                 4: Allow secret key cloning : 1
                 5: Allow secret key wrapping : 1
                 6: Allow secret key unwrapping : 1
                 7: Allow secret key masking : 1
                 9: Allow digest key : 0
                10: Allow multipurpose keys : 1
                11: Allow changing key attributes : 1
                15: Ignore failed challenge responses : 1
                16: Operate without RSA blinding : 1
                17: Allow signing with non-local keys : 1
                18: Allow raw RSA operations : 1
                20: Max failed user logins allowed : 10
                21: Allow high availability recovery : 1
                25: Minimum pin length (inverted: 255 - min) : 247
                26: Maximum pin length : 255
                28: Allow Key Management Functions : 1
                29: Perform RSA signing without confirmation : 1
                31: Allow private key unmasking : 1
                32: Allow secret key unmasking : 1
                33: Allow RSA PKCS mechanism : 1
                34: Allow CBC-PAD (un)wrap keys of any size : 1
                37: Force Secure Trusted Channel : 0
                39: Allow Start/End Date Attributes : 0
                40: Require Per-Key Authorization Data : 1
                41: Partition Version : 1
                42: Allow CPv1 : 0
                43: Allow non-FIPS algorithms : 1
                44: Allow Extended Domain Management : 0
                45: Allow ECDSA/RSA Prehash SigVer : 1


Command Result : No Error

2.Backup the contents of this source slot to the Backup HSM (in this case, it is slot 204).



lunacm:>partition archive backup -slot 204 -password <your_unique_password_for_co> -sopassword <your_unique_password_for_so> -domain <your_non-default_domain> -par mldsa -f

        You are backing up an SKS partition.

        Logging in as the SO on slot 204.

        Creating partition mldsa on slot 204.

        Verifying that all objects can be backed up...

        6 objects found; attempting to back up 6 objects

        The SMKs were backed up to partition mldsa successfully.

        Backing up SKS Blobs...

        Object 111 has been backed up to partition mldsa (new handle 27).
        Object 112 has been backed up to partition mldsa (new handle 100).
        Object 109 has been backed up to partition mldsa (new handle 132).
        Object 102 has been backed up to partition mldsa (new handle 142).
        Object 97 has been backed up to partition mldsa (new handle 148).
        Object 93 has been backed up to partition mldsa (new handle 155).

        Resizing partition mldsa on slot 204 to minimum necessary space.

        Backup Successfully Completed.

        6 objects have been backed up to partition mldsa
        on slot 204.

Command Result : No Error

3.Set the focus (current slot) to the other non-backup partition and log in; this will be the target to which objects from the backup HSM will be restored.


lunacm:>slot set slot 4

        Current Slot Id:    4     (Luna User Slot 7.9.0 (PW) Key Export With Cloning Mode)

Command Result : No Error


lunacm:>partition showpolicies
        Partition Capabilities
                 0: Enable private key cloning : 1
                 1: Enable private key wrapping : 1
                 2: Enable private key unwrapping : 1
                 3: Enable private key masking : 1
                 4: Enable secret key cloning : 1
                 5: Enable secret key wrapping : 1
                 6: Enable secret key unwrapping : 1
                 7: Enable secret key masking : 1
                 9: Enable digest key : 1
                10: Enable multipurpose keys : 1
                11: Enable changing key attributes : 1
                15: Allow failed challenge responses : 1
                16: Enable operation without RSA blinding : 1
                17: Enable signing with non-local keys : 1
                18: Enable raw RSA operations : 1
                20: Max failed user logins allowed : 10
                21: Enable high availability recovery : 1
                22: Enable activation : 0
                23: Enable auto-activation : 0
                25: Minimum pin length (inverted: 255 - min) : 247
                26: Maximum pin length : 255
                28: Enable Key Management Functions : 1
                29: Enable RSA signing without confirmation : 1
                31: Enable private key unmasking : 1
                32: Enable secret key unmasking : 1
                33: Enable RSA PKCS mechanism : 1
                34: Enable CBC-PAD (un)wrap keys of any size : 1
                37: Enable enforcing Secure Trusted Channel : 1
                39: Enable Start/End Date Attributes : 1
                40: Enable Per-Key Authorization Data : 1
                41: Enable Partition Version : 1
                42: Enable CPv1 : 1
                43: Enable non-FIPS algorithms : 1
                44: Enable Extended Domain Management : 1
                45: Enable ECDSA/RSA Prehash SigVer : 1

        Partition Policies
                 0: Allow private key cloning : 1
                 1: Allow private key wrapping : 0
                 2: Allow private key unwrapping : 1
                 3: Allow private key masking : 1
                 4: Allow secret key cloning : 1
                 5: Allow secret key wrapping : 1
                 6: Allow secret key unwrapping : 1
                 7: Allow secret key masking : 1
                 9: Allow digest key : 0
                10: Allow multipurpose keys : 1
                11: Allow changing key attributes : 1
                15: Ignore failed challenge responses : 1
                16: Operate without RSA blinding : 1
                17: Allow signing with non-local keys : 1
                18: Allow raw RSA operations : 1
                20: Max failed user logins allowed : 10
                21: Allow high availability recovery : 1
                25: Minimum pin length (inverted: 255 - min) : 247
                26: Maximum pin length : 255
                28: Allow Key Management Functions : 1
                29: Perform RSA signing without confirmation : 1
                31: Allow private key unmasking : 1
                32: Allow secret key unmasking : 1
                33: Allow RSA PKCS mechanism : 1
                34: Allow CBC-PAD (un)wrap keys of any size : 1
                37: Force Secure Trusted Channel : 0
                39: Allow Start/End Date Attributes : 0
                40: Require Per-Key Authorization Data : 1
                41: Partition Version : 1
                42: Allow CPv1 : 0
                43: Allow non-FIPS algorithms : 1
                44: Allow Extended Domain Management : 0
                45: Allow ECDSA/RSA Prehash SigVer : 1


Command Result : No Error


lunacm:>role login -name co -password <your_unique_password_for_co>

Command Result : No Error

4.Restore the contents of the Backup HSM (slot 204 in this example) onto the current target slot, to which you are logged-in.


lunacm:>partition archive restore -slot 204 -partition mldsa -password <your_unique_password_for_co>

        You are restoring an SKS partition.

        Logging in to partition mldsa on slot 204 as the user.

        Verifying that all objects can be restored...

        6 objects found; attempting to restore 6 objects

        Restoring the SKS partition

        The SMKs were restored from partition mldsa successfully.

        Restoring SKS Blobs...

        Object 31 has been restored from partition mldsa (handle 155).
        Object 40 has been restored from partition mldsa (handle 148).
        Object 32 has been restored from partition mldsa (handle 142).
        Object 64 has been restored from partition mldsa (handle 132).
        Object 147 has been restored from partition mldsa (handle 100).
        Object 151 has been restored from partition mldsa (handle 27).

        Restore Successfully Completed.

        6 objects have been restored from partition mldsa on slot 204.

Command Result : No Error


lunacm:>exit
 
(TITLE) menu titles, (99 or FULL) Full Help, (NONE) No help, (0 or EXIT) Quit


Status: Doing great, no errors (CKR_OK)

Enter your choice : 1

Slots available:
        slot#3 - User Token Slot
        slot#4 - User Token Slot
        slot#204 - Admin Token Slot
Select a slot (last selected slot = 3): 4

Status: Doing great, no errors (CKR_OK)

(TITLE) menu titles, (99 or FULL) Full Help, (NONE) No help, (0 or EXIT) Quit


Status: Doing great, no errors (CKR_OK)
Enter your choice : 3

Sessions available:
        session#1 - slot 3
        session#2 - slot 4
Select a session: 2
Partition SO            [0]
Crypto Officer          [1]
Crypto User             [2]
Limited Crypto Officer  [3]: 1
Enter PIN            : ***********


Status: Doing great, no errors (CKR_OK)

(TITLE) menu titles, (99 or FULL) Full Help, (NONE) No help, (0 or EXIT) Quit


Status: Doing great, no errors (CKR_OK)
Enter your choice : 43

Sessions available:
        session#1 - slot 3
        session#2 - slot 4
Select a session: 2
Mechanism to use:

(RSA)
  [1] RSA
  [2] SHA1-RSA            [3] SHA224-RSA         [4] SHA256-RSA
  [5] SHA384-RSA          [6] SHA512-RSA
  [7] RSA-PSS             [8] SHA1-RSA-PSS      [9] SHA224-RSA-PSS
 [10] SHA256-RSA-PSS     [11] SHA384-RSA-PSS    [12] SHA512-RSA-PSS
 [13] RSA_X9_31
 [14] SHA1-RSA_X9_31     [15] SHA224-RSA_X9_31 [16] SHA256-RSA_X9_31
 [17] SHA384-RSA_X9_31   [18] SHA512-RSA_X9_31
 [19] RSA_X_509

(DSA)
 [20] DSA                [21] SHA1-DSA

(ECDSA)
 [30] ECDSA
 [31] SHA1-ECDSA         [32] SHA224-ECDSA      [33] SHA256-ECDSA
 [34] SHA384-ECDSA       [35] SHA512-ECDSA      [36] SHA256-ECDSA-GBCS

(KCDSA)
 [40] HAS160-KCDSA
 [41] SHA1-KCDSA         [42] SHA224-KCDSA      [43] SHA256-KCDSA
 [44] SHA384-KCDSA       [45] SHA512-KCDSA

(KCDSA - NO_PAD)
 [46] HAS160-KCDSA
 [47] SHA1-KCDSA         [48] SHA224-KCDSA      [49] SHA256-KCDSA
 [50] SHA384-KCDSA
 [51] SHA512-KCDSA

(Digest Based HMAC)
 [60] SHA1-HMAC          [61] SHA1-HMAC-GEN
 [62] SHA224-HMAC        [63] SHA224-HMAC-GEN
 [64] SHA256-HMAC        [65] SHA256-HMAC-GEN
 [66] SHA384-HMAC        [67] SHA384-HMAC-GEN
 [68] SHA512-HMAC        [69] SHA512-HMAC-GEN

(Symmetric Key MAC)
 [70] DES-MAC
 [80] DES3-MAC           [81] DES3-CMAC         [82] DES3-X919-MAC
 [90] AES-MAC            [91] AES-CMAC          [92] AES-GMAC
[110] RC2-MAC            [111] RC2-MAC-GEN
[120] RC5-MAC            [121] RC5-MAC-GEN
[130] SEED-MAC           [131] SEED-CMAC
[140] ARIA-MAC           [141] ARIA-CMAC

(SM3 Based HMAC)
[150] SM3-HMAC           [151] SM3-HMAC-GEN

(EDDSA)
[160] NACL-EDDSA         [161] EDDSA
[162] SHA1-NACL-EDDSA    [163] SHA1-EDDSA
[164] SHA224-NACL-EDDSA  [165] SHA224-EDDSA
[166] SHA256-NACL-EDDSA  [167] SHA256-EDDSA
[168] SHA384-NACL-EDDSA  [169] SHA384-EDDSA
[170] SHA512-NACL-EDDSA  [171] SHA512-EDDSA
[172] EDDSA-PH

(SM2/SM3/SM4)
[180] SM3-SM2DSA     [181] SHA1-SM2DSA
[182] SHA224-SM2DSA  [183] SHA256-SM2DSA
[184] SHA384-SM2DSA  [185] SHA512-SM2DSA

(5G - 3GPP)
[190] Milenage Auth      [191] Milenage Resync  [192] Milenage AUTS
[193] TUAK Auth          [194] TUAK Resync      [195] TUAK AUTS
[196] COMP128 Auth

(SHA-3)
[200] SHA3-224-HMAC      [201] SHA3-224-HMAC-GEN
[202] SHA3-256-HMAC      [203] SHA3-256-HMAC-GEN
[204] SHA3-384-HMAC      [205] SHA3-384-HMAC-GEN
[206] SHA3-512-HMAC      [207] SHA3-512-HMAC-GEN
[208] SHA3-224-RSA       [209] SHA3-256-RSA
[210] SHA3-384-RSA       [211] SHA3-512-RSA
[212] SHA3-224-RSA-PSS   [213] SHA3-256-RSA-PSS
[214] SHA3-384-RSA-PSS   [215] SHA3-512-RSA-PSS
[216] SHA3-224-DSA       [217] SHA3-256-DSA
[218] SHA3-384-DSA       [219] SHA3-512-DSA
[220] SHA3-224-ECDSA     [221] SHA3-256-ECDSA
[222] SHA3-384-ECDSA     [223] SHA3-512-ECDSA
[224] SHA3-224-EDDSA     [225] SHA3-256-EDDSA
[226] SHA3-384-EDDSA     [227] SHA3-512-EDDSA

(Post Quantum Crypto)
[229] HSS
[230] ML-DSA             [231] ML-DSA HASH
[232] ML-DSA_SHA224      [233] ML-DSA_SHA256
[234] ML-DSA_SHA384      [235] ML-DSA_SHA512
[236] ML-DSA_SHA3_224    [237] ML-DSA_SHA3_256
[238] ML-DSA_SHA3_384    [239] ML-DSA_SHA3_512
[240] ML_DSA_SHAKE128    [241] ML_DSA_SHAKE256
[242] ML_DSA EXTMU
Selection : 230

Do you wish to add a parameter to mechanism ( CKM_ML_DSA ) - Yes[1] No[0] : testing123

You must enter a number between 0 and 1: 0

NOTE: 512 bytes max from this prompt, use option 98 to switch to file input for larger data sets
Enter data to verify: testing123

Enter key used to verify (0 to list available objects) : 0

handle        151 (0x00000097) -- label: ML-DSA-87 Private Key
handle        147 (0x00000093) -- label: ML-DSA-87 Public Key
handle         64 (0x00000040) -- label: ML-DSA-65 Private Key
handle         32 (0x00000020) -- label: ML-DSA-65 Public Key
handle         40 (0x00000028) -- label: ML-DSA-44 Private Key
handle         31 (0x0000001f) -- label: ML-DSA-44 Public Key

Number of objects found = 6


Enter key used to verify (0 to list available objects) : 147

The following data was recovered from file SIGN.BIN
(hex) bb40c3ee2aac11062aaf401a6b9ee8376635b5579... clipped for length ...4677b9fb2cfdce00000000000000000000007121a2029323841
Verification was successful.
Status: Doing great, no errors (CKR_OK)

(TITLE) menu titles, (99 or FULL) Full Help, (NONE) No help, (0 or EXIT) Quit


Status: Doing great, no errors (CKR_OK)
Enter your choice : 42

Sessions available:
        session#1 - slot 3
        session#2 - slot 4
Select a session: 2
Mechanism to use:

(RSA)
  [1] RSA
  [2] SHA1-RSA            [3] SHA224-RSA         [4] SHA256-RSA
  [5] SHA384-RSA          [6] SHA512-RSA
  [7] RSA-PSS             [8] SHA1-RSA-PSS      [9] SHA224-RSA-PSS
 [10] SHA256-RSA-PSS     [11] SHA384-RSA-PSS    [12] SHA512-RSA-PSS
 [13] RSA_X9_31
 [14] SHA1-RSA_X9_31     [15] SHA224-RSA_X9_31 [16] SHA256-RSA_X9_31
 [17] SHA384-RSA_X9_31   [18] SHA512-RSA_X9_31
 [19] RSA_X_509

(DSA)
 [20] DSA                [21] SHA1-DSA

(ECDSA)
 [30] ECDSA
 [31] SHA1-ECDSA         [32] SHA224-ECDSA      [33] SHA256-ECDSA
 [34] SHA384-ECDSA       [35] SHA512-ECDSA      [36] SHA256-ECDSA-GBCS

(KCDSA)
 [40] HAS160-KCDSA
 [41] SHA1-KCDSA         [42] SHA224-KCDSA      [43] SHA256-KCDSA
 [44] SHA384-KCDSA       [45] SHA512-KCDSA

(KCDSA - NO_PAD)
 [46] HAS160-KCDSA
 [47] SHA1-KCDSA         [48] SHA224-KCDSA      [49] SHA256-KCDSA
 [50] SHA384-KCDSA
 [51] SHA512-KCDSA

(Digest Based HMAC)
 [60] SHA1-HMAC          [61] SHA1-HMAC-GEN
 [62] SHA224-HMAC        [63] SHA224-HMAC-GEN
 [64] SHA256-HMAC        [65] SHA256-HMAC-GEN
 [66] SHA384-HMAC        [67] SHA384-HMAC-GEN
 [68] SHA512-HMAC        [69] SHA512-HMAC-GEN

(Symmetric Key MAC)
 [70] DES-MAC
 [80] DES3-MAC           [81] DES3-CMAC         [82] DES3-X919-MAC
 [90] AES-MAC            [91] AES-CMAC          [92] AES-GMAC
[110] RC2-MAC            [111] RC2-MAC-GEN
[120] RC5-MAC            [121] RC5-MAC-GEN
[130] SEED-MAC           [131] SEED-CMAC
[140] ARIA-MAC           [141] ARIA-CMAC

(SM3 Based HMAC)
[150] SM3-HMAC           [151] SM3-HMAC-GEN

(EDDSA)
[160] NACL-EDDSA         [161] EDDSA
[162] SHA1-NACL-EDDSA    [163] SHA1-EDDSA
[164] SHA224-NACL-EDDSA  [165] SHA224-EDDSA
[166] SHA256-NACL-EDDSA  [167] SHA256-EDDSA
[168] SHA384-NACL-EDDSA  [169] SHA384-EDDSA
[170] SHA512-NACL-EDDSA  [171] SHA512-EDDSA
[172] EDDSA-PH

(SM2/SM3/SM4)
[180] SM3-SM2DSA     [181] SHA1-SM2DSA
[182] SHA224-SM2DSA  [183] SHA256-SM2DSA
[184] SHA384-SM2DSA  [185] SHA512-SM2DSA

(5G - 3GPP)
[190] Milenage Auth      [191] Milenage Resync  [192] Milenage AUTS
[193] TUAK Auth          [194] TUAK Resync      [195] TUAK AUTS
[196] COMP128 Auth

(SHA-3)
[200] SHA3-224-HMAC      [201] SHA3-224-HMAC-GEN
[202] SHA3-256-HMAC      [203] SHA3-256-HMAC-GEN
[204] SHA3-384-HMAC      [205] SHA3-384-HMAC-GEN
[206] SHA3-512-HMAC      [207] SHA3-512-HMAC-GEN
[208] SHA3-224-RSA       [209] SHA3-256-RSA
[210] SHA3-384-RSA       [211] SHA3-512-RSA
[212] SHA3-224-RSA-PSS   [213] SHA3-256-RSA-PSS
[214] SHA3-384-RSA-PSS   [215] SHA3-512-RSA-PSS
[216] SHA3-224-DSA       [217] SHA3-256-DSA
[218] SHA3-384-DSA       [219] SHA3-512-DSA
[220] SHA3-224-ECDSA     [221] SHA3-256-ECDSA
[222] SHA3-384-ECDSA     [223] SHA3-512-ECDSA
[224] SHA3-224-EDDSA     [225] SHA3-256-EDDSA
[226] SHA3-384-EDDSA     [227] SHA3-512-EDDSA

(Post Quantum Crypto)
[229] HSS
[230] ML-DSA             [231] ML-DSA HASH
[232] ML-DSA_SHA224      [233] ML-DSA_SHA256
[234] ML-DSA_SHA384      [235] ML-DSA_SHA512
[236] ML-DSA_SHA3_224    [237] ML-DSA_SHA3_256
[238] ML-DSA_SHA3_384    [239] ML-DSA_SHA3_512
[240] ML_DSA_SHAKE128    [241] ML_DSA_SHAKE256
[242] ML_DSA EXTMU
Selection : 230

Do you wish to add a parameter to mechanism ( CKM_ML_DSA ) - Yes[1] No[0] : 0

NOTE: 512 bytes max from this prompt, use option 98 to switch to file input for larger data sets
Enter data to sign: testing123

Enter key used for signature (0 to list available objects) : 0

handle        151 (0x00000097) -- label: ML-DSA-87 Private Key
handle        147 (0x00000093) -- label: ML-DSA-87 Public Key
handle         64 (0x00000040) -- label: ML-DSA-65 Private Key
handle         32 (0x00000020) -- label: ML-DSA-65 Public Key
handle         40 (0x00000028) -- label: ML-DSA-44 Private Key
handle         31 (0x0000001f) -- label: ML-DSA-44 Public Key

Number of objects found = 6


Enter key used for signature (0 to list available objects) : 151

The following data was saved to file SIGN.BIN
(hex) 31e4a5f52e514e89c6861485f50f298ba53ef4b6bb... clipped for length ...0000000000000000000000000000000009101519282a2c32
Status: Doing great, no errors (CKR_OK)

(TITLE) menu titles, (99 or FULL) Full Help, (NONE) No help, (0 or EXIT) Quit


Status: Doing great, no errors (CKR_OK)
Enter your choice : 43

Sessions available:
        session#1 - slot 3
        session#2 - slot 4
Select a session: 1
Mechanism to use:

(RSA)
  [1] RSA
  [2] SHA1-RSA            [3] SHA224-RSA         [4] SHA256-RSA
  [5] SHA384-RSA          [6] SHA512-RSA
  [7] RSA-PSS             [8] SHA1-RSA-PSS      [9] SHA224-RSA-PSS
 [10] SHA256-RSA-PSS     [11] SHA384-RSA-PSS    [12] SHA512-RSA-PSS
 [13] RSA_X9_31
 [14] SHA1-RSA_X9_31     [15] SHA224-RSA_X9_31 [16] SHA256-RSA_X9_31
 [17] SHA384-RSA_X9_31   [18] SHA512-RSA_X9_31
 [19] RSA_X_509

(DSA)
 [20] DSA                [21] SHA1-DSA

(ECDSA)
 [30] ECDSA
 [31] SHA1-ECDSA         [32] SHA224-ECDSA      [33] SHA256-ECDSA
 [34] SHA384-ECDSA       [35] SHA512-ECDSA      [36] SHA256-ECDSA-GBCS

(KCDSA)
 [40] HAS160-KCDSA
 [41] SHA1-KCDSA         [42] SHA224-KCDSA      [43] SHA256-KCDSA
 [44] SHA384-KCDSA       [45] SHA512-KCDSA

(KCDSA - NO_PAD)
 [46] HAS160-KCDSA
 [47] SHA1-KCDSA         [48] SHA224-KCDSA      [49] SHA256-KCDSA
 [50] SHA384-KCDSA
 [51] SHA512-KCDSA

(Digest Based HMAC)
 [60] SHA1-HMAC          [61] SHA1-HMAC-GEN
 [62] SHA224-HMAC        [63] SHA224-HMAC-GEN
 [64] SHA256-HMAC        [65] SHA256-HMAC-GEN
 [66] SHA384-HMAC        [67] SHA384-HMAC-GEN
 [68] SHA512-HMAC        [69] SHA512-HMAC-GEN

(Symmetric Key MAC)
 [70] DES-MAC
 [80] DES3-MAC           [81] DES3-CMAC         [82] DES3-X919-MAC
 [90] AES-MAC            [91] AES-CMAC          [92] AES-GMAC
[110] RC2-MAC            [111] RC2-MAC-GEN
[120] RC5-MAC            [121] RC5-MAC-GEN
[130] SEED-MAC           [131] SEED-CMAC
[140] ARIA-MAC           [141] ARIA-CMAC

(SM3 Based HMAC)
[150] SM3-HMAC           [151] SM3-HMAC-GEN

(EDDSA)
[160] NACL-EDDSA         [161] EDDSA
[162] SHA1-NACL-EDDSA    [163] SHA1-EDDSA
[164] SHA224-NACL-EDDSA  [165] SHA224-EDDSA
[166] SHA256-NACL-EDDSA  [167] SHA256-EDDSA
[168] SHA384-NACL-EDDSA  [169] SHA384-EDDSA
[170] SHA512-NACL-EDDSA  [171] SHA512-EDDSA
[172] EDDSA-PH

(SM2/SM3/SM4)
[180] SM3-SM2DSA     [181] SHA1-SM2DSA
[182] SHA224-SM2DSA  [183] SHA256-SM2DSA
[184] SHA384-SM2DSA  [185] SHA512-SM2DSA

(5G - 3GPP)
[190] Milenage Auth      [191] Milenage Resync  [192] Milenage AUTS
[193] TUAK Auth          [194] TUAK Resync      [195] TUAK AUTS
[196] COMP128 Auth

(SHA-3)
[200] SHA3-224-HMAC      [201] SHA3-224-HMAC-GEN
[202] SHA3-256-HMAC      [203] SHA3-256-HMAC-GEN
[204] SHA3-384-HMAC      [205] SHA3-384-HMAC-GEN
[206] SHA3-512-HMAC      [207] SHA3-512-HMAC-GEN
[208] SHA3-224-RSA       [209] SHA3-256-RSA
[210] SHA3-384-RSA       [211] SHA3-512-RSA
[212] SHA3-224-RSA-PSS   [213] SHA3-256-RSA-PSS
[214] SHA3-384-RSA-PSS   [215] SHA3-512-RSA-PSS
[216] SHA3-224-DSA       [217] SHA3-256-DSA
[218] SHA3-384-DSA       [219] SHA3-512-DSA
[220] SHA3-224-ECDSA     [221] SHA3-256-ECDSA
[222] SHA3-384-ECDSA     [223] SHA3-512-ECDSA
[224] SHA3-224-EDDSA     [225] SHA3-256-EDDSA
[226] SHA3-384-EDDSA     [227] SHA3-512-EDDSA

(Post Quantum Crypto)
[229] HSS
[230] ML-DSA             [231] ML-DSA HASH
[232] ML-DSA_SHA224      [233] ML-DSA_SHA256
[234] ML-DSA_SHA384      [235] ML-DSA_SHA512
[236] ML-DSA_SHA3_224    [237] ML-DSA_SHA3_256
[238] ML-DSA_SHA3_384    [239] ML-DSA_SHA3_512
[240] ML_DSA_SHAKE128    [241] ML_DSA_SHAKE256
[242] ML_DSA EXTMU
Selection : 230

Do you wish to add a parameter to mechanism ( CKM_ML_DSA ) - Yes[1] No[0] : 0

NOTE: 512 bytes max from this prompt, use option 98 to switch to file input for larger data sets
Enter data to verify: testing123

Enter key used to verify (0 to list available objects) : 0

handle        111 (0x0000006f) -- label: ML-DSA-87 Private Key
handle        112 (0x00000070) -- label: ML-DSA-87 Public Key
handle        109 (0x0000006d) -- label: ML-DSA-65 Private Key
handle        102 (0x00000066) -- label: ML-DSA-65 Public Key
handle         97 (0x00000061) -- label: ML-DSA-44 Private Key
handle         93 (0x0000005d) -- label: ML-DSA-44 Public Key

Number of objects found = 6


Enter key used to verify (0 to list available objects) : 112

The following data was recovered from file SIGN.BIN
(hex) 31e4a5f52e514e89c6861485f50f298ba53ef4b6b... clipped for length ...0000000000000000000000000000000000009101519282a2c32
Verification was successful.
Status: Doing great, no errors (CKR_OK)

(TITLE) menu titles, (99 or FULL) Full Help, (NONE) No help, (0 or EXIT) Quit


Status: Doing great, no errors (CKR_OK)
Enter your choice :