CALI research

CALI v2.0 roadmap

Implemented, specified and planned work across operations, algorithms, providers, policy, storage, deployment and packaging.

Implemented research slice

  • HTTP health, capabilities, policy resolution, key creation, sign and verify;
  • pinned policy and explicit failure categories;
  • opaque tenant-bound key references;
  • in-memory software provider and non-secret evidence;
  • OpenAPI, JSON Schema, examples and contract tests; and
  • native personal-site research documentation.

Next operation coverage

  1. encryption and decryption;
  2. MAC generation and verification;
  3. key agreement;
  4. encapsulation and decapsulation;
  5. key derivation;
  6. symmetric-key lifecycle;
  7. rotation, transformation and migration; and
  8. richer discovery.

Algorithm priorities

The v2 examples center RSA-PSS, ECDSA P-256, ML-DSA-65 and the ECC-to-ML-DSA transition. Runtime work must add provider-specific execution, test vectors, negative tests and explicit profiles before any algorithm is labeled implemented.

Provider backends

Planned adapters include PKCS#11, OpenSSL, KMIP/KMS, JCA and cloud key services. Each adapter publishes capabilities and limitations without changing CALI semantics.

Platform work

  • richer policy templates and security properties;
  • gRPC and REST/HTTP gateway bindings;
  • persistent storage encrypted at rest;
  • hierarchical policy with regulatory profiles;
  • local, remote and hybrid deployment modes;
  • declarative key-evolution policy;
  • Docker and Kubernetes packaging; and
  • a black-box conformance runner and versioned test vectors.

Release rule

A roadmap item moves to implemented only when code, schemas, OpenAPI, examples, negative tests, documentation and security limitations agree.