Abstract
<title>Abstract</title> <p>CA/B Forum Ballot SC081v3 introduced a phased schedule reducing public TLS certificate maximum validity from 398 days to 47 days by March 2029, a forcing function exposing structural limits of revocation-by-expiry. DIT (Decentralized Identity and Trust) replaces the CA hierarchy entirely. Domain identity anchors in DNSSEC-committed ML-DSA-65 keys published via SVCB DNS records, with a three-level hierarchy (Identity Key, Epoch Authentication Key (EAK), and ephemeral session material) that eliminates CA-issued end-entity certificates. A SHA3-384 Merkle transparency log with witness cosigning (5-of-7 quorum) provides auditability without centralized log operators. The handshake follows the TLS 1.3 shape using X25519MLKEM768 hybrid key exchange and ML-DSA-65 authentication, achieving ∼6 KB on the warm path (comparable to classical TLS 1.3) and ∼34 KB on first contact. Normal identity key rotation is PQ-secure via dual ML-DSA-65 signatures; recovery rotation uses classical FROST-Schnorr threshold signing and is explicitly not claimed as post-quantum. Seven security theorems reduce DIT’s properties to ML-DSA-65 EUF-CMA, ML-KEM-768 IND-CCA2, HKDF-SHA3-384 PRF, and SHA3-384 collision resistance; the recovery path reduces to classical FROST-Schnorr unforgeability. Zero CA-issued end-entity certificates; epoch credentials rotate automatically.</p>