Tombstone notice: This draft is no longer being pursued at the IETF. A variant of this proposal was adopted in [itu-t-x509-2019], which allows two keys to be placed in a certificate but only one used at a time. The major downside of this proposal is that it requires the large PQC key to be sent eveā¦