# Addendum 06 — single-port authenticated TLS transition measurement

Sealed before execution. This is an owned Node 22/OpenSSL 3.5 loopback harness, separate from QScout. A favorable outcome is not assumed. The earlier TLS matrix used separate ephemeral ports and disabled certificate verification; it remains historical and cannot establish continuity.

Bind one OS-assigned 127.0.0.1 TCP port. Use that exact port for three sequential server policies: X25519, X25519MLKEM768-only, then rollback X25519. Each policy change closes the existing listener, waits a deliberate 250 ms, and rebinds the same port; record close/listen UTC and monotonic timestamps, PID, errors, and port release. There is no claim of uninterrupted listener availability. A compatible client sends one request every 100 ms throughout all phases and restart windows, with 700 ms per-request timeout. Target durations are 900 ms per policy and 250 ms per restart. Record every started probe, including failures, and separate per-phase and transition denominators; no retries or omission. Also send an X25519-only negative while hybrid-only and an untrusted-CA negative; after rollback, an X25519-only client must get an application response. Keep every outcome even when an expected check fails.

Create a new lab RSA self-signed certificate with SAN localhost and private key mode 0600 under lab/tls/private only. Compatible client explicitly passes this cert as CA, `rejectUnauthorized=true`, `servername=localhost`, verifies authorized true and peer fingerprint, and records hostname/verification failures. Wrong-CA client uses an unrelated lab CA; it must not get an application response. TLS 1.3 only. Enable OpenSSL SSL_trace for synthetic sockets, retain raw trace separately, and associate trace NamedGroup excerpts to recorded phase boundaries and request IDs where feasible. A trace lacking per-request association supports only phase policy inference. Preserve raw stdout/stderr and script/cert hashes. The script is sealed by SHA256 before execution; outputs include that SHA, cert fingerprint, timing, request IDs and port. Verify port release after run.

A measured failure is valid. Success can establish only sampled behavior of this one owned Node/OpenSSL endpoint with trusted classical RSA identity. It cannot establish production/customer availability, universal client compatibility, PQ authentication, QScout actuation, or zero downtime. Private key/keylog must never be copied into public packet; public summary may include public certificate fingerprint and scoped, secret-screened trace excerpts only after review.
