Current signature schemes can use as few as 32 bytes per key and 64 bytes per signature [RFC8032], but post-quantum replacements are much larger. [...] a new form of X.509 certificate that integrates logging with certificate issuance [...] This achieves the following: Log entries do not scale with public key and signature sizes. Entries replace public keys with hashes and do not contain signatures
Comments
And maybe soon in even more places :) Merkle Tree Certificates (https://datatracker.ietf.org/doc/draft-ietf-plants-merkle-tr...) seems to be in order to "make space" for quantum-secure signatures if I understand it correctly: