Mental model
A Docker image is a pre-packaged, self-consistent snapshot of an operating system. docker build produces that snapshot from a recipe file (a Dockerfile); docker run runs it. You do not need to know anything beyond these two commands. You do not need to clone a repository for this lesson: the full Dockerfile is below, and copying it into a file on your machine is enough.
Why no source build is needed
Early materials reviewed during this course’s research recommended building OpenSSL 3.5 from source (see the native-install-deep-dive lesson, which carries an important warning about that material: three different days gave three different, contradictory build instructions). The Dockerfile in this lesson instead installs directly from a package manager (Debian trixie’s apt repository), because that is enough: Debian trixie’s own repository ships 3.5.7MEASURED, and from 3.5 onward OpenSSL’s ML-KEM, ML-DSA and SLH-DSA support is in the default provider with no special build flags.
FROM debian:trixie-slim
RUN apt-get update -qq \
&& apt-get install -y -qq --no-install-recommends \
openssl \
ca-certificates \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /lab
CMD ["bash"]
Line by line: FROM sets the base image (here the slimmed-down “slim” variant of Debian’s “trixie” release). RUN gives shell commands to execute while the image is built; here it refreshes the package list, installs openssl and the certificate package, then deletes the downloaded package cache to keep the image small. WORKDIR sets the default working directory inside the container. CMD says what to run when the container starts with docker run and no other command is given (here a bash shell).
This Dockerfile was actually tested with docker build and docker run on 2026-09-04; the outputs of the lab commands above are real results, not estimates. The public key file of the ML-DSA-65 key (PEM format, base64 encoded) holds 2726 BMEASURED. That differs from the raw 1952-byte public key FIPS 204 specifies (see M4), because the PEM format adds base64 encoding and an ASN.1 wrapper.
If you want a persistent shell
docker run --rm -it pqc-academy-lab bash
This opens an interactive bash session inside the container. Instead of typing docker run before every command, you can run the lab commands from other lessons one after another in this shell. The --rm flag you saw in every docker run above cleans up the container when the session ends (otherwise stopped containers pile up after each docker run, visible with docker ps -a). If you want to keep data, mount your own directory with -v $(pwd):/lab. The -it flag allocates an interactive terminal (i) and a pseudo-TTY (t), which you need to run an interactive program like bash.
Is this the course’s “only” OpenSSL version
No, and it matters to say so clearly: the container you build in this lesson has OpenSSL 3.5.7MEASURED, but the certificate chain measurements in M7 were made on a different machine with OpenSSL 3.6.2. Both are 3.5 or later, so they support ML-KEM, ML-DSA and SLH-DSA the same way. The exact patch version (3.5.7 or 3.6.2) does not matter; what matters is that major.minor is at least 3.5. When a number in this course is labelled “measured with OpenSSL X.Y”, that tells you which environment the measurement came from. If your container shows a different patch version, that is not an error, just a natural difference depending on when you ran apt-get update.