diff --git a/ChangeLog.md b/ChangeLog.md
--- a/ChangeLog.md
+++ b/ChangeLog.md
@@ -1,5 +1,10 @@
 # ChangeLog for crypton-x509-util
 
+## 1.9.1
+
+* Show ML-DSA keys, with the seed when the file held one
+  [#35](https://github.com/kazu-yamamoto/crypton-certificate/pull/35)
+
 ## 1.9.0
 
 * Using "ram" instead of "memory"
diff --git a/crypton-x509-util.cabal b/crypton-x509-util.cabal
--- a/crypton-x509-util.cabal
+++ b/crypton-x509-util.cabal
@@ -1,6 +1,6 @@
 cabal-version:      >=1.10
 name:               crypton-x509-util
-version:            1.9.0
+version:            1.9.1
 license:            BSD3
 license-file:       LICENSE
 copyright:          Vincent Hanquez <vincent@snar.org>
@@ -28,14 +28,14 @@
     build-depends:
         base >=3 && <5,
         bytestring,
-        crypton >=1.1.0 && <1.2,
+        crypton >=1.1.0 && <2.3,
         crypton-asn1-encoding,
         crypton-asn1-types >=0.4.1 && <0.5,
         crypton-pem >=0.2.4 && <0.4,
-        crypton-x509 >=1.9.0 && <1.10,
-        crypton-x509-store >=1.9.0 && <1.10,
-        crypton-x509-system >=1.9.0 && <1.10,
-        crypton-x509-validation >=1.9.0 && <1.10,
+        crypton-x509 >=1.10 && <1.11,
+        crypton-x509-store >=1.10 && <1.11,
+        crypton-x509-system >=1.10 && <1.11,
+        crypton-x509-validation >=1.10 && <1.11,
         directory,
         ram,
         time-hourglass
diff --git a/src/Certificate.hs b/src/Certificate.hs
--- a/src/Certificate.hs
+++ b/src/Certificate.hs
@@ -1,7 +1,6 @@
 {-# LANGUAGE DeriveDataTypeable #-}
 {-# LANGUAGE OverloadedStrings #-}
 
-import Control.Applicative ((<$>))
 import Control.Monad
 import qualified Data.ByteArray as BA
 import qualified Data.ByteString as B
@@ -91,6 +90,9 @@
     showKnownExtension
         "authority-key-id"
         (X509.extensionGetE es :: Maybe (Either String X509.ExtAuthorityKeyId))
+    showKnownExtension
+        "name-constraint"
+        (X509.extensionGetE es :: Maybe (Either String X509.ExtNameConstraints))
   where
     showExt er = do
         putStrLn
@@ -115,6 +117,9 @@
         X509.PubKeyX448 _ -> printf "public key: ECDH (curve448)\n"
         X509.PubKeyEd25519 _ -> printf "public key: EdDSA (edwards25519)\n"
         X509.PubKeyEd448 _ -> printf "public key: EdDSA (edwards448)\n"
+        X509.PubKeyMLDSA44 _ -> printf "public key: ML-DSA-44\n"
+        X509.PubKeyMLDSA65 _ -> printf "public key: ML-DSA-65\n"
+        X509.PubKeyMLDSA87 _ -> printf "public key: ML-DSA-87\n"
         X509.PubKeyUnknown oid ws -> printf "public key: unknown: %s\n" (show oid)
         pk -> printf "public key: %s\n" (show pk)
   where
@@ -179,6 +184,9 @@
         X509.PubKeyX448 pubkey -> showPubHexdump "X448" pubkey
         X509.PubKeyEd25519 pubkey -> showPubHexdump "Ed25519" pubkey
         X509.PubKeyEd448 pubkey -> showPubHexdump "Ed448" pubkey
+        X509.PubKeyMLDSA44 pubkey -> showPubHexdump "ML-DSA-44" pubkey
+        X509.PubKeyMLDSA65 pubkey -> showPubHexdump "ML-DSA-65" pubkey
+        X509.PubKeyMLDSA87 pubkey -> showPubHexdump "ML-DSA-87" pubkey
         X509.PubKeyUnknown oid ws -> do
             printf "public key unknown: %s\n" (show oid)
             printf "  raw bytes: %s\n" (show ws)
@@ -261,6 +269,14 @@
         [ "priv:   " ++ hexdump privkey
         ]
 
+-- | An ML-DSA key is written as its seed, its expanded key, or both, so
+-- what is dumped is what the file actually held.
+showMLDSAHexdump :: X509.PrivKeyMLDSA p -> String
+showMLDSAHexdump k =
+    unlines $
+        maybe [] (\s -> ["seed:   " ++ hexdump s]) (X509.privkeyMLDSA_seed k)
+            ++ ["priv:   " ++ hexdump (X509.privkeyMLDSA_key k)]
+
 showASN1 :: Int -> [ASN1] -> IO ()
 showASN1 at = prettyPrint at
   where
@@ -398,6 +414,12 @@
                 putStrLn "Ed25519 KEY" >> putStrLn (showPrivHexdump k)
             [X509.PrivKeyEd448 k] ->
                 putStrLn "Ed448 KEY" >> putStrLn (showPrivHexdump k)
+            [X509.PrivKeyMLDSA44 k] ->
+                putStrLn "ML-DSA-44 KEY" >> putStrLn (showMLDSAHexdump k)
+            [X509.PrivKeyMLDSA65 k] ->
+                putStrLn "ML-DSA-65 KEY" >> putStrLn (showMLDSAHexdump k)
+            [X509.PrivKeyMLDSA87 k] ->
+                putStrLn "ML-DSA-87 KEY" >> putStrLn (showMLDSAHexdump k)
             _ -> error "private key unknown"
 
 doSystemMain _ = do
