Introduce ML-DSA (FIPS 204) as a first-class signature algorithm: - algorithm binding and streaming signature context - key generation specs/builders and key import specs - correct handling of pure vs pre-hash (SHA-512) ML-DSA JCA variants - policy security strength mapping (44/65/87 → 128/192/256) - comprehensive JUnit streaming sign/verify tests Signed-off-by: Leo Galambos <lg@hq.egothor.org>