Post-Quantum TLS Is Now a Platform Engineering Problem, Not a Research Topic

Post-quantum TLS has quietly shifted from a cryptography research subject to a live infrastructure concern, arriving through default changes in cloud SDKs, CDN configurations, and browser handshake preferences rather than formal migration projects. The immediate engineering challenge centers on key agreement, where hybrid schemes combining classical X25519 with ML-KEM are already shipping — notably via Cloudflare's X25519MLKEM768 — while post-quantum certificate authentication remains a longer, more complex migration. AWS has set a 2026 deadline to remove older Kyber-based support across KMS, ACM, and Secrets Manager endpoints, giving platform teams a concrete deprecation date to plan around. Microsoft has shipped Windows support for ML-KEM hybrid TLS groups and is targeting critical product migrations by 2029, while mid-2026 measurement data across tens of thousands of domains shows readiness remains highly uneven. Engineers are advised to audit which services, SDKs, middleboxes, and certificate workflows can handle larger handshake sizes and hybrid key exchange before defaults shift further beneath them.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in