Loading…
Loading…
Every article tagged migration, newest first.
10 articles
Cloudflare now supports post-quantum authentication between its edge and your origin server: Authenticated Origin Pulls and Custom Origin Trust Store both accept ML-DSA (FIPS 204) certificates. Paired with the X25519MLKEM768 key exchange already running on that hop, this is the first mainstream path to a fully post-quantum CDN-to-origin connection, not just the browser-to-edge leg.
Go 1.27, released this month, adds a crypto/mldsa package implementing ML-DSA (FIPS 204), plus ML-DSA support in crypto/x509 and crypto/tls. Post-quantum signatures are no longer a third-party dependency for Go services, they are a standard-library import. Here is what shipped and what it means for the migration.
By late 2025, around 43% of human web connections to Cloudflare were already using hybrid post-quantum key agreement, and X25519MLKEM768 is on by default in every major browser. The browser-to-edge hop is largely migrated. The unfinished half is origins, authentication, and your own stack. Here is where the line actually is.
NIST's transition report, IR 8547, names the dates the whole migration is timed against: today's public-key algorithms deprecated after 2030 and disallowed after 2035. Those are not distant abstractions, they are a schedule you have to work backwards from. Here is what the deadlines say and what they mean.
Most post-quantum material is one of two things: a vendor pitch that tells you to panic, or a standard that assumes you already have a doctorate. We built the part in between and put it online for free. The quantakrypto knowledge base is 11 collections, 49 topics, an 85-term glossary, and straight answers, with reading paths for employees, IT, and leadership.
Every post-quantum migration plan starts with the same step, and almost everyone underestimates it: know exactly what cryptography you have. A cryptographic bill of materials (CBOM) is that inventory in a standard, machine-readable form. Here is how to produce one across your code and your infrastructure in about a minute, with qScan, and what to do with it once you have it.
A one-time scan tells you where you stand today. Migration is a moving target, so we now track posture over time: an append-only snapshot per scan, a drift alert when a commit reintroduces quantum-vulnerable crypto, and migration projects that group findings by an identity that survives a line shift.
AI coding agents are fluent in cryptography and blind to its expiry date. The quantakrypto MCP gives them the missing sense. Here is the workflow we actually use: what to delegate to the agent, and where a human still decides.
Why we don't wait for a quantum computer to arrive before we act, and how to decide what to migrate first using a clock you already own.
“Add post-quantum” is not a single switch. The first deliverable of a serious migration is a cryptographic inventory: every place asymmetric cryptography is used, and what depends on it. Here is how national cyber agencies build one, and why it is the hard part.
Book a discovery call and get an indicative scope and pricing for your organisation.