SECURITY Signal 203
Post-quantum authentication to origins is now supported
This closes the authentication gap on the origin connection, protecting against quantum-computer impersonation attacks rather than just harvest-now/decrypt-later encryption threats. Engineers can configure fully post-quantum mutually authenticated TLS to their origins today, ahead of WebPKI standardization.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
ML-DSA is supported across all FIPS 204 parameter sets (ML-DSA-44, ML-DSA-65, ML-DSA-87), with ML-DSA-44 recommended for most applications due to its performance and NIST category 2 security strength.
Post-quantum authentication could be deployed on the origin connection before the public WebPKI because Cloudflare controls the client side (enabling connection pooling) and has a pre-existing trust relationship with customers, removing the need for intermediate certificates and Certificate Transparency.
This is the first milestone toward Cloudflare's 2029 full post-quantum security target; Merkle Tree Certificates for the visitor-to-Cloudflare connection are being developed at the IETF with initial deployments targeting 2027.
THE CLUSTER
↗