Skip to content

Include support for Post-Quantum Cryptography as experimental #279

@tomato42

Description

@tomato42

Firefox ships with support for the X25519MLKEM768 group from draft-kwiatkowski-tls-ecdhe-mlkem-02. Similarly, current versions of openssl (>= 3.2.x) with current versions of oqsprovider (== 0.7.0) support that key exchange on the server side (other browsers and libraries with support for this key exchange are available).

At the very least, I think we should start to think at what point do we start including PQC in the configured groups.

Optimally, we should have a switch, labelled "experimental", to enable post-quantum key exchanges in the existing configs.

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationWrite down all the thingsspecsThis involves changes in recommendations

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions