What Is Post-Quantum SSL? Why Should You Migrate Now?
· Post-Quantum
Post-Quantum cryptography refers to a new generation of security algorithms designed to withstand attacks from quantum computers, which can theoretically break the mathematical problems underlying today's RSA and ECC encryption using Shor's algorithm.
NIST's 2024 Standardization
After a years-long evaluation, NIST officially standardized three post-quantum algorithms in 2024: ML-KEM (CRYSTALS-Kyber) for key encapsulation, ML-DSA (CRYSTALS-Dilithium) for digital signatures, and SLH-DSA (SPHINCS+) as a hash-based backup signature scheme. These replace ECDH and RSA/ECDSA in TLS handshakes and certificate signing respectively.
The "Harvest Now, Decrypt Later" Threat
Even though capable quantum computers don't yet exist commercially, the threat is present today. State-sponsored actors are believed to be recording encrypted traffic now, planning to decrypt it once quantum hardware matures. This is especially critical for sectors requiring long-term confidentiality: healthcare, defense, legal, and finance.
The Hybrid Approach
The safest migration path combines classical (RSA/ECC) and post-quantum (ML-KEM) algorithms in a hybrid handshake. This preserves backward compatibility with today's browsers while adding quantum-resistant protection. Google Chrome, Firefox, Cloudflare and major cloud providers already use hybrid post-quantum key exchange in production.
The step you can take today is to enable hybrid key exchange (X25519MLKEM768) on your server; it works alongside your existing RSA or ECC certificate. Browser-trusted post-quantum (ML-DSA) certificates are not being issued yet; we will announce them on PekiSSL once they become available.