Home / Companies / Cloudflare / Blog / Post Details
Content Deep Dive

Post-quantum authentication to origins is now supported

Blog post from Cloudflare

Post Details
Company
Date Published
Author
-
Word Count
2,667
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

Cloudflare has implemented post-quantum authentication for its Authenticated Origin Pulls and Custom Origin Trust Store products, marking a significant step in its roadmap towards full post-quantum security by 2029. This initiative aims to protect against future quantum computer threats that could compromise classical encryption methods. The new capability supports Module-Lattice-Based Digital Signature Algorithm (ML-DSA) signatures to secure connections between Cloudflare and customer origin servers, differentiating in approach from visitor-to-Cloudflare connections. The company has also collaborated with Google and the IETF on developing Merkle Tree Certificates for fast post-quantum web certificates, targeting 2027 for initial deployments. Cloudflare's deployment is ahead of the broader WebPKI implementation, allowing the use of custom PKIs to expedite post-quantum authentication without the typical public infrastructure constraints. The company offers flexible configuration options, enabling customers to upload ML-DSA CAs to the Custom Origin Trust Store and configure Authenticated Origin Pulls with ML-DSA certificates. Furthermore, Cloudflare has updated its control and data plane services to support these new post-quantum features, and plans to integrate future updates as the ecosystem evolves, including anticipated native support for ML-DSA in Go 1.27.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.