
If you run mutual TLS between Cloudflare and your origin, you can now configure fully post-quantum authenticated connections using ML-DSA (FIPS 204) — a concrete step toward quantum-safe infrastructure with documented config steps and known caveats from Cloudflare's own rollout.
“We instead implemented the necessary functionality in Cloudflare’s CIRCL library to patch in support.”
“we have an admission to make: we snoozed Pingora Origin’s update to BoringSSL for four years, instead maintaining an internal fork to patch in additional functionality as needed.”
“Now, BoringSSL lives up to its name: over the past several years, there have been no CVEs or major changes.”
“The result was that even after testing the changes for weeks and a very slow release rollout looking for just this sort of regression, a small number of customers’ certificates were deemed invalid after the change, leading to an incident on June 10, 2026.”
Checking sign-in…
Loading comments…