Full Report
Cloudflare has added visibility into post-quantum (PQ) encryption in TLS 1.3 directly into HTTP Analytics, Log Explorer, and Logpush. Learn how to make sure your domain is protected with PQ encryption.
Analysis Summary
# Best Practices: Post-Quantum Cryptography Visibility and Transition
## Overview
These practices address the adoption, management, and auditing of post-quantum (PQ) encryption at the individual domain level. They leverage granular, per-connection telemetry to identify cryptographic gaps, remediate legacy configurations, and protect data against future quantum adversaries ("harvest-now-decrypt-later" attacks) using TLS 1.3 and hybrid key exchange mechanisms.
## Key Recommendations
### Immediate Actions
1. **Audit Domain-Level Telemetry:** Check the HTTP Traffic Analytics dashboard and active logs to determine the exact percentage of visitor connections to your domain currently secured with TLS 1.3 post-quantum encryption (`X25519MLKEM768`).
2. **Review Origin Logging:** Inspect your Logpush datasets or Log Explorer to evaluate the `OriginTLSKeyExchangeGroup` field. This confirms if your Cloudflare-to-origin connections are using post-quantum encryption.
### Short-term Improvements (1-3 months)
1. **Remediate Outdated Origin Configurations:** Deploy the Automatic Key Exchange feature for Cloudflare-to-origin connections to discover which cryptographic algorithms your origin servers support, correcting outdated settings that cause unexpected fallbacks to classical cryptography.
2. **Isolate Legacy Origins:** For ossified or legacy origin servers that cannot be easily updated to natively support post-quantum cryptography, place them behind a Cloudflare Tunnel to force the connection to Cloudflare over TLS 1.3 with `X25519MLKEM768`.
### Long-term Strategy (3+ months)
1. **Establish a Quantum-Readiness Roadmap:** Formulate an organizational transition plan aligned with the industry's 2030 quantum-readiness deadlines (and Cloudflare's target for full post-quantum security by 2029) to eliminate classical cryptographic dependencies.
2. **Prepare for Post-Quantum Authentication:** Monitor vendor capabilities to phase in post-quantum authentication (such as Merkle Tree Certificates for TLS signatures and certificates) as the technology achieves broader deployment.
## Implementation Guidance
### For Small Organizations
- Rely on Cloudflare’s default post-quantum product settings to secure traffic automatically.
- Periodically check the native HTTP Traffic Analytics dashboard to maintain high-level visibility into visitor encryption types without managing complex log architectures.
### For Medium Organizations
- Use Log Explorer and Automatic Key Exchange to actively troubleshoot individual domains.
- Identify specific origin servers lagging in post-quantum adoption and prioritize them for software configuration updates.
### For Large Enterprises
- Integrate the `OriginTLSKeyExchangeGroup` log parameter directly into centralized enterprise SIEM or data pipelines via Logpush.
- Run continuous compliance audits across all corporate domains to capture per-connection telemetry and definitively map out remaining cryptographic gaps.
## Configuration Examples
* **Logpush Telemetry Field:** To track the key exchange algorithm negotiated between Cloudflare and your backend servers, configure Logpush to capture:
text
OriginTLSKeyExchangeGroup
* **Target Hybrid Algorithm:** Verify or configure your systems to accept the hybrid ML-KEM key exchange protocol:
text
X25519MLKEM768
* **Legacy Server Protection Architecture:**
text
[Visitor] --(TLS 1.3 / X25519MLKEM768)--> [Cloudflare Edge] --(Cloudflare Tunnel / TLS 1.3 / X25519MLKEM768)--> [Legacy Origin Server]
## Compliance Alignment
- **FIPS 203:** Alignment with the Federal Information Processing Standard for hybrid ML-KEM post-quantum key exchange mechanisms.
- **Regulatory Frameworks:** Assists in meeting explicit quantum-readiness compliance mandates and deadlines tracking toward 2029–2030.
## Common Pitfalls to Avoid
- **Configurational Ossification:** Allowing outdated server settings to force an origin to connect using classical cryptography, even when the underlying origin server technically supports post-quantum algorithms.
- **Over-reliance on Macro Statistics:** Assuming your specific domains are secure based on global internet-wide averages (e.g., Cloudflare Radar stats) rather than validating your own domain-level and origin-level metrics.
- **Abandoning Legacy Origins:** Leaving older backend infrastructure completely unprotected by failing to use intermediate proxying tools like secure tunnels.
## Resources
- **Logpush Documentation:** hxxps://developers[.]cloudflare[.]com/logs/logpush/
- **Log Explorer Search Guidance:** hxxps://developers[.]cloudflare[.]com/log-explorer/log-search/
- **Cloudflare Account Dashboard:** hxxps://dash[.]cloudflare[.]com/
- **Post-Quantum SASE Architecture Information:** hxxps://blog[.]cloudflare[.]com/post-quantum-sase/
- **Post-Quantum to Origin Deployment Guide:** hxxps://developers[.]cloudflare[.]com/ssl/post-quantum-cryptography/pqc-to-origin/
- **NIST FIPS 203 Standard:** hxxps://csrc[.]nist[.]gov/pubs/fips/203/final