Skip to main content
SecuritySeptember 30, 20264 min read

Visitors Already Use Post-Quantum TLS. Most Servers Do Not

Get technical support

Patched, monitored, restored on a schedule

About 70 percent of browser traffic reaching Cloudflare uses post-quantum TLS, but only about 15 percent of origin servers do. The gap is usually the server's OpenSSL version. Here is how to check an origin, which systems ship OpenSSL 3.5, and what to change in nginx.

Two Numbers From Cloudflare

On September 29, 2026, Cloudflare published two figures that belong side by side. About 70 percent of the browser traffic reaching its network is already protected with post-quantum encryption. Only about 15 percent of the origin servers Cloudflare connects to use it.

Post-quantum TLS changes how the two ends of a connection agree on the key that encrypts everything after the handshake. The standard method today relies on elliptic curve math that a large enough quantum computer could break. That computer does not exist yet, but traffic recorded now could be decrypted once it does, which matters for anything that has to stay private for years. The fix is a hybrid key exchange called X25519MLKEM768, which pairs today's X25519 with ML-KEM, the algorithm NIST standardized in 2024. If either half holds, the connection holds.

For a site behind Cloudflare, that leaves two legs. The visitor's connection to Cloudflare is post-quantum whenever the browser supports it, which is why the first figure is already so high. The connection from Cloudflare to your server depends on your server.

Cloudflare Is Ready, the Server Usually Is Not

Cloudflare now checks each origin roughly every 24 hours and, where the server supports it, opens the connection with the post-quantum key share straight away. The feature is on for every zone and every plan. It needs the SSL mode set to Full or Full (strict) and TLS 1.3 on the origin, since post-quantum key exchange does not exist in TLS 1.2 or earlier.

What is missing, most of the time, is a TLS library on the server that speaks ML-KEM. OpenSSL added it in version 3.5.0, released on April 8, 2025, and made the hybrid group part of its defaults at the same time. OpenSSL 3.5 is a long-term support release, maintained until April 2030.

Which Systems Ship OpenSSL 3.5

SystemOpenSSLHybrid group in the defaults
Ubuntu 22.043.0.2no
Ubuntu 24.043.0.13no
Ubuntu 26.043.5.5yes
Debian 123.0.xno
Debian 133.5.xyes
AlmaLinux 9.7 and 10.1 or later3.5.xdepends on the system crypto policy

On RHEL-family systems the system-wide crypto policy decides which groups are enabled, so test rather than assume. Node.js carries its own copy of OpenSSL, and has bundled 3.5 since version 24.5.0 and 22.20.0, which matters only where Node terminates TLS itself.

The upshot is that most servers still on Ubuntu 22.04 or 24.04, or Debian 12, cannot do post-quantum TLS without moving to a newer release. The upstream OpenSSL 3.0 series they ship is also out of support, as we covered when it reached end of life, with the distributions backporting fixes on their own.

Check Your Origin

Test the origin's own address, not the proxied hostname, because a check against the hostname only tells you about Cloudflare's edge. You need an OpenSSL 3.5 or later client, and the openssl that ships with macOS is an older LibreSSL build that cannot run this test.

openssl s_client -connect ORIGIN_IP:443 -servername www.example.com -groups X25519MLKEM768 -brief </dev/null

If the output shows Negotiated TLS1.3 group: X25519MLKEM768, the server is ready. If the handshake fails, it does not offer the hybrid group. On an Enterprise plan, the OriginTLSKeyExchangeGroup field in Logpush shows which group Cloudflare actually used for each request to your origin.

The Usual Blocker Is an Old Curve List

Even with OpenSSL 3.5 in place, a hardening line copied from an older guide can switch post-quantum off. nginx uses the OpenSSL defaults only while ssl_ecdh_curve is left at auto. An explicit list without the hybrid group removes it:

ssl_protocols TLSv1.2 TLSv1.3;
# either delete ssl_ecdh_curve, or put the hybrid group first
ssl_ecdh_curve X25519MLKEM768:X25519:prime256v1:secp384r1;

Apache has no curve directive of its own. It passes a Groups list to OpenSSL through SSLOpenSSLConfCmd, so if you set one, include X25519MLKEM768. Cloudflare's own advice is to look beyond the web server too, since load balancers and other devices in front of it can carry the same legacy settings. And the hybrid key share is larger, 1,216 bytes against 32 for X25519, which OpenSSL notes can upset old firewalls that inspect the handshake.

If the Server Cannot Be Upgraded

Cloudflare's suggestion for an origin that cannot move is Cloudflare Tunnel. The connection between the cloudflared agent and Cloudflare's network already uses post-quantum key agreement, and the remaining hop from cloudflared to the application usually stays inside the same machine or private network.

It is the same algorithm GitHub is adding to SSH, as we noted with its SSH changes. Moving a fleet to an operating system release with OpenSSL 3.5, and checking the TLS settings on the way, is the kind of work Servers Management covers.

Sources

Or read how we handle it in Servers Management.

Related Articles

Security

AWS WAF Configuration for Web Application Security

Deploy and configure AWS WAF with managed rule groups, custom rules, rate limiting, and bot control to protect web applications from common threats.

Security

Eleven npm Packages Compromised in a 53 Minute Attack That Steals Every Credential Your Build Host Can Reach

On August 4, 2026 a worm pushed malicious versions of eleven npm caching packages inside a 53 minute window, harvesting npm tokens, GitHub PATs, AWS credentials, Kubernetes service account tokens and SSH keys. The headline was keyv and its 604 million monthly downloads, but keyv was the safest package on the list: its malicious release was a major version bump that no caret range accepts. The other ten were patch bumps, silently eligible for every dependency range in the ecosystem. That distinction, not the download count, decided who got hit. This is a practical guide to the defenses that actually change the outcome: what your semver range really grants, why npm install and npm ci are not interchangeable, when to disable install scripts and what breaks when you do, and how to check a tree you already have.

Security

How to Handle Secrets in CI Without Leaking Them Into Logs

The safest credential in your pipeline is the one that does not exist between jobs. OpenID Connect lets a workflow authenticate directly to a cloud provider and receive a token that expires on its own, which removes the stored key entirely. Masking is the backstop for everything left over, and it is worth knowing exactly where it stops working, because it relies on finding an exact match for the value. This guide covers the short-lived credential setup, the limits of redaction, and what to actually do in the ten minutes after a secret reaches a log.