About 70 percent of browser traffic reaching Cloudflare uses post-quantum TLS, but only about 15 percent of origin servers do. The gap is usually the server's OpenSSL version. Here is how to check an origin, which systems ship OpenSSL 3.5, and what to change in nginx.
Two Numbers From Cloudflare
On September 29, 2026, Cloudflare published two figures that belong side by side. About 70 percent of the browser traffic reaching its network is already protected with post-quantum encryption. Only about 15 percent of the origin servers Cloudflare connects to use it.
Post-quantum TLS changes how the two ends of a connection agree on the key that encrypts everything after the handshake. The standard method today relies on elliptic curve math that a large enough quantum computer could break. That computer does not exist yet, but traffic recorded now could be decrypted once it does, which matters for anything that has to stay private for years. The fix is a hybrid key exchange called X25519MLKEM768, which pairs today's X25519 with ML-KEM, the algorithm NIST standardized in 2024. If either half holds, the connection holds.
For a site behind Cloudflare, that leaves two legs. The visitor's connection to Cloudflare is post-quantum whenever the browser supports it, which is why the first figure is already so high. The connection from Cloudflare to your server depends on your server.
Cloudflare Is Ready, the Server Usually Is Not
Cloudflare now checks each origin roughly every 24 hours and, where the server supports it, opens the connection with the post-quantum key share straight away. The feature is on for every zone and every plan. It needs the SSL mode set to Full or Full (strict) and TLS 1.3 on the origin, since post-quantum key exchange does not exist in TLS 1.2 or earlier.
What is missing, most of the time, is a TLS library on the server that speaks ML-KEM. OpenSSL added it in version 3.5.0, released on April 8, 2025, and made the hybrid group part of its defaults at the same time. OpenSSL 3.5 is a long-term support release, maintained until April 2030.
Which Systems Ship OpenSSL 3.5
| System | OpenSSL | Hybrid group in the defaults |
|---|---|---|
| Ubuntu 22.04 | 3.0.2 | no |
| Ubuntu 24.04 | 3.0.13 | no |
| Ubuntu 26.04 | 3.5.5 | yes |
| Debian 12 | 3.0.x | no |
| Debian 13 | 3.5.x | yes |
| AlmaLinux 9.7 and 10.1 or later | 3.5.x | depends on the system crypto policy |
On RHEL-family systems the system-wide crypto policy decides which groups are enabled, so test rather than assume. Node.js carries its own copy of OpenSSL, and has bundled 3.5 since version 24.5.0 and 22.20.0, which matters only where Node terminates TLS itself.
The upshot is that most servers still on Ubuntu 22.04 or 24.04, or Debian 12, cannot do post-quantum TLS without moving to a newer release. The upstream OpenSSL 3.0 series they ship is also out of support, as we covered when it reached end of life, with the distributions backporting fixes on their own.
Check Your Origin
Test the origin's own address, not the proxied hostname, because a check against the hostname only tells you about Cloudflare's edge. You need an OpenSSL 3.5 or later client, and the openssl that ships with macOS is an older LibreSSL build that cannot run this test.
openssl s_client -connect ORIGIN_IP:443 -servername www.example.com -groups X25519MLKEM768 -brief </dev/null
If the output shows Negotiated TLS1.3 group: X25519MLKEM768, the server is ready. If the handshake fails, it does not offer the hybrid group. On an Enterprise plan, the OriginTLSKeyExchangeGroup field in Logpush shows which group Cloudflare actually used for each request to your origin.
The Usual Blocker Is an Old Curve List
Even with OpenSSL 3.5 in place, a hardening line copied from an older guide can switch post-quantum off. nginx uses the OpenSSL defaults only while ssl_ecdh_curve is left at auto. An explicit list without the hybrid group removes it:
ssl_protocols TLSv1.2 TLSv1.3;
# either delete ssl_ecdh_curve, or put the hybrid group first
ssl_ecdh_curve X25519MLKEM768:X25519:prime256v1:secp384r1;
Apache has no curve directive of its own. It passes a Groups list to OpenSSL through SSLOpenSSLConfCmd, so if you set one, include X25519MLKEM768. Cloudflare's own advice is to look beyond the web server too, since load balancers and other devices in front of it can carry the same legacy settings. And the hybrid key share is larger, 1,216 bytes against 32 for X25519, which OpenSSL notes can upset old firewalls that inspect the handshake.
If the Server Cannot Be Upgraded
Cloudflare's suggestion for an origin that cannot move is Cloudflare Tunnel. The connection between the cloudflared agent and Cloudflare's network already uses post-quantum key agreement, and the remaining hop from cloudflared to the application usually stays inside the same machine or private network.
It is the same algorithm GitHub is adding to SSH, as we noted with its SSH changes. Moving a fleet to an operating system release with OpenSSL 3.5, and checking the TLS settings on the way, is the kind of work Servers Management covers.
Sources
- Cloudflare: Is your domain using post-quantum encryption?
- Cloudflare: Automatic key exchange for origins
- Cloudflare docs: Post-quantum between Cloudflare and origin servers
- OpenSSL 3.5 release notes
- OpenSSL release strategy
- nginx: ssl_ecdh_curve
- Apache httpd: SSLOpenSSLConfCmd
- Ubuntu packages: openssl
- Debian tracker: openssl
Or read how we handle it in Servers Management.
Related Articles
AWS WAF Configuration for Web Application Security
Deploy and configure AWS WAF with managed rule groups, custom rules, rate limiting, and bot control to protect web applications from common threats.
SecurityEleven npm Packages Compromised in a 53 Minute Attack That Steals Every Credential Your Build Host Can Reach
On August 4, 2026 a worm pushed malicious versions of eleven npm caching packages inside a 53 minute window, harvesting npm tokens, GitHub PATs, AWS credentials, Kubernetes service account tokens and SSH keys. The headline was keyv and its 604 million monthly downloads, but keyv was the safest package on the list: its malicious release was a major version bump that no caret range accepts. The other ten were patch bumps, silently eligible for every dependency range in the ecosystem. That distinction, not the download count, decided who got hit. This is a practical guide to the defenses that actually change the outcome: what your semver range really grants, why npm install and npm ci are not interchangeable, when to disable install scripts and what breaks when you do, and how to check a tree you already have.
SecurityHow to Handle Secrets in CI Without Leaking Them Into Logs
The safest credential in your pipeline is the one that does not exist between jobs. OpenID Connect lets a workflow authenticate directly to a cloud provider and receive a token that expires on its own, which removes the stored key entirely. Masking is the backstop for everything left over, and it is worth knowing exactly where it stops working, because it relies on finding an exact match for the value. This guide covers the short-lived credential setup, the limits of redaction, and what to actually do in the ten minutes after a secret reaches a log.