You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: src/content/docs/ssl/post-quantum-cryptography/pqc-to-origin.mdx
+4-23Lines changed: 4 additions & 23 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -26,7 +26,7 @@ If the origin supports post-quantum hybrid key agreement, it can use HelloRetryR
26
26
27
27
### Cloudflare zone settings
28
28
29
-
The method described above is the one used to allow Cloudflare to support post-quantum to all outbound connections. However, if your origin server supports PQC and prefers it, you can use the [API](/api/operations/zone-cache-settings-change-origin-post-quantum-encryption-setting) to adjust it and avoid the extra round trip.
29
+
The method described above is the one Cloudflare uses to support post-quantum to all outbound connections. However, if your origin server supports PQC and prefers it, you can use the [API](/api/operations/zone-cache-settings-change-origin-post-quantum-encryption-setting) to adjust your Cloudflare zone settings and avoid the extra round trip.
30
30
31
31
It is also possible to opt out of PQC using the same API endpoint.
32
32
@@ -51,34 +51,15 @@ The possible values are:
51
51
52
52
### Origin server
53
53
54
-
To make sure that your origin server prefers the post-quantum key agreement use the `bssl` tool of [BoringSSL](https://github.com/google/boringssl):
Verify that the `ECDHE curve`in the handshake output indicates `X25519MLKEM768`.
60
-
</Example>
61
-
62
-
1. Use Cloudflare's [fork of BoringSSL](https://github.com/cloudflare/boringssl-pq).
63
-
2. Use the `bssl` tool of BoringSSL:
64
-
65
-
- If you set your Cloudflare zone to `supported`, check that your origin prefers the hybrid key agreement, by using the `-disable-second-keyshare` parameter:
66
-
67
-
<Example>
68
-
```bash
69
-
$ cd boringssl-pq && cmake -B build && make -C build
0 commit comments