Skip to main content
Version: v45

Post-Quantum Cryptography Readiness

Overview​

PrivX supports post-quantum cryptography (PQC) in the following areas:

  • PQC key establishment: Secure Shell connections, PrivX Extender v2 tunnels, and TLS connections that terminate in PrivX.

PQC readiness depends on the deployment for the following connections:

  • Browser-facing TLS: A load balancer or other external component can terminate the connection before it reaches PrivX. PQC support then depends on that component and its configuration.

PrivX does not currently support PQC for the following:

  • Authentication and signatures: Secure Shell authentication keys, TLS certificate signatures, and JWS signatures.
  • JOSE key management: Public-key key establishment in JWE flows.
  • Key management: Asymmetric key types and operations in PrivX Keyvault and its HSM/PKCS#11 integration.

FAQ​

What does PQC key establishment mean for PrivX connections?
PQC key establishment means that a connection can negotiate a hybrid or standalone post-quantum key-establishment algorithm. It does not imply that every connection uses PQC, or that the associated authentication, signatures, stored data, or peer system are post-quantum secure.

Does PrivX support PQC key establishment for Secure Shell connections?
Yes. PrivX Secure Shell connections support PQC key establishment in both the client-to-PrivX and PrivX-to-target directions. The selection and preference order of the supported key-establishment algorithms can be configured. See Supported SSH Algorithms for configuration details and supported algorithms.

Can non-PQC Secure Shell key-establishment algorithms be disabled?
Yes. Non-PQC key-establishment algorithms can be disabled entirely if desired.

Is PQC key establishment available in FIPS-approved mode?
Yes, for Secure Shell connections. FIPS-approved mode permits hybrid PQC key-establishment algorithms that combine a non-FIPS-approved PQC KEM with a FIPS-approved ECDH algorithm. See the list of Secure Shell algorithms allowed in FIPS-approved mode. The PQC KEM itself is currently non-FIPS-approved because PQC KEMs are not available through the FIPS cryptography used by PrivX, although this may change in the future.

Does PrivX Extender v2 support PQC key establishment?
Yes. PrivX Extender v2 tunnels traffic using Secure Shell and supports PQC key establishment. Its key-establishment algorithm is currently fixed to a hybrid algorithm combining ML-KEM-1024 and NIST P-384.

Does PrivX support PQC key establishment for TLS connections?
Yes. PrivX components support PQC key establishment for TLS connections. Whether a connection uses it depends on the configuration and the capabilities of the other endpoint.

Are browser-to-PrivX connections PQC ready?
Browser-to-PrivX TLS terminates in Nginx. In HA deployments, a load balancer may also terminate the browser-facing TLS connection before forwarding traffic to Nginx. PQC readiness therefore depends on the deployment and on the TLS implementation and configuration used at each termination point. For configuration instructions, see Configuring PQC Key Exchange Prioritization for Nginx and TLS 1.3.

Does PrivX support PQC authentication or signature schemes?
No. Secure Shell authentication keys, TLS certificate signatures, and JWS signatures, including signed JWTs, use classical cryptography.

Does PrivX support PQC key management in JOSE-based encryption flows?
No. PrivX uses JWE with the classical ECDH-ES algorithm for public-key key establishment in its JOSE-based encryption flows. JWE does not currently have a standardized ML-KEM key-management algorithm, and PrivX does not define or implement a custom PQC key-management algorithm for these flows.

Can PrivX Keyvault or its HSM/PKCS#11 integration manage PQC keys?
No. PrivX Keyvault and its HSM/PKCS#11 integration do not currently support PQC asymmetric key types or operations. PrivX therefore cannot generate, import, or use PQC keys, such as ML-KEM or ML-DSA keys, through these interfaces.

Are 128-bit symmetric keys a PQC readiness gap?
No. PrivX uses both 128-bit and 256-bit symmetric keys. AES-256 is commonly used, but 128-bit keys remain in use. AES-128 is still widely considered acceptable in the post-quantum context.

PQC Readiness Release Status​

PrivX ReleasePQC Readiness Changes
PrivX 45Initial PQC readiness overview.