Post-quantum authentication to origins is now supported
- ID
- 8760
- Status
- summarized
- Published
- 29 Jul 2026, 9:00 PM
- Fetched
- 29 Jul 2026, 11:08 PM
- Provider
- Cloudflare Blog
- Category
- infrastructure
- Original URL
- https://blog.cloudflare.com/post-quantum-authentication-to-origins/
- Source URL
- https://blog.cloudflare.com/rss/
Summary
- Score
- 5.0
- Created
- 31 Jul 2026, 4:33 PM
- Tags
- Audience
- developersdatabase_learners
What happened
Cloudflare's Authenticated Origin Pulls and Custom Origin Trust Store now support post-quantum authentication via ML-DSA signatures, securing the Cloudflare-to-origin connection against future quantum impersonation attacks. Cloudflare targets 2029 for full post-quantum security and is separately working on Merkle Tree Certificates with Google at the IETF for the visitor-to-Cloudflare connection.
Why it matters
If you operate origin servers behind Cloudflare and rely on Authenticated Origin Pulls, you can now enable ML-DSA-based post-quantum authentication on the Cloudflare-to-origin leg. Most teams do not need to act today, but those with long-lived sensitive data or compliance requirements should evaluate whether to opt in now or wait for broader ecosystem support.
Discussion angle
Is post-quantum authentication something Malaysian infra teams should start testing now, or is it premature given the 2029 timeline and limited ecosystem support?