Post Quantum Cryptography (PQC) Client to Edge
To protect your data and address privacy and security goals, Akamai uses Post Quantum Cryptography (PQC) to protect transport layer security (TLS) communications. We align with the industry standard and accept the ML-KEM based hybrid key exchange.
How it works
The Post Quantum Cryptography Client to Edge behavior allows you to manage Post Quantum Cryptography (PQC) key exchanges Client to Edge. We recommend keeping PQC Client to Edge enabled for enhanced security.
- To use Post Quantum Cryptography (PQC), your certificate needs to have transport layer security (TLS) 1.3 enabled in its deployment settings.
- Post Quantum Cryptography (PQC) Client to Edge is enabled by default for all Enhanced TLS hostnames. To disable PQC, add the behavior and set the Enable option to Off.
Standard TLS
PQC Client to Edge for Standard TLS hostnames is in limited availability and disabled by default. To turn on PQC for Standard TLS, add the behavior, and set the Enable option to On.
- Only one instance of the behavior can exist in the same configuration.
- You can place this behavior in the default rule, under a particular hostname match, or under a percentage of clients match.
- The behavior is only available in secure configurations.
- There is a risk of bypassing PQC if multiple hostnames share a single TLS certificate, but PQC is only enabled for a subset of those hostnames. For example, a client has the ability to establish a standard, non-PQC protected TLS connection to a hostname without PQC enabled. If the client then reuses that same connection to make a request to a different hostname that has PQC enabled, the request is sent over the existing, non-PQC-protected connection. This effectively bypasses the intended security benefits provided by PQC.
Features and options
| Field | What it does |
|---|---|
| Enable | Enables the Post Quantum Cryptography Client to Edge behavior, enhancing security using PQC key exchanges. |
Updated 9 days ago
Did this page help you?
