
Cloudflare adds post-quantum authentication for origin server connections
Cloudflare added ML-DSA post-quantum authentication support for origin connections in AOP and Custom Origin Trust Store.
Cloudflare says it has added post-quantum authentication support to two products that protect the link between its network and customer origin servers, moving a practical part of web infrastructure beyond post-quantum encryption alone.
The July 29 announcement covers Authenticated Origin Pulls and Custom Origin Trust Store. In Cloudflare's architecture, a website visit often involves one TLS connection from the browser to Cloudflare and a second connection from Cloudflare to the customer's origin. Cloudflare has already deployed post-quantum encryption for those paths, but the new work targets authentication: proving that the server or client certificate being presented has not been forged by an attacker with future quantum capabilities.
What changed
The company says both products now support Module-Lattice-Based Digital Signature Algorithm, or ML-DSA, the digital signature standard published by NIST as FIPS 204. Cloudflare says it supports the ML-DSA-44, ML-DSA-65 and ML-DSA-87 parameter sets, while recommending ML-DSA-44 for most applications because it is the most performant option and still provides what NIST classifies as category 2 security strength.
For Custom Origin Trust Store, customers can upload ML-DSA certificate authorities so Cloudflare will trust origin certificates chaining to those authorities. For Authenticated Origin Pulls, per-zone and per-hostname configurations can now use ML-DSA certificates and private keys, allowing Cloudflare to present a post-quantum client certificate when it connects to an origin over mutual TLS. Cloudflare notes that the global configuration level is not included in this first rollout.
Why it matters
The release is narrow but important because the origin connection is a controlled environment where Cloudflare and its customers can move faster than the public WebPKI. Browser-facing post-quantum certificates still depend on industry-wide work, including Merkle Tree Certificates at the IETF. By contrast, Cloudflare can support ML-DSA for origin authentication through customer-controlled trust relationships and existing account configuration.
The company also warns that adding post-quantum options is not enough if classical authentication paths remain trusted. To avoid downgrade attacks, customers that want full post-quantum protection need to remove trust in quantum-vulnerable mechanisms where appropriate and configure their origins carefully.
Cloudflare frames the update as the first milestone in its broader plan to reach full post-quantum security by 2029. For security teams, the immediate takeaway is that post-quantum migration is shifting from policy discussion into operational TLS settings, certificate formats and origin-server deployment choices.
Sources
Cover photo by Field Engineer on Pexels, used under the Pexels License.
CyberOGZ Team






Comments (0)
Leave a Comment