PQC support
Cloudflare's deployment of post-quantum hybrid key agreements is supported by different software as listed below.
- Default for Firefox 132+ ↗ (Beta)
- Default for Chrome 131+ ↗ (Beta)
- Cloudflare's fork of Go ↗
- BoringSSL ↗
- Default for Chrome 124-130 ↗ on Desktop
- For older Chrome or on mobile, toggle TLS 1.3 hybridized Kyber support (
enable-tls13-kyber
) inchrome://flags
.
- For older Chrome or on mobile, toggle TLS 1.3 hybridized Kyber support (
- Default for Edge 124+ ↗
- Default for recent Opera ↗ and Brave ↗
- Firefox 124+ ↗ if you turn on
security.tls.enable_kyber
inabout:config
- For QUIC/HTTP3, use Firefox 128+ with
network.http.http3.enable_kyber
.
- For QUIC/HTTP3, use Firefox 128+ with
- Cloudflare's fork of Go ↗
- Default for Go 1.23 ↗
- BoringSSL ↗
- Cloudflare's fork of QUIC-go ↗
- Goutam Tamvada's fork of Firefox ↗
- Open Quantum Safe ↗ C library
- Zig 0.11.0+ ↗
- nginx ↗ when compiled with BoringSSL ↗ (guide ↗)
- Caddy HTTP server ↗ nightly compiled with Go 1.23+ ↗
- Botan C++ library 3.2.0+ ↗ (instructions ↗)
- ISRG's fork of Rustls ↗