PQC support
Cloudflare's deployment of post-quantum hybrid key agreements is supported by different software as listed below. Contributions ↗ to keep the listing up-to-date are welcome!
- Default for Firefox 132+ ↗ on Desktop
- For QUIC/HTTP3, use Firefox 135+
- Default for Chrome 131+ ↗
- Default for Edge 131+ ↗
- Default for recent Opera ↗ and Brave ↗
- Cloudflare's fork of Go ↗
- Default for Go 1.24+ ↗
- BoringSSL ↗
- rustls 0.23.22+ ↗
- Default for rpxy 0.9.4+ ↗
- Open Quantum Safe ↗
- C library: liboqs 0.10.0+
- OpenSSL provider: oqs-provider 0.7.0+
- Caddy HTTP server ↗ nightly compiled with Go 1.24+ (instructions ↗)
- Botan C++ library 3.7.0+ ↗
- Default for Chrome 124-130 ↗ on Desktop
- For older Chrome or on mobile, toggle TLS 1.3 hybridized Kyber support (
enable-tls13-kyber
) inchrome://flags
.
- For older Chrome or on mobile, toggle TLS 1.3 hybridized Kyber support (
- Default for Edge 124-130 ↗
- Firefox 124-131 ↗ if you turn on
security.tls.enable_kyber
inabout:config
- For QUIC/HTTP3, use Firefox 128+ with
network.http.http3.enable_kyber
.
- For QUIC/HTTP3, use Firefox 128+ with
- Cloudflare's fork of Go ↗
- Default for Go 1.23 ↗
- BoringSSL ↗
- Cloudflare's fork of QUIC-go ↗
- Goutam Tamvada's fork of Firefox ↗
- Open Quantum Safe ↗
- C library:
liboqs
0.5.0-0.12.0 - OpenSSL provider:
oqs-provider
0.5.0-0.8.0
- C library:
- Zig 0.11.0-0.13.0 ↗
- nginx ↗ when compiled with BoringSSL ↗ (guide ↗)
- Botan C++ library 3.2.0+ ↗ (instructions ↗)