The Secure Way
Post-quantum and TLS, the secure way
ML-KEM key exchange, TLS 1.3 done properly, and proving what your server actually negotiates.
10 guides
- Checking a server's TLS key exchange, the secure waySee which key exchange a TLS server really agrees to, hybrid ML-KEM, MLKEM1024 or classical X25519, with OpenSSL 3.5 and curl, and read the output right.
- CNSA 2.0 for web servers, the secure wayConfigure a CNSA 2.0 TLS endpoint on nginx with OpenSSL 3.5 or on Envoy: TLS 1.3, ML-KEM-1024 only, AES-256-GCM, P-384 signatures, and proof of each.
- ECDSA P-384 certificates with cert-manager, the secure wayIssue ECDSA P-384 certificates with cert-manager instead of the RSA-2048 default: the Certificate fields, key rotation, the Let's Encrypt chain, and checks.
- Finding classical key exchange in your estate, the secure wayInventory which TLS and SSH endpoints still use classical key exchange: a read-only script, how to read its output, and how to rank what to fix first.
- ML-DSA certificates: what is ready, the secure wayWhat works with ML-DSA certificates today: private PKI with OpenSSL 3.5 end to end, no publicly trusted ML-DSA certificates, and the Merkle Tree plan.
- ML-KEM-1024 on Envoy Gateway, the secure wayTurn on ML-KEM-1024 and hybrid ML-KEM at an Envoy Gateway edge with one ClientTrafficPolicy, keep browsers working, and prove the negotiated group.
- Post-quantum mTLS in a Kuma mesh, the secure wayMake Kuma sidecar-to-sidecar mTLS use ML-KEM-1024: MeshTLS for TLS 1.3, a MeshProxyPatch on both inbound and outbound, and counters that prove it.
- Post-quantum SSH with mlkem768x25519, the secure wayMake every SSH connection use mlkem768x25519-sha256: check what your servers negotiate, restrict KexAlgorithms to hybrids, and see what a refused client prints.
- Post-quantum TLS in nginx and HAProxy with OpenSSL 3.5, the secure wayEnable ML-KEM in nginx and HAProxy on OpenSSL 3.5: hybrid by default, MLKEM1024 when offered, and the group-tuple syntax that decides which one wins.
- TLS 1.3 only at the edge, the secure wayRefuse TLS 1.2 at an Envoy or Envoy Gateway edge, know which clients that cuts off, and why cipher_suites cannot restrict TLS 1.3 ciphers in Envoy.
T Academy
Every guide here is taught hands-on in H2-CPQE Edge and Post-Quantum Networking: a real host in your browser, and every objective checked on the machine.
Start free