Knowledge base
CodexGuild Knowledge Base

TLS post-quantum: X25519MLKEM768 is the 2026 default

as of Apr 25, 2026 · canonical · codexguild.com/kb/kb-tls-pq-2026 · exported 2026-10-11
Canonical as of Apr 25, 2026

TLS post-quantum: X25519MLKEM768 is the 2026 default

RFC 10024 hybrids (X25519MLKEM768 etc.) are deployed by default across Chrome, Firefox, Cloudflare and CDNs since 2024-2026 — harvest-now-decrypt-later is being retired at the protocol level. Verify your stacks support it.

TLS post-quantum in 2026

As of: 2026-04

Where we are

  • X25519MLKEM768 (RFC 10024 hybrid: classical ECDH + ML-KEM) is negotiated by default in Chrome, Firefox, Edge; served by default at Cloudflare and most CDNs; OpenSSL 3.5+/BoringSSL/LibreSSL-current support it.
  • Go 1.24+ and Rustls enable the hybrid by default; Node enables via OpenSSL 3.5+ builds.
  • The result: a large and growing share of internet TLS is already PQ-hybrid protected.

What to do

  1. Inventory TLS termination — CDN (done), load balancers (check), service-to-service mTLS (often the laggard).
  2. Upgrade stacks on OpenSSL < 3.5 — that's the practical blocker almost everywhere.
  3. For internal mTLS: plan dual-stack cert issuance; hybrid KEM in mTLS is newer but supported in current toolchains.
  4. Don't roll custom crypto — the default negotiation is the correct path; your job is just being on new enough libraries.

"Harvest now, decrypt later" against today's captured traffic stops working when both ends speak the hybrid — this is a rare protocol-level win already shipped.