Summary
On July 29, 2026, Cloudflare enabled post-quantum (PQ) authentication for the mutually authenticated TLS connections between its edge and customer origin servers, through Authenticated Origin Pulls (AOP) and the Custom Origin Trust Store (COTS). Authentication uses ML-DSA signatures across all FIPS 204 parameter sets (ML-DSA-44 recommended for most applications), paired with X25519MLKEM768 for key exchange.
What changed
AOP and COTS now support ML-DSA (FIPS 204) certificate signatures for authenticating Cloudflare-to-origin TLS connections, extending Cloudflare's existing X25519MLKEM768 post-quantum key exchange to the origin authentication leg.
Why it matters
Origin authentication is where quantum risk turns into impersonation risk: an adversary able to forge a classical origin certificate could impersonate a customer origin. Bringing ML-DSA signatures to the origin leg, not just the browser leg, closes a gap most CDNs still leave open and gives regulated buyers a concrete path toward FIPS 204 alignment without changing their application.
Evidence excerpt
Our Authenticated Origin Pulls and Custom Origin Trust Store products now support post-quantum (PQ) authentication via Module-Lattice-Based Digital Signature Algorithm