Quantum-Ready Cloud PKI in Azure

Quantum-Ready Cloud PKI in Azure

Executive Order 14412 and Quantum-Ready Cloud PKI

Executive Order 14412 directs federal agencies to migrate to quantum-resistant cryptography by 2030 to protect sensitive government data. That deadline doesn’t mean you should switch to post-quantum PKI today. Support within the Microsoft ecosystem is still evolving (see Richard Hicks’ post-quantum cryptography series). However, it does mean you should be planning your upgrade path and beginning to test post-quantum algorithms and workflows.

Today, we’re excited to announce that we’ve added quantum-resistant PKI options in EZCA. Beginning today, our customers affected by this executive order can create a post-quantum CA and begin validating workflows now and be ready to make the full transition as the ecosystem matures.

Quantum-Ready PKI in EZCA

EZCA has created a quantum-ready PKI with ML-DSA (Module-Lattice-Based Digital Signature Standard) which is designed to be resistant to quantum computer attacks. Our implementation is as simple as creating a cloud CA and selecting the ML-DSA algorithm for the key algorithm. This allows organizations to start testing new quantum-resistant cryptographic workflows without disrupting their existing PKI infrastructure and operations.

Why We Chose ML-DSA for Quantum-Ready PKI

We chose ML-DSA for our quantum-ready PKI because it is based on module-lattice cryptography, which is currently considered by NIST one of the most promising approaches for achieving quantum resistance. ML-DSA provides strong security guarantees against quantum computer attacks while maintaining efficient performance for cryptographic operations.

Can I Use Quantum-Resistant PKI in Production?

While EZCA provides the capability to create a quantum-resistant PKI, it is important to understand that this is still an emerging technology. Organizations can start experimenting and testing quantum-resistant cryptographic workflows in a controlled environment. However, for production environments, we recommend sticking to RSA and ECC algorithms, which are well-established and widely supported, until quantum-resistant cryptography matures and gains broader adoption.

Are Quantum-Resistant PKI CAs HSM-Protected?

Quantum-resistant PKI CAs in EZCA are currently software-based and are not protected by Hardware Security Modules (HSMs). This means that while they provide quantum-resistant cryptographic capabilities, they do not offer the same level of physical security as HSM-protected CAs. We are working closely with Microsoft to explore options for integrating HSM protection for quantum-resistant PKI CAs in the future, aiming to provide both quantum-resistant cryptography and robust physical security.

What Should I be Doing to Prepare for Quantum-Resistant PKI?

To be honest, there is no immediate action required for most organizations. The technology is still emerging, and widespread adoption of quantum-resistant PKI is likely several years away. However, it is wise to start automating your PKI management, this is what buzzword companies call “crypto-agility”. Crypto-agility refers to the ability to quickly and efficiently switch cryptographic algorithms and protocols as new threats and technologies emerge. Meaning that if you have your certificate issuance and management automated, if tomorrow they say we gotta switch to quantum-resistant cryptography, you can do it with minimal disruption and effort.