October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk4 min

How to Enable Post-Quantum TLS for a Website Behind Cloudflare

Cloudflare supports hybrid post-quantum TLS, but visitor-to-edge and Cloudflare-to-origin are separate connections. Here’s how to check the origin setting and verify negotiation.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a website proxied through Cloudflare, visitor-to-Cloudflare TLS 1.3 already supports hybrid post-quantum key agreement when the visitor’s client supports it. To enable or verify the separate Cloudflare-to-origin connection, check Automatic key exchange under SSL/TLS > Overview > Origin connection & post-quantum encryption, then test the negotiated group. Cloudflare says this setting is enabled for existing zones and on by default for new zones; it prefers X25519MLKEM768 when the origin supports it and the zone’s compliance requirements allow it.

Understand which TLS connection you want to protect

A proxied request uses two separate TLS connections: one from the visitor’s browser or client to Cloudflare’s edge, and another from Cloudflare to your origin server. The peers and configuration are different on each leg, so an encrypted browser-to-Cloudflare connection does not prove that Cloudflare negotiated post-quantum key agreement with your origin.

As an Amazon Associate I earn from qualifying purchases.

  • Visitor to Cloudflare: Cloudflare says websites and APIs it serves over TLS 1.3 have supported hybrid post-quantum key agreement since October 2022. The client must also support the hybrid exchange for that connection to negotiate it. See Cloudflare’s Post-quantum cryptography (PQC) overview and PQC in Cloudflare products.
  • Cloudflare to origin: Cloudflare can negotiate a hybrid exchange only if the origin supports the relevant group and the zone’s TLS compliance requirements permit it. This is the leg controlled by the origin-connection setting described below.

The hybrid group Cloudflare identifies for automatic post-quantum selection is X25519MLKEM768. It combines conventional X25519 key agreement with ML-KEM key establishment, retaining a classical component while adding post-quantum protection to the shared-secret exchange.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check Automatic key exchange in Cloudflare

  1. Sign in to Cloudflare and select the zone for the proxied hostname.
  2. Open SSL/TLS > Overview > Origin connection & post-quantum encryption.
  3. Confirm that Automatic key exchange is on. Cloudflare documents it as enabled for existing zones and on by default for new zones. It scans for origin support and selects a preferred key share; it does not, by itself, prove which group a particular connection negotiated. See Automatic key exchange to origins.
  4. Review the zone’s TLS compliance requirements. The available requirements include post-quantum hybrid and FIPS options, and apply to TLS 1.3 connections. The allowed requirements can affect which key exchanges Cloudflare may use.

Cloudflare’s origin documentation says key-exchange selection applies across the zone. Check the origin’s actual TLS implementation and any compliance constraints rather than assuming that turning on the setting will make every origin connection post-quantum.

#1 Best Overall
pcWRT PW-AX1800 WiFi 6 Dual-Band Router with VLAN Support, OpenVPN/WireGuard/IPsec VPN Client/Server - Compatible with ExpressVPN/SurfShark etc., Parental Controls, Ad Blocking, Gigabit Ethernet
  • VLAN Network Segregation: This router includes five preconfigured VLANs that isolate IoT devices, guest users, and work systems into separate, secure networks. Each LAN port and every WiFi SSID can be assigned to a VLAN, giving you complete control over how traffic flows inside your home.
  • Dual VPN Client and Server Support: The router works as both a VPN client and a VPN server, supporting OpenVPN, IPsec, and WireGuard. You can route selected VLANs through a VPN while keeping others on your regular ISP connection, giving each device group the exact level of privacy it needs.
  • Full WiFi 6 on Both Bands: With dual-band WiFi 6 support, the router delivers modern wireless performance across 2.4GHz b/g/n/ax and 5GHz a/n/ac/ax. It improves capacity, stability, and speed while remaining compatible with older devices, making it ideal for busy homes with many connections. Wi-Fi Mesh is available after firmware update.
  • High-Performance Hardware Architecture: Powered by the IPQ6000 quad-core ARM processor at 1.2GHz, along with 128MB flash, 256MB RAM, and hardware NAT acceleration, the router handles multitasking, streaming, VPN traffic, and VLAN isolation smoothly without slowing your network.
  • Flexible and Powerful Parental Controls: You can use trusted services like OpenDNS, CleanBrowsing, and Cloudflare for filtering, then add custom block lists, allow lists, and schedules. The router includes defenses against common bypass attempts, letting families create rules that match each user. Best of all, it's subscription free!

Verify the negotiated key exchange

Check the public hostname with Cloudflare Radar

Use Cloudflare Radar’s Post-Quantum TLS support check for the public hostname. Inspect the reported negotiated key exchange and post-quantum status, and review any indicators for split ClientHello handling, unknown key shares, or HelloRetryRequest failures. The result describes the tested host and connection conditions; it is not proof that every visitor or every origin connection negotiates the same way. Cloudflare documents the check in Post-Quantum Encryption and Key Transparency on Cloudflare Radar.

Test a reachable origin directly

If you can reach the origin’s TLS endpoint independently, Cloudflare documents using BoringSSL’s bssl client to request the hybrid group:

bssl client -connect <YOUR_ORIGIN>:443 -curves X25519MLKEM768

Replace <YOUR_ORIGIN> with the origin hostname or address that resolves to the TLS endpoint you intend to test. In the handshake output, check that the ECDHE curve is named X25519MLKEM768. A direct test checks the origin endpoint from your test environment; Cloudflare Radar checks the public hostname, so the two tests answer different questions. See Cloudflare’s product documentation and the API reference for Check Post-Quantum TLS support.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
Cudy New 5G NR SA NSA AX3000 WiFi 6 CPE Router, AX3000 Dual SIM 5G Cellular Router, Qualcomm IPQ5018, SDX62, Band Lock, VPN, Zerotier, Cloudflare, P5 (Renewed)
  • Lightning-fast Qualcomm Snapdragon SDX62 5G NR SA / NSA Modem Inside . The Cudy P5 supports 5G NR downlink speeds of up to 2.5 Gbps and 4G LTE downlink speeds of up to 1 Gbps. Wide spectrum bandwidth accelerates internet speed and reduces network latency for premium and time-sensitive mobile broadband services.
  • Qualcomm IPQ5018 WiFi 6 SoC. 1 GHz Dual-core ARM Cortex-A53 CPU High Capacity 802.11ax SoC, delivers super fast dual band Wi-Fi with speeds of up to 2402 Mbps on the 5 GHz band and 574 Mbps on the 2.4 GHz band. Exceptional wireless performance enables online gaming and HD video streaming at the same time, while large files can be shared with multiple devices.
  • Dual SIM and WAN Failover Keep You Always On-internet. Dual SIM slots provide redundancy and keep the device always online. Both SIM slots can be filled, you can choose whether to use SIM card 1 or SIM card 2, or auto select by Cudy. Set WAN/LAN port as WAN to enable Cudy use the landline internet from WAN, and 3G/4G connection works as a backup to provide a sustained and reliable internet connection for you.
  • The replaceable cellular antenna interface provides a variety of installation possibilities. 4 x 5dBi cellular antenna and 2x5dBi WiFi antenna enhance the sensitivity of the router and improve the signal quality of 5G NR and Wi-Fi. At the same time, the cellular antenna is a detachable design. If you want to use an outdoor cellular antenna, the SMA connector also provides the possibility of an external cellular antenna.
  • Multiple VPN Clients. With built-in PPTP/ L2TP / OpenVPN / WireGuard /IPsec/ Zerotier VPN, this 4G router can easily establish a connection to the VPN server to transport all your online data and traffic, securing it with its encryption at the same time. Compatible with 20 more DDNS providers, convenient to manage your remote cameras.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot failed or unexpected handshakes

The hybrid key share is larger than a classical one. That can create a split ClientHello, which some origin servers, firewalls, load balancers, or other middleboxes may mishandle. Cloudflare also notes that an origin can request another advertised key share using HelloRetryRequest, which adds a round trip. For background, see Post-quantum between Cloudflare and origin servers.

  • If the public-host check reports a split ClientHello or a related failure, inspect the full path to the origin, including TLS termination devices and network middleboxes.
  • If the origin does not support X25519MLKEM768, the post-quantum origin handshake cannot be established with that endpoint; determine whether its TLS implementation can be updated or configured to support the group.
  • If a HelloRetryRequest failure appears, check whether the origin and devices in front of it correctly handle the retry and the requested advertised key share.
  • Re-run the appropriate check after changes. A successful visitor-to-edge result and a successful direct-origin test are not interchangeable evidence.

When Cloudflare Tunnel is the origin path

Cloudflare documents post-quantum key agreement for the TLS 1.3 connection between cloudflared and Cloudflare when using Cloudflare Tunnel. That describes the tunnel connection, not a public origin TLS endpoint. Cloudflare’s documentation also says post-quantum signatures are not yet used for authentication on that path. See Cloudflare Tunnel post-quantum encryption.

Key agreement does not make certificates post-quantum

Hybrid post-quantum key agreement concerns how the TLS peers establish a shared secret. It is distinct from the signatures used to authenticate certificates. Cloudflare separately documents accepting ML-DSA certificates for Authenticated Origin Pulls and Custom Origin Trust Store; enabling Automatic key exchange does not change a website’s public certificate or make all TLS authentication post-quantum. See Cloudflare’s PQC in Cloudflare products documentation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.