Following the IETF 126 meeting in Vienna, July 18-24, the organization is now focusing on a critical next step in securing digital communications: post-quantum authentication. While post-quantum key establishment is moving into deployment, authentication lags behind, and the Internet Architecture Board plans to address this gap with a workshop in Prague on October 11 and 12.
The event aims to gather real-world deployment experience, as the IETF recognizes that specification work is no longer the only constraint. Organizers specifically seek evidence about what delays implementation in production systems, moving beyond benchmarks of individual operations to understand impacts on certificate chains and firmware budgets.
IETF Workshop Addresses Post-Quantum Authentication Deployment Gaps
The Internet Engineering Task Force is prioritizing practical hurdles to post-quantum authentication, recognizing that simply having standardized protocols is insufficient for widespread adoption. A recent restructuring within the IETF Administration LLC, with the insourcing of the Secretariat completed since January 2026, signals a shift in operational approach. This internal change aims to accelerate the standards development process and improve responsiveness to emerging challenges, like those now apparent in post-quantum cryptography deployment.
The organization is actively soliciting submissions detailing deployment experiences, with a deadline of September 4, 2026, to inform the Prague workshop and guide future efforts. While post-quantum key establishment has seen considerable progress, with Cloudflare reporting in April 2026 that more than 65 percent of human traffic to its network was post-quantum encrypted, authentication lags significantly. This discrepancy stems from differing deployment dynamics; key establishment allows independent upgrades on both client and server sides, whereas authentication demands coordinated changes across multiple entities.
The IETF notes that “Deployment requires certificate authorities, relying parties, trust stores, cryptographic modules, and applications to make compatible changes,” highlighting the complex web of dependencies hindering progress. The size of post-quantum cryptographic objects presents a substantial obstacle.
At NIST security level 3, an ML-DSA-65 public key is 1,952 bytes and a signature is 3,309 bytes, a dramatic increase compared to the 32-byte public key and 64-byte signature of Ed25519. A four-field certificate chain using ML-DSA-65 can reach 10,522 bytes, nearly 55 times larger than its Ed25519 counterpart, though this represents a lower bound and does not account for other factors. This size increase impacts protocols like QUIC, where a client’s initial datagram must be at least 1,200 bytes, and the server has limited transmission capacity before validating the client’s address.
The IETF states that “These examples show that both size and computational cost matter,” emphasizing the need for measurements from live systems to understand the true impact. The longevity of credentials adds another layer of complexity; some credentials are used in real-time handshakes, while others are embedded in firmware or archived documents, requiring verification years after creation.
This necessitates different deployment strategies and poses challenges for systems with limited update capabilities. The IETF is specifically seeking data on constraints encountered in production systems, including impacts on packet counts, latency, authentication failures, and resource utilization. The organization emphasizes, “We would like to hear from the people who have tried, measured, purchased, planned, or operated any part of this transition,” signaling a commitment to data-driven decision-making. The workshop’s focus extends beyond simply identifying problems; it aims to differentiate between various constraints, such as size limitations, hardware compatibility, and the challenges of long-lived verification.
Understanding these nuances is crucial for developing targeted solutions and ensuring a smooth transition to a post-quantum internet. The IETF recognizes that the migration to post-quantum authentication will take considerable time, and delaying action until key establishment is complete is not a viable option. The IETF notes that “If the work consumes most of the remaining warning period, treating authentication as the second priority cannot mean waiting until key establishment is finished.”
The IETF is particularly interested in understanding how new cryptographic approaches interact with existing systems, moving beyond theoretical benchmarks to assess impacts on certificate chains, handshake limitations, and cryptographic module budgets.
NIST Standards: ML-DSA and SLH-DSA in X.509 Implementation
Joe Clarke’s recent appointment as the new IETF Network Operations Center Lead signals a focused effort on network stability as the organization prepares for a significant shift in cryptographic standards. Clarke prioritizes ensuring the IETF network can support the increased demands of post-quantum cryptography, a necessity highlighted by the growing complexity of deploying these new algorithms.
They are specifically requesting position papers, due September 4, 2026, to inform the workshop and pinpoint the factors delaying production system adoption. While SLH-DSA offers smaller public keys, its signatures can range from 7,856 to 49,856 bytes depending on the chosen parameter set.
The IETF is also investigating how these changes affect various system constraints, differentiating between issues related to protocol behavior, hardware limitations, and the challenges of long-lived, offline verification. For example, RFC 9191 details EAP authenticators that abandon sessions after 40-50 round trips, meaning certificate chains cannot complete successfully in many existing EAP-TLS deployments.
The IETF Secretariat’s insourcing may accelerate this process by streamlining administrative functions and potentially speeding up standards development. The organization is actively seeking to understand which constraints are truly binding, distinguishing between size limitations, hardware capabilities, and the requirements for long-term verification and signing capacity.
Post-Quantum Authentication Migration Timeline Lags Key Establishment
The Internet Engineering Task Force is actively seeking real-world data to understand why post-quantum authentication is lagging behind key establishment in deployment, a gap revealed in the results of the post-meeting survey following IETF 126 in Vienna, held July 18-24, 2026. The organization’s focus has shifted from purely defining standards to gathering evidence of what truly impedes implementation in live systems. The complexity stems from the numerous dependencies involved in authentication, requiring coordinated changes across certificate authorities, applications, trust stores, cryptographic modules, and relying parties.
Unlike key establishment, where clients and servers can independently adopt new mechanisms, authentication demands advance knowledge and acceptance of credentials by verifiers, creating a slower and more fragmented deployment path. Credentials used in live handshakes, embedded in firmware, or archived for offline verification each present distinct challenges, and many of these components are updated less frequently than standard software.
An ML-DSA-65 public key is 1,952 bytes and a signature is 3,309 bytes, while an Ed25519 public key is 32 bytes and its signature is 64 bytes. Similarly, systems adhering to RFC 9191, such as EAP-TLS deployments, cannot complete successfully if certificate chains exceed approximately 60 kilobytes.
The IETF is now differentiating between several distinct constraints impacting deployment, including size and protocol behavior, hardware and key custody, long-lived and offline verification, and signing architecture capacity. Understanding which of these constraints are truly binding requires measurements from production systems, data the organization is actively soliciting through a call for position papers due September 4, 2026.
ML-DSA and SLH-DSA Size Impacts Protocol Constraints & Performance
The sheer scale of post-quantum signatures presents immediate challenges to existing internet protocols, a reality diverging from initial expectations that focused primarily on the computational demands of these new cryptographic methods. While key establishment utilizing mechanisms like CRYSTALS-Kyber has progressed toward deployment, authentication lags, and the Internet Engineering Task Force is now concentrating on the practical hurdles hindering wider adoption. Systems designed with assumptions based on smaller certificate sizes are now strained, requiring careful consideration of packet counts, latency, and authentication failure rates.
The IETF Community Survey 2025 provides a comprehensive assessment of community demographics, engagement patterns, and perceptions of organizational effectiveness, but the survey results and the restructuring are secondary to the immediate need for practical data. This longer migration timeline, coupled with the complex dependencies involved in authentication, requires certificate authorities, relying parties, trust stores, and applications all requiring coordinated changes, demands immediate attention and measurement.




See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
