Cloudflare 刚上线 Automatic Key Exchange,并默认对现有和新域名启用。 它会自动探测源站支持的密钥交换算法,如果支持,就优先使用后量子混合算法 X25519MLKEM768。 官方数据还挺夸张:HelloRetryRequest 从约 52% 降到 3.7%,TLS 握手 p90 延迟减少 150ms+,目前每天约有 450 亿次源站连接已经在使用后量子密钥交换。 安全增强还能顺便降延迟,这个更新感觉挺实用。 Cloudflare Blog – 8 Sep 26 Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45... Automatic Key Exchange probes TLS 1.3-capable customer origins to learn which key agreement algorithms they support. We then lead with the most secure algorithm when connecting to the origin, preferring post-quantum connections wherever the origin... 1 个帖子 - 1 位参与者 阅读完整话题


  • 情报分类:技术价值
  • 命中依据:Cloudflare后量子TLS部署与性能数据,实用技术信息
  • 来源:服务器 / LINUX DO - 最新话题
  • 原作者:chunkei chan
  • 发布时间:2026/9/9 09:15:14