Commit 33147a

2025-06-11 13:46:58 novaflash: -/-
PQCryptoOpenVPN.md ..
@@ 41,7 41,7 @@
# Post-quantum signing/certificates
- Having post-quantum key-agreement is much more critical right now. Especially for a TLS/VPN connection where verification of certificates is only needed for the connection itself and being able to verify signatures and identity later is at least currently of lesser concern. So at least at the moment, the urgency here is not as big as it is for the key-agreement.
+ Asymmetric algorithms are used in two major use cases in OpenVPN - verification of identity using certificates, and in the key-agreement for encryption. It is much more critical to focus on the post-quantum key-agreement now. Especially for a TLS/VPN connection where verification of certificates is only needed during the connection itself, and being able to verify signatures and identity later is at least currently of lesser concern. So at least at the moment, the urgency here is not as big as for the key-agreement.
But creating certificates with post-quantum algorithms is also possible. E.g. creating a self-signed certificate that is usable with
`--peer-fingerprint` using the ML-DSA-65 algorith can be created using OpenSSL (3.5.0 or later):
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9