
ML-DSA Certificates on Cisco IPsec: What Changes in IKEv2?
ML-DSA certificates change Cisco IKEv2 by replacing pre-shared-key authentication with post-quantum digital signatures while ML-KEM continues to handle key establishment. The operational tradeoff is size: Cisco’s hardware lab found that certificate-bearing IKE_AUTH exchanges became several times larger than its RSA baseline, making RFC 7383 fragmentation, PKI hygiene, interoperability testing, and reconnect-capacity testing essential. This is a promising lab design, not a reason to assume every peer or platform combination is ready. ...
My Lab