-
Feature
-
Resolution: Unresolved
-
Major
-
None
-
None
Feature Overview (aka. Goal Summary)
Evaluate the tasks associated with implementation of Post-Quantum Cryptography (PQC) across OpenShift Networking components for planning purposes.
List of components that are covered under the 2026 PQC requirements for networking equipments: https://docs.google.com/spreadsheets/d/1ckBoRWDNeCMmWrE1kVpOLHh2aVwi9TqrdbYzQtdTdbw/edit?gid=1744150642#gid=1744150642
Goals (aka. expected user outcomes)
Thorough understanding of what OpenShift Networking is required to do for integration of PQC ciphers across networking components (e.g. IPsec) for the purposes of roadmap planning of action items in 4.21 and 4.22.
Requirements (aka. Acceptance Criteria):
- A list of impacted networking features and the responsible networking team
- For each impacted feature, a list of work required and OpenShift release at which it must be completed (starting at 4.21)
| Deployment considerations | List applicable specific needs (N/A = not applicable) |
| Self-managed, managed, or both | |
| Classic (standalone cluster) | |
| Hosted control planes | |
| Multi node, Compact (three node), or Single node (SNO), or all | |
| Connected / Restricted Network | |
| Architectures, e.g. x86_x64, ARM (aarch64), IBM Power (ppc64le), and IBM Z (s390x) | |
| Operator compatibility | |
| Backport needed (list applicable versions) | |
| UI need (e.g. OpenShift Console, dynamic plugin, OCM) | |
| Other (please specify) |
Questions to Answer (Optional):
Out of Scope
Background
- “If large-scale quantum computers are ever built, they will be able to break many of the public-key cryptosystems currently in use. This would seriously compromise the confidentiality and integrity of digital communications on the Internet and elsewhere. The goal of post-quantum cryptography (also called quantum-resistant cryptography) is to develop cryptographic systems that are secure against both quantum and classical computers, and can interoperate with existing communications protocols and networks.” ([Source|https://csrc.nist.gov/Projects/post-quantum-cryptography)]