tech · quantum risk
Is LB / proxy TLS Quantum Proof? Network Security & PQC
Verdict
Load balancers and reverse proxies that terminate TLS are not quantum-proof while certs and handshakes are classical. They are ideal control points to pilot hybrid TLS—and dangerous if keys are poorly protected.
Overview
Most enterprises terminate TLS on load balancers, API gateways, or reverse proxies. That concentration is an opportunity for hybrid pilots and a risk if private keys sprawl.
Backend mTLS to apps reintroduces the mTLS inventory problem—see dedicated mTLS and mesh pages.
Cryptographic profile
- Signatures: Terminator certificates, Optional backend mTLS
- Hash: TLS
- Public-key exposure: Central terminators hold private keys for many hostnames—high-value targets.
What breaks
- Classical certs on shared terminators
- Exported private keys on disk without HSM
- Inconsistent cipher policy across fleets
FAQ
Should hybrid start at the load balancer?
Often yes for internet edges—maximize coverage and measure breakage.
CDN vs self-managed?
Both need a roadmap; CDNs may ship hybrid earlier for public sites.
Key concepts (technical dictionary)
Terms used on this page — open a definition: