tech · quantum risk
Is North-south mTLS Quantum Proof? Network Security & PQC
Verdict
North-south mTLS (internet or partner client certs) is high quantum and operational risk: classical client certs are hard to rotate across partners. Start inventory and dual-stack plans early.
Overview
Unlike mesh east-west mTLS, north-south client certificates often involve external organizations and mobile apps.
Quantum migration must include partner runbooks and app update channels—not only load balancer cipher suites.
See api-gateway-mtls and mtls hubs.
Cryptographic profile
- Signatures: Client certificates at public or partner APIs, Server certificates on VIP
- Hash: TLS
- Public-key exposure: Partner and mobile clients pin classical client certs for years.
What breaks
- Partner certs with multi-year validity
- Mobile apps pinning classical-only chains
- No test environment for larger PQC certs
Mitigations
- Partner certificate inventory and SLAs
- Short-lived client certs where clients allow
- Pilot hybrid at edge with canary partners
FAQ
Prefer OAuth over client certs?
Different tradeoffs; OAuth still needs token and TLS algorithm plans.
Same as internal mesh?
Harder externally—more stakeholders per rotation.
Key concepts (technical dictionary)
Terms used on this page — open a definition: