tech · quantum risk
Linux PQC | Quantum-Safe Claims & Education
Verdict
Linux PQC readiness is package- and distro-dependent. Inventory OpenSSL/GnuTLS versions and whether PQC providers are enabled—distro brand alone is not quantum-proof.
Overview
Long-term support distros may lag features; rolling distros lag operational stability. Plan both.
Cryptographic profile
- Signatures: OpenSSL/GnuTLS and kernel crypto as packaged, Distro backports
- Hash: Package-dependent
- Public-key exposure: Servers and appliances run distro crypto packages of uneven age.
- Verify distro package changelogs for PQC.
Claim scrutiny (buyer checklist)
Marketing / stated claims
- Distro-ready PQC
Open questions
- Default algorithms in your distro’s OpenSSL package?
Educational analysis only. Verify primary sources, specs, and audits yourself before any financial or procurement decision.
What breaks
- EOL distros
- Static appliances
- Containers with ancient base images
Mitigations
- Base image scanning for crypto libs
- Standard golden images with known OpenSSL builds
- See openssl-pqc page
FAQ
Related?
/is-quantum-proof/openssl-pqc
SBOM?
/is-quantum-proof/sbom-crypto
Key concepts (technical dictionary)
Terms used on this page — open a definition: