Post-Quantum Cryptography and the Future of SSL Certificates
Quantum computers threaten current RSA and ECDSA algorithms. Learn what post-quantum cryptography means for SSL certificates and when to expect changes.
The algorithms that underpin every SSL certificate today — RSA and ECDSA — are vulnerable to sufficiently powerful quantum computers. This isn't an immediate crisis, but it's a predictable one, and the standards community is already preparing the response.
The Threat: Shor's Algorithm
In 1994, mathematician Peter Shor proved that a quantum computer could efficiently factor large integers and compute discrete logarithms — the two mathematical problems that RSA and EC cryptography rely on. A quantum computer large enough to run Shor's algorithm at scale would break the public key algorithms in every certificate issued today.
Current estimates suggest such a machine is 10–20 years away (and possibly never — engineering challenges are substantial). But the concern is real: encrypted data harvested today could be decrypted in the future ("harvest now, decrypt later").
NIST's Post-Quantum Standards
In 2024, NIST finalized its first set of post-quantum cryptography standards:
- ML-KEM (CRYSTALS-Kyber) — key encapsulation, replacing RSA/ECDH in TLS key exchange
- ML-DSA (CRYSTALS-Dilithium) — digital signatures, replacing RSA/ECDSA for certificate signing
- SLH-DSA (SPHINCS+) — hash-based signatures, a conservative alternative
Hybrid Approaches
During the transition period, TLS implementations are deploying hybrid key exchange — combining classical ECDH with ML-KEM so that security is maintained even if one of the algorithms is broken. Chrome and Firefox already support hybrid post-quantum key exchange in TLS 1.3. Certificate signing (the part that appears in the X.509 structure) will transition more slowly.
Impact on Certificate Format
Post-quantum certificates will look different: the public key and signature algorithm fields will reference new OIDs. The overall X.509 structure remains the same, but the key sizes and algorithm identifiers will change. Certificate decoders and tools will need to be updated to display these fields correctly.
What to Do Now
For most organizations, the immediate action is awareness and inventory: know where all your certificates are, what algorithms they use, and plan for agile certificate replacement. Organizations handling sensitive long-lived data (government, healthcare, financial records) should evaluate their exposure more urgently.
Decode any SSL certificate instantly
Paste any PEM certificate into the free decoder — see subject, issuer, SANs, fingerprints, validity dates, and all X.509 extensions explained in plain English.
Open the Decoder