Skip to content

[Feature]: Post Quantum Cryptography support in nuget.org #10763

@omajid

Description

@omajid

Related Problem

No response

The Elevator Pitch

nuget.org is not PQC ready:

https://quready.com/check/ says:

Image

https://pqc.sinevis.com/ says:

Image

Additional Context and Details

.NET added support for PQC inbox in .NET 10: https://devblogs.microsoft.com/dotnet/post-quantum-cryptography-in-dotnet/

Various organizations, standards and government agencies are starting to list PQC as mandatory feature with a hard deadline date. CNSA 2.0, for example, lists 2025 as the date where software should support PQC signatures:

Other requirements for NSS

NSA anticipates the following timetable for implementing other CNSA 2.0 requirements for NSS:

  • Software and firmware signing: begin transitioning immediately, support and prefer CNSA 2.0 by 2025, and exclusively use CNSA 2.0 by 2030.
  • Web browsers/servers and cloud services: support and prefer CNSA 2.0 by 2025, and exclusively1 use CNSA 2.0 by 2033.
  • Traditional networking equipment (e.g., virtual private networks, routers): support and prefer CNSA 2.0 by 2026, and exclusively use CNSA 2.0 by 2030.
  • Operating systems: support and prefer CNSA 2.0 by 2027, and exclusively use
    CNSA 2.0 by 2033.
  • Niche equipment (e.g., constrained devices, large public-key infrastructuresystems): support and prefer CNSA 2.0 by 2030, and exclusively use CNSA 2.0 by 2033.
  • Custom applications and legacy equipment: update or replace by 2033

Metadata

Metadata

Assignees

No one assigned
    No fields configured for Feature.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions