news
Rocky Linux 10.2 Released with Post-Quantum Cryptography Improvements
Highlights of Rocky Linux 10.2 include several post-quantum cryptography improvements like support for ML-KEM hybrid key exchange (mlkem768nistp256-sha256, mlkem1024nistp384-sha384) in OpenSSH’s FIPS mode, support for PQ/T hybrid key exchange methods in libssh combining ML-KEM with ECDH, and support for PQC definitions in PKCS #11 headers.
In addition, the Directory Server has been updated to support TLS certificates using ML-DSA keys (ML-DSA-44/65/87), and podman-sequoia now supports composite post-quantum signatures. The Rocky Linux devs also note the fact that the FUTURE system-wide cryptographic policy now only allows hybrid ML-KEM key exchange algorithms.