Migrating from RSA to Post-Quantum Secure ML-DSA Authentication on Cisco Networks
Cisco engineers have published an in-depth guide to migrating from RSA certificates to post-quantum secure ML-DSA authentication across a multi-router network. The document, part of the IPsec series, highlights the complexities and challenges involved in this process.
Most production networks rely on RSA (or ECDSA) certificates issued by an internal CA for authentication. However, migrating from these classical algorithms to post-quantum secure ML-DSA requires careful planning and execution. The engineers demonstrate how to transition from RSA to ML-DSA across a live network using the same process as importing ML-DSA certificates.
One of the key differences between key exchange and authentication is that key exchange offers optional negotiation, but authentication methods must be explicitly configured per profile with no fallback. This drives the entire migration strategy.