<html><body><div dir="ltr">You find the published plans in JEPs or Jira tickets about PQC, currently however I have seen more groundwork like KEM and HKDF plus ML, none hybrid (mostly due to the fact that OpenJDK waits for standards, see the recent XWing discussion),</div><div dir="ltr" style="font-size: 12pt;"><br></div><div dir="ltr" style="font-size: 12pt;">I have seen that Oracle (of course) stated, that they will work on TLS and even back port it, for example here: <span style="color: rgb(0, 0, 0);"><a href="https://blogs.oracle.com/security/post/post-quantum-cryptography" rel="noreferrer noopener">https://blogs.oracle.com/security/post/post-quantum-cryptography</a></span></div><div dir="ltr" style="font-size: 12pt;">Maybe Sean can comment on it, but I think the same caveat applies here - missing completed standardization (and NIST did their fair share to hinder development, glad IETF picked up, draft-ietf-tls-ecdhe-mlkem-00 is till pretty fresh, though).</div><div dir="ltr"><br></div><div dir="ltr">I also know that ssh client providers (probably with the help of Bouncycastle) want to catch up to OpenSSH 10. With x25519mlkem (and maybe sntrupx?)</div><div dir="ltr"><br></div><div dir="ltr">The next, much bigger step IMHO is the area of (certificate) signatures/authentication. We have a bit more time there, so the future stays interesting,</div><div id="ms-outlook-mobile-body-separator-line" dir="ltr"><br></div><div id="ms-outlook-mobile-signature"><div dir="ltr">Gruß,</div><div dir="ltr">Bernd</div><div dir="ltr">-- </div><div dir="ltr">https://bernd.eckenfels.net</div></div><div id="mail-editor-reference-message-container" class="ms-outlook-mobile-reference-message"><hr style="display: inline-block; width: 98%;"><div id="divRplyFwdMsg" dir="ltr"><span style="font-family: Calibri, sans-serif;"><b>Von:</b> security-dev <security-dev-retn@openjdk.org> im Auftrag von Azeem Jiva <a_jiva@apple.com><br><b>Gesendet:</b> Samstag, Mai 31, 2025 3:10 AM<br><b>An:</b> security-dev@openjdk.org <security-dev@openjdk.org><br><b>Betreff:</b> Quantum Resistant hybrid key exchange</span><div style="font-family: Calibri, sans-serif;"> </div></div>Hi,
<br>Is there a list of future quantum resistant hybrid key changes under development for future OpenJDK releases? Thanks.
<br></div><div> </div></body></html>