Microsoft urges testing of post-quantum TLS certificates now
Microsoft’s August 2026 PQC TLS pilot lets selected CAs test non-public ML-DSA-87 certificates that must not be used in production.
Microsoft says post-quantum planning must cover authentication as well as harvest-now-decrypt-later confidentiality risk, because certificates, PKI services, applications, devices, hardware security modules, and security appliances will face new algorithms and larger chains. Its PQC TLS Pilot Program, launched August 27, 2026, lets approved authorities in the Microsoft Trusted Root Program test non-public NIST FIPS 204 ML-DSA-87 roots and issuance only in closed environments. Pilot certificates are not publicly trusted and must not be used for production or public websites; a secondary report adds that they will not enter the Common CA Database or Certificate Transparency logs. Sources disagree on participants: Microsoft names DigiCert, Sectigo, HARICA, IdenTrust, and ComSign, while later reports say seven root operators including DigiCert, Sectigo, HARICA, IdenTrust, and SSL.com, with admissions open through 2026. Testing is described as limited to specified Windows 11 releases with July 28, 2026 updates, including KB5101681 and KB5101684, before Schannel pilot testing, and Windows Server support is still planned. Microsoft warns larger chains may affect handshake size, storage, inspection, issuance, renewal, and management, and urges multi-year inventory, vendor-roadmap review, and non-production testing.
- Microsoft’s PQC TLS Pilot Program launched August 27, 2026, for non-public NIST FIPS 204 ML-DSA-87 roots and issuance in closed environments.
- Pilot certificates are not publicly trusted and must not protect production or public websites; one report says they will not enter the Common CA Database or Certificate Transparency logs.
- Sources disagree on participants: Microsoft names DigiCert, Sectigo, HARICA, IdenTrust, and ComSign, while later reports say seven operators including DigiCert, Sectigo, HARICA, IdenTrust, and SSL.com, with admissions open through 2026.
- Pilot TLS testing is limited to specified Windows 11 releases with July 28, 2026 updates, including KB5101681 and KB5101684, before Schannel testing; Windows Server support is still planned.
- Larger ML-DSA chains may affect handshake size, storage, inspection, issuance, renewal, and management across PKI, HSMs, appliances, applications, and devices.
- Microsoft recommends multi-year inventory of dependencies, vendor-roadmap review, and non-production lifecycle testing before post-quantum authentication is required at scale.
Coverage timelineoldest first · each row is one article
- · 13h agoPost-quantum authentication: Why organizations should start testing certificate ecosystems now
Microsoft Security Blog· 47
Microsoft urges organizations to inventory and test certificate systems now for post-quantum authentication using its PQC TLS pilot.
- · 5h agoMicrosoft Pushes Enterprises to Test Post-Quantum Certificates Before Large-Scale Migration
GBHackers· 46
Microsoft's post-quantum TLS pilot asks enterprises to test ML-DSA certificates before production migration.
- · 2h ago