Crypto agility: change the algorithm, keep the network

Three cryptographic choices sit on one screen in QS-WAN and apply to every gateway you run: the certificate authority algorithm, the TLS groups used for the handshake, and the cipher that protects the traffic. Your firewall, your routes and your addressing stay exactly where they are, and nothing leaves the rack.

Post Quantum Vault
The cryptography your gateways run, set from the console
What it is

Which three settings, what they ship as, and how far they reach

The CA algorithm is the certificate authority behind every certificate your gateways and devices present to each other, and it ships as rsa-2048. The TLS groups are the key agreement for the handshake, and the default is the hybrid pair `X25519MLKEM768:x25519`: post-quantum key encapsulation running alongside a classical curve, not instead of it. The cipher is AES-256-GCM, and it protects the traffic once the handshake is done. All three are set in the console and apply across the gateways instead of being retyped per box, which is what stops one site quietly drifting onto something you retired two years ago. That’s the whole feature, and it’s deliberately smaller than a vendor page usually makes it sound.

The Network
The network these three settings reach, gateway by gateway.

Cybersecurity in action

This is the tunnel log on somebody’s laptop seconds after they pressed connect, showing the cipher suite that was actually negotiated rather than the one a document says should have been.

Client Tunnel Logs
Tunnel logs in the QNova Client, with the negotiated cipher suite in plain sight
Benefits

Two readings of the same three settings

The person who runs the network wants to know what breaks the day the cipher changes. The person who signs the contract wants to know what it costs to answer the question when a standard moves, and those aren’t the same worry.

For the network

One screen, every gateway

The three choices apply across the gateways from the console, so you find out what your fleet negotiates by looking instead of by going site by site. What the screen says is what you set.

A change, not a project

Moving to a different key agreement or a different cipher is a configuration change. There’s no new appliance, no re-addressing, and no migration weekend bolted onto it.

The caveat, in advance

Applying a CA rotation regenerates the certificate authority and the server certificate, sends out a new bundle and restarts OpenVPN on the gateway, and it needs every gateway connected. That makes it a maintenance window job. We’d rather you read that here than discover it at 4pm.

For the business

The tender answer, already true

Sooner or later a regulator, a tender or a security questionnaire asks what it would take to change the cipher everywhere. In a lot of networks the honest answer is a project, a budget line and a new box. Here it’s a screen, and the documented cryptographic inventory is the paperwork that goes with it.

A claim with a longer shelf life

Being post-quantum today is a claim about today. Being able to change algorithm without rebuilding the network is what keeps the claim true after the next revision of the standard, and the post-quantum standards are moving right now.

It isn't a tier

The hybrid post-quantum pair is the default, not an upgrade path, so there’s no add-on line on the quote and no conversation waiting for you in eighteen months. You’re paying for the network, not for the right to change its cryptography.

Three steps, and in the first one nobody chooses anything

Here’s what actually has to happen for a cipher change to be real, from the laptop that has no say in it to the screen where you decide. Nobody in this story opens a config file.

Step 1

Nothing to pick, in a hotel, at 7am Someone who'll never log into your console opens the QNova Client and presses connect. There's no algorithm picker on the endpoint, and nothing here a user can switch off on a bad afternoon. Open the connection details and the negotiated cipher suite is right there, next to the tunnel address, the DNS in use and the adapter speed, with quantum-safe shown as a property of the link rather than a badge on a brochure. They can see what's protecting them; they just can't change it.

Client Settings
The settings on the device, where there is no algorithm to pick.
Vpn Power Control
Gateway control in QS-WAN, where the same three choices reach every gateway you run
Step 2

You set it once, and you didn't have to ask anyone The same three choices live on one screen in QS-WAN and reach the gateways from there, so the cryptography stops being something you have to go and confirm per site. One honest caveat, because you'd hit it anyway: with a gateway's Tower Connection off, the change is saved but not pushed. The console is authoritative about what you decided, and it converges when that gateway is reachable again. It shows you the difference instead of a green tick it hasn't earned.

Step 3

The week you get back when the standard moves Now the awkward question has a short answer. When the regulator or the tender asks what it would take to change the cipher across the estate, you point at a screen, and the documented cryptographic inventory per subsystem says which algorithm runs where and for what purpose. Rotating the certificate authority is the one piece that stays a scheduled operation rather than a click, because it regenerates the CA and the server certificate, pushes a new bundle and restarts the service with every gateway connected. Knowing that in advance is the whole difference between a maintenance window and a bad afternoon.

Compliance
Compliance in QS-WAN, where the cryptographic evidence gets read
Specifications
LayerWhat you already haveWhat comes inDoes it move?
[…][…][…]No
[…][…][…]No
[…][…][…]No
Comparison
Replace

**Replace the tunnel whose cryptography you can’t change** If the VPN is already on this year’s list, this takes its place and brings the three settings with it, so the algorithm stops being part of the building.

Add the layer

**Keep what you run and put the changeable channel next to it** If the VPN isn’t going anywhere this year, the gateway sits inside your own addressing and carries the traffic that has to stay private for a decade.

Integrations and dependencies

Gateway connectivity

With a gateway’s Tower Connection off, a change is saved but not pushed. The intent is recorded and converges when the gateway comes back.

OpenVPN on the gateway

A CA rotation regenerates the CA and the server certificate, sends a new bundle and restarts the service, so it needs a window and every gateway connected.

Certificate management

The day-to-day work around these settings, reissue, revoke, reinstate and resend an enrollment, is ordinary console work and lives on its own page.

Platform coverage, stated straight

Windows is complete, Linux is a genuine port with declared gaps, and macOS and iOS are planned. We publish one column at a time instead of a tick across the row.

Proof

100%

of communications encrypted, always with post-quantum cryptography, including the establishment of the tunnels

Two algorithms

in the default key agreement, ML-KEM-768 and X25519 together, so breaking one buys an attacker nothing

2023

, the year we were founded out of quantum computing research. Three full years behind us in 2026

Credentials

Bring the question you can't answer yet

Tell us which tunnel you run today and what your last security questionnaire asked about changing the cipher. We’ll show you the three settings on a live console, applied to a gateway in your own network, and tell you straight which parts need a maintenance window.

Frequently Asked Questions

Crypto agility is being able to change the cryptographic algorithms a system uses without rebuilding the system. Here that means three settings in QS-WAN: the CA algorithm, the TLS groups for the handshake, and the cipher on the traffic. The point isn’t which algorithm you run today. It’s that the answer to “what would it take to change it” is a screen and not a project.

No. Changing the TLS groups or the cipher is a configuration change applied across the gateways from the console, and the network diagram doesn’t move. Rotating the certificate authority is the exception, and it’s covered below.

It regenerates the certificate authority and the server certificate, sends a new bundle out, and restarts OpenVPN on the gateway. It needs every gateway connected when you run it, which makes it a scheduled maintenance operation rather than a click and forget. We say that on the page on purpose, because it’s the part that gets glossed over elsewhere.

No. These three choices are fleet-wide by design, so this isn’t the screen for letting one gateway hold on to something you retired. That’s a limitation and also the reason the setting is worth anything: a fleet-wide switch is what stops a site drifting on its own.

With the documented cryptographic inventory per subsystem, which records what algorithm runs where and for what purpose. The console shows what you set, and the inventory is the artefact a regulator or a tender usually asks for first. One document says what you’re running, one screen changes it, and auditors tend to want both, in that order.

Still unsure
Next

Post-quantum cryptography** - What's actually negotiating on the wire today, and why hybrid means the floor never drops below your classical baseline. `/features/post-quantum-cryptography/`

Certificate management** - Where these certificates come from, and what happens the day one has to be revoked, reissued or reinstated. `/features/certificate-management/`

Secure remote access** - The same three settings seen from the other end: a tunnel that comes up, decided by whoever is supposed to decide it. `/use-cases/secure-remote-access/`

Bring the question you can't answer yet

Tell us which tunnel you run today and what your last security questionnaire asked about changing the cipher. We’ll show you the three settings on a live console, applied to a gateway in your own network, and tell you straight which parts need a maintenance window.

Resources

NEWSLETTER

Get weekly tips, product news and early access, straight to your inbox.

Scroll to Top