Mutual Post-Quantum Auth over IKEv2 – IPsec Series, Part 8

· Blogs Cisco · Aug. 24, 2026, 8 p.m.
Summary
This post discusses the technical implementation of mutual authentication in IKEv2 tunneling, utilizing classical ECDSA and ML-DSA over an ML-KEM key exchange. It highlights the performance implications due to the size of ML-DSA certificates exceeding expectations, resulting in fragmented messages. This is a detailed, technical exploration aimed at developers or engineers involved in network security.