Hi Matt,

1: For the NCP VPN solution we plan to implement the full RFC 9370 and RFC 4739 
with all NIST standardized PQ KEM and signature algorithms that are available 
in the OpenSSL library.

2:  We have just started on implementing PQC for our IPSec Client and Server, 
and would like to do some interoperability testing once we have a working 
prototype, hopefully sometime in Q3 of this year.

Regards,
Christian





[cid:NCP-Logo_91be57f9-c3b1-4968-a5e9-634c99c151e9.png]

Christian Vögl

Software Engineer
[email protected]
Phone: +49 911 9968 0
www.ncp-e.com





Follow us on: Facebook<https://www.facebook.com/NCPengineering> | 
Xing<https://www.xing.com/companies/ncpengineeringgmbh> | 
YouTube<https://www.youtube.com/user/NCPengineeringGmbH> | 
LinkedIn<http://www.linkedin.com/company/ncp-engineering-inc.?trk=cws-cpw-coname-0-0>
 | Instagram<https://www.instagram.com/ncp_engineering/> | Blog: VPN 
Haus<https://www.vpnhaus.com/de/> | 
Podcast<https://podcasts.apple.com/de/podcast/be-safe-not-sorry/id1702137490>

Headquarters Germany: NCP engineering GmbH • Dombuehler Str. 2 • 90449 • 
Nuremberg
North American HQ: NCP engineering Inc. • 19321 US Highway 19 N, Suite 401 • 
Clearwater, FL 33764

Authorized representatives: Peter Soell, Patrick Oliver Graf, Beate Dietrich
Registry Court: Lower District Court of Nuremberg
Commercial register No.: HRB 7786 Nuremberg, VAT identification No.: DE 
133557619

This e-mail message including any attachments is for the sole use of the 
intended recipient(s) and may contain privileged or confidential information. 
Any unauthorized review, use, disclosure or distribution is prohibited. If you 
are not the intended recipient, please immediately contact the sender by reply 
e-mail and delete the original message and destroy all copies thereof.


<https://www.ncp-e.com/de/aktuelles/events/veranstaltungen><https://www.ncp-e.com/de/aktuelles/events/veranstaltungen>
From: Matt Ige <[email protected]>
Sent: Friday, 15 May 2026 21:06
To: [email protected]; [email protected]
Cc: Shankar Seal <[email protected]>; Nick Grifka 
<[email protected]>; Sarath Madakasira <[email protected]>; Anirban Paul 
<[email protected]>
Subject: [IPsec] PQC integration in IPsec/IKEv2 - implementation experience and 
interop

Hi,
I’m reaching out to understand how others are approaching the integration of 
post-quantum cryptography (PQC) into their IPsec/IKEv2 implementations.

We are currently looking at the CNSA 2.0 IPsec profile draft as a reference: 
https://datatracker.ietf.org/doc/draft-guthrie-cnsa2-ipsec-profile

I have a couple of specific questions:
1. Beyond what is outlined in this draft, are there additional requirements, 
design considerations, or extensions that implementations are incorporating in 
practice?
2. Are there organizations actively implementing PQC for IPsec that would be 
interested in interoperability testing or collaboration?

We are actively working on our implementation and are particularly interested 
in ensuring alignment with emerging standards and ecosystem compatibility. I 
appreciate any insights or pointers.


Thanks,

Matt

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to