It’s called a Postquantum Preshared Key (PPK), defined in RFC 8784. The idea: mix in a secret that never travelsRFC 8784 takes a completely different route to the harvest-now-decrypt-later problem. (At scale, the secrets are either managed manually or generated by Quantum Key Distribution appliances needing a full mesh of point-to-point fibers, none of which scales gracefully.) The output now lists the PPK alongside the auth PSK:loaded ike secret 'ike-psk' loaded ppk secret 'ppk-lab'Reminder: these are lab secrets. Prove it’s actually requiredBecause we set ppk_required = yes , a peer that doesn’t hold the matching PPK can’t complete the handshake.