None
IT
A Different Road to Quantum Safety: The PPK – IPsec Series, Part 5
['Julio Gomez']
Cisco Blogs
It’s called a Postquantum Preshared Key (PPK), defined in RFC 8784.
The idea: mix in a secret that never travelsRFC 8784 takes a completely different route to the harvest-now-decrypt-later problem.
(At scale, the secrets are either managed manually or generated by Quantum Key Distribution appliances needing a full mesh of point-to-point fibers, none of which scales gracefully.)
The output now lists the PPK alongside the auth PSK:loaded ike secret 'ike-psk' loaded ppk secret 'ppk-lab'Reminder: these are lab secrets.
Prove it’s actually requiredBecause we set ppk_required = yes , a peer that doesn’t hold the matching PPK can’t complete the handshake.