Skip to content

SYSTEM Cited by 1 source

Cloudflare Automatic Key Exchange

What

Automatic Key Exchange (announced 2026-09-08) is a Cloudflare feature — an extension of Automatic SSL/TLS — that eliminates wasted TLS-1.3 round trips on the Cloudflare → origin hop by replacing a static key-agreement guess with a per-origin measurement. Cloudflare, acting as the TLS client to the origin, previously always led with a classical X25519 keyshare in its first ClientHello (see predictive key exchange). When the origin preferred another group it replied with a HelloRetryRequest, costing a second round trip. Automatic Key Exchange scans each origin, learns which groups it supports, and leads with the strongest — preferring the post-quantum hybrid X25519MLKEM768 — so post-quantum origin handshakes complete in one round trip with no customer configuration. (Source: sources/2026-09-08-cloudflare-automatic-key-exchange-faster-post-quantum-secure-origin-han)

Why it exists

TLS 1.3 requires committing to a key-agreement group and sending a keyshare in the first packet. A static X25519 guess was safe (>95% of origins support X25519) but suboptimal for ~30% of origins, and it forced every post-quantum-capable origin through an HRR because PQ was only advertised, not led with. Leading with a PQ keyshare directly was blocked by size: an X25519MLKEM768 keyshare is 1,216 bytes vs X25519's 32 bytes, pushing the ClientHello past one packet, and ~0.34% of origins fail on a split ClientHello. Automatic Key Exchange resolves this by measuring per-origin capability out-of-band, so it only leads with PQ where the origin and the network path are confirmed to handle it.

How it works

  1. Active out-of-band probing. For each TLS 1.3 origin, run a few lightweight handshakes, each offering exactly one group (X25519, P-256, P-384, P-521, X25519MLKEM768). Off the production path, so origin + network are confirmed before real traffic depends on the stronger group. This is the measure-don't-guess pattern — passive observation can't reveal full capability because origins often accept X25519 without signalling PQ preference.
  2. Per-subdomain, traffic-weighted aggregation. Each subdomain (which may resolve to a different origin) is evaluated independently and weighted by actual HTTP traffic, so busy www/api endpoints dominate the domain-wide preference.
  3. Strict priority selection. X25519MLKEM768 → then fastest accepted classical (X25519 → P-256 → P-384 → P-521).
  4. Monitored progressive rollout with rollback. New preference ships to a small traffic slice while HRR/failure rate is watched; if retries exceed the origin's baseline, roll back. Worst case = one extra round trip, never a broken connection — same revert discipline as Automatic SSL/TLS encryption- mode upgrades. See patterns/staged-rollout.
  5. Daily rescan. Origins change (new load balancer, TLS library ships PQ, operator disables a curve); rescanning daily re-derives the preference.

Compliance requirements (intent-based)

A new control restricts what Automatic Key Exchange may negotiate:

  • Post-quantum hybrid — X25519MLKEM768 only; every successful TLS 1.3 origin connection is guaranteed PQ-secure (removes classical groups entirely).
  • FIPS — FIPS-compliant groups only.

Selecting both requires an algorithm satisfying both; no overlap → config rejected. You configure intent, so the algorithm set stays current as standards evolve. Footgun: enforcing PQ-hybrid on an origin lacking X25519MLKEM768 leaves no mutual algorithm → all TLS 1.3 connections fail; Cloudflare advises leaving both unset absent a hard policy mandate.

Impact (measured)

  • HRR on scanned origins 52% → 3.7%; >150 ms off p90 handshake latency.
  • PQ origin handshakes completing in one round trip 0% → 99.2%.
  • PQ origin traffic ~25B → 45B connections/day.
  • Preference assigned to >1 million domains so far (~9,000 more/day move off X25519, nearly all to PQ). First cohort: 64% stayed X25519, 33% → X25519MLKEM768, 3% other classical curve.

Particularly benefits dynamic requests and CDN cache misses that need a fresh origin TLS connection; keep-alive traffic is unaffected.

Roadmap

  • Per-origin/per-subdomain preference granularity (today decisions are domain-level, so one weak origin holds a whole domain back).
  • On-demand rescans from dashboard/API + as a diagnostic tool.
  • Automatic PQ origin authentication — extend scanning to detect ML-DSA cert (later Merkle Tree Certificates) support and auto-disable classical fallback to close the downgrade gap.

Seen in

Last updated · 766 distilled / 2,225 read