The realities of quantum computing and its inevitable impact on enterprise cryptography are already taking shape:
- Red Hat Enterprise Linux has been post-quantum cryptographically (PQC)-capable since the launch of Red Hat Enterprise Linux 10 (RHEL) in 2025.
- Hyperscalers like AWS and Google Cloud Platform are revisiting their original estimates for PQC availability in light of continued advances in the space.
- Organizations like Microsoft and Google are either advancing PQC adoption deadlines or progressively adopting PQC as part of their standard security stack.
- Governments, including the United States, are speeding up certain PQC deadlines while others, such as France, will stop certifying security products that lack quantum-resistant encryption.
The quantum transition is not a future upgrade. It is an active, structural vulnerability requiring immediate architectural attention; the US government is considering classical cryptography as a vulnerability. National Security Memorandum 10 and the subsequent Executive Order 14412 (Securing the Nation Against Advanced Cryptographic Attacks) alongside OMB Memorandum M-26-15 categorize traditional, classical public-key (asymmetric) cryptography as an active security vulnerability that must be inventoried, phased out, and replaced across government systems and critical infrastructure.
Modernization projects take time, and not treating PQC transition as such is a strategic mistake.
Getting the quantum transition "right"
To accelerate this migration safely, you first need clear visibility into your estate. This is where automation sets the stage. One option our customers have is to run the PQC Discovery Workflow with Red Hat Ansible Automation Platform to identify legacy certificates (among many other cryptographic attributes) in use by your fleet for remediation.
Having an automated map of your cryptographic exposure is essential, but discovery is only half the equation. Once Ansible Automation Platform flags your non-compliant assets, you need an enterprise-grade trust engine to issue and manage quantum-resistant identities at scale.
This is where Red Hat Certificate System 11 comes in. At Red Hat, we believe that cryptographic modernization is not a point-in-time compliance exercise, but a foundational capability for enterprise survival. With Red Hat Certificate System acting as your centralized, post-quantum trust anchor, you can seamlessly turn discovery into action—moving your organization from reactive panic to a posture of continuous, automated cryptographic readiness.
What is Red Hat Certificate System 11?
Every enterprise security architecture begins with a trust anchor — the root of trust that binds identities to cryptographic keys. Red Hat Certificate System is a highly scalable, enterprise-grade Public Key Infrastructure (PKI) engine built on the open source Dogtag project. It provides the certificate authority, key recovery, and OCSP services that government agencies and Fortune 500 enterprises rely on to issue, manage, and revoke certificates across their most critical infrastructure. With support for automated enrollment protocols like EST and ACME, Certificate System enables zero-touch certificate issuance at the scale that modern hybrid-cloud and IoT environments demand
With Red Hat Certificate System 11, this proven foundation takes a definitive leap forward.
- It natively supports standard-compliant quantum-resistant algorithms, including ML-DSA for digital signatures (FIPS-204) and ML-KEM for key encapsulation (FIPS-203).
- Acting as a centralized, multi-tenant trust anchor, Red Hat Certificate System 11 allows organizations to issue, manage, and revoke x.509 post-quantum certificates across hybrid-cloud architectures
- It confirms that your server-to-server communications are fundamentally unreadable to future quantum eyes.
3 reasons Red Hat Certificate System is your best strategy for the PQC transition
The question is not whether your organization needs to transition, but how quickly you can do it without collapsing under the weight of manual cryptographic management. We previously talked about how Mosca's Inequality Theorem can assist in understanding migration timelines against the Q-day horizon.
Malicious actors are not waiting for quantum computers to be built. Under the strategy of "harvest now, decrypt later" (HNDL), they are actively intercepting and storing encrypted enterprise traffic today. Their goal is simple: Hold your data until a cryptanalytically relevant quantum computer can effortlessly unravel its encryption. If your infrastructure relies on standard, non-quantum-resistant cryptography, you are unprotected. You are renting a temporary window of confidentiality.
1. Modernize without friction with RHEL Global Crypto Policies
Manually reconfiguring every application, database, and endpoint to utilize new PQC algorithms is an operational nightmare. It takes months of manual labor, introduces catastrophic human error, and risks widespread system downtime.
Red Hat Certificate System 11 removes this friction by integrating directly with RHEL's Global Cryptographic Policies. Instead of modifying apps individually, administrators can shift the entire operating system's cryptographic posture to a post-quantum standard with a single command line change. Certificate System seamlessly aligns with these policies, automatically enforcing quantum-resistant standards across your entire fleet.
2. Defeating the shrinking certificate lifespan with zero-touch automation
The quantum transition is colliding head-on with an immediate operational crisis: rapidly shrinking certificate lifespans. As industry mandates push TLS validity down from 398 days to 90 days (and eventually fewer), certificate renewal volumes are quadrupling across the enterprise. Managing this manually was already a leading cause of costly, unplanned downtime; attempting to do it under PQC, where key sizes swell, network payloads increase, and dual-signatures double the operational burden, can lead organizations on a fast track to paralysis..
Red Hat Certificate System 11 answers this crisis with zero-touch, automated lifecycle management. Utilizing secure, machine-to-machine token workflows, the platform automates the entire lifecycle of post-quantum certificates, from issuance to automated rotation and revocation. By removing human touchpoints from the pipeline, Certificate System 11 transforms weeks or error prone manual labor into seconds of policy-driven, zero-trust machine provisioning at the velocity of your agentic and enterprise operations.
3. A foundation built on government-grade trust
Enterprise decision-makers are rightly cautious about deploying new cryptographic standards in mission and business-critical networks. They don't need experimental sandboxes, they need proven stability. Certificate System 11 delivers NIST-finalized post-quantum algorithms on top of established, enterprise-hardened infrastructure.
As a National Information Assurance Partnership (NIAP) certified and NSA CSfC-approved platform, Red Hat Certificate System 11 is a defense-grade bedrock used by both public sector agencies and Fortune 500 enterprises to enforce compliance in high-threat environments. When you deploy Red Hat Certificate System 11, you are adopting a mature, legally validated product designed for long-term operational resilience.
Speed up your transition plan
Digital sovereignty, zero trust, and data protection (PQC or otherwise) are not static checkboxes, nor are they destinations where you cross a finish line and stop. They represent a living operational discipline: a continuous posture of non-negotiable trust and resilience.
The cornerstone of this discipline is crypto-agility. Without a crypto-agile framework, migrating to PQC can become a fragile, high-risk overhaul that threatens operational collapse. With crypto-agility at its core, PQC transition isn't a disruptive emergency; it becomes a rapid, repeatable, policy-driven evolution.
Trust cryptographic modernization is about perpetual readiness. By pairing automated fleet intelligence with the enterprise-grade trust anchor of Red Hat Certificate System 11, you gain the power to continuously upgrade your enterprise armor, enforce zero trust at scale, and maintain absolute digital sovereignty, without your business collapsing under the weight of the change.
Red Hat Certificate System 11 is designed to bridge the gap between today's operational realities and tomorrow's quantum threats. By choosing Red Hat Certificate System, you gain:
- Seamless modernization: Align your security posture with RHEL Global Cryptographic Policies, reducing the operational friction of manual updates.
- Zero-touch automation: Eliminate the operational nightmare of shrinking certificate lifespans and complex post-quantum keys with automated, one-time password provisioning.
- Government-grade trust: Deploy post-quantum cryptography with complete confidence using a mature, NIAP-certified, CNSA 2.0-capable platform built for high-security environments.
Ready to secure your trust chain?
- Take the first step by reviewing the Red Hat Certificate System documentation.
- Contact your Red Hat Account Team today to audit your current cryptographic posture and map out your PQC migration strategy.
- Contribute to the DogTag Certificate System, the upstream project of Red Hat Certificate System.
Red Hat Product Security
About the authors
Emily Fox is a DevOps enthusiast, security unicorn, and advocate for Women in Technology. She promotes the cross-pollination of development and security practices.
Luis I. Cortes brings 20 years of experience in enterprise software. He specializes in generative AI, Red Hat partners, and startup ecosystems. From starting up technology companies, to raising funds to grow and scale them globally, to helping multinational technology companies achieve new feats, Luis is all about innovation and growth.
More like this
The Lightwell reality check
Beyond container boundaries: Kernel-level agent security in Red Hat OpenShift AI 3.5
Can Compliance Be A Piece Of Cake? | Compiler
Collaboration In Product Security | Compiler
Keep exploring
- Security approaches for hybrid cloud environments
Whitepaper - A layered approach to container and Kubernetes securityWhitepaper
Browse by channel
Automation
The latest on IT automation for tech, teams, and environments
Artificial intelligence
Updates on the platforms that free customers to run AI workloads anywhere
Open hybrid cloud
Explore how we build a more flexible future with hybrid cloud
Security
The latest on how we reduce risks across environments and technologies
Edge computing
Updates on the platforms that simplify operations at the edge
Infrastructure
The latest on the world’s leading enterprise Linux platform
Applications
Inside our solutions to the toughest application challenges
Virtualization
The future of enterprise virtualization for your workloads on-premise or across clouds