For CSfC customers protecting classified information that needs protection for 15 years or longer, symmetric pre-shared keys (post-quantum PSKs) are used now instead of, or in addition to, certificate-based cryptography: at least one of the two CSfC tunnels must use PSKs, preferably both, while at least one tunnel keeps asymmetric key pairs for mutual authentication. The approved PSK protocols are IPsec with RFC 8784-compliant IKEv2 (public-key certificates still required for mutual authentication) and MACsec with pre-shared connectivity association keys. PSK generation, distribution, installation, rekey, destruction and accounting are critical functions; a compromised PSK means rekeying every component that holds it. The FAQ ranks standards-compliant pre-shared symmetric keys above unvalidated post-quantum asymmetric algorithms as a near-term measure.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.