Add Post-Quantum Cryptography Support
@bukka 已经在做这个了。
开始于 2026年7月22日。
- 主要语言
- C
- 星标
- 40.4k
- 派生
- 8.2k
- 平均合并
- 2 天 15 小时
- 30 天内合并 PR
- 103
描述
Description
Over 35 countries want their vendors to be post-quantum ready by 2030. Large companies are trying to be post-quantum cryptography (PQC) ready by 2029. This can be seen in blogs by:
Google: https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/#:~:text=Google%27s%20introducing,%28PQC%29%20migration
Microsoft: https://www.microsoft.com/en-us/security/blog/2026/06/30/microsoft-advances-quantum-safe-security-as-the-risk-timeline-shifts/
Cloudflare: https://blog.cloudflare.com/post-quantum-roadmap/
DigiCert: https://www.digicert.com/blog/digicert-post-quantum-infrastructure-migration-plan
In order for a company based on PHP to meet government requirements for post-quantum cryptography by 2030, PHP needs to have native support available with enough time left over for developers to both perform a major PHP version upgrade and then also have the time leftover to write, test, and ship their PQC features on the new PHP version by 2030. Therefore, the work to add PQC support to PHP needs to start now.
Support for post-quantum cryptography (PQC) was added in OpenSSL 3.5: https://openssl.foundation/news/the-features-of-3-5-post-quantum-cryptography
A third-party vendor has developed PQC PHP modules as an option: https://paragonie.com/blog/2026/04/post-quantum-cryptography-for-php-community . However, PHP should have native support for PQC for the same reasons that PHP already has support for traditional cryptography. The existing algorithms that PHP supports will be deprecated in 2030 and disallowed by governments by 2035.
There are more PQC algorithms in development and they will likely be added to OpenSSL in the future. Therefore, it is recommended that PHP support for new PQC algorithms be added in a cryptographically agile way that will help streamline the addition of future algorithms.
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
评估
这个 Issue 还没有评估数据。