rules
rules copied to clipboard
cross-transport PQC (TLS/DTLS, IPsec/IKEv2) guidance
NEW: PQC guidance across transports.
-
TLS/DTLS: enforce 1.3 only. (ML-KEM-768 + ECDHE; ML-KEM-1024 where required)
-
IPsec/IKEv2: IKEv2-only; AEAD ESP; PFS via ECDHE; disable legacy suites; enable PQC hybrids per RFC 9242/9370 (ML-KEM-768 + ECDHE; ML-KEM-1024 where required).
Validation: 109/109 passed; skills regenerated; frontmatter OK.