ADR-007: Post-Quantum Cryptography Migration Strategy #3072
+981
−0
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Context
With NIST publishing the first post-quantum cryptography standards in August 2024 (FIPS 203, 204, 205), and "harvest now, decrypt later" attacks already active, it's prudent to document Openfire's quantum threat exposure and plan for migration.
Key Findings
Proposed Timeline
Technology Choices
Why This Matters
Related ADRs
Notes for Reviewers
This ADR is intentionally forward-looking. It documents current quantum readiness and proposes a migration strategy, but does not require immediate implementation. The "Proposed" status indicates this is open for community discussion before acceptance.
Key questions for reviewers: