PQ-TLS mainly means swapping key exchange first; cert signatures stay the real bloat in the handshake.
3 comments
So PQ-TLS is mostly hybrid key exchange first, with cert signatures still the annoying part. Feels like the real migration pain gets deferred again.
> real migration pain gets deferred again
No, cert signatures are the hard stop, since handshake size and trust roots won't vanish with KEMs.
The bigger bill lands on CDNs and load balancers, not cert teams.