Mutual Post-Quantum Auth over IKEv2 – IPsec Series, Part 8
We mutually authenticate an IKEv2 tunnel: classical ECDSA first, then ML-DSA over an ML-KEM key exchange, and watch the ML-DSA certs balloon the authentication message into six fragments on the wire.















