Skip to main content

Crypto posture

The Crypto posture screen tells you what your estate can actually support today, so you know what can migrate before you change policy.

ConsoleCrypto posture

What it's for​

  • See how many endpoints can accept a post-quantum (PQ) signature, a hybrid key exchange, or only classical cryptography.
  • Decide whether it is safe to introduce or require post-quantum algorithms in Policies.
  • Plan which certificate sets to move first in Migrations.

What you see​

Crypto posture screen with the Estate compatibility bars, the Transition posture donut and the Migration control note
Crypto posture.

Estate compatibility​

The large number is the count of fresh cryptographic endpoint observations: endpoints for which a Mesh Node or SDK has reported current capability evidence.

Below it, three bars show the count and percentage of those endpoints in each class:

BarMeaning
PQC signature readyThe endpoint can accept a certificate with a post-quantum signature.
Hybrid key exchange readyThe endpoint can negotiate a hybrid (classical plus post-quantum) key exchange.
Classical onlyThe endpoint supports only classical algorithms.

Expired or unverified observations never count toward readiness. An endpoint whose evidence has expired, or whose evidence was imported by an administrator rather than observed by a machine, does not make the readiness numbers look better than they are.

Transition posture​

A donut chart of the PQ signature ready percentage, with a legend for PQ signature, Hybrid KEM and Classical only.

Migration control is operational​

A note pointing to Migrations, which turns this posture into immutable, dependency-ordered waves with independent approval, sustained health proof and automatic exact certificate rollback.

Where the evidence comes from​

Capability evidence is reported by your enrolled Mesh Nodes and by workloads using the SDK. The Trust health screen summarizes the same data as x of y endpoints are ready for the next wave, or No endpoint capability evidence yet if nothing has been reported. See Overview & trust health.

Common tasks​

Decide whether to require post-quantum signatures​

  1. Open ConsoleCrypto posture and check the Classical only bar. Any endpoint in that class cannot accept a PQ-only identity.
  2. Open Trust graph to see which callers depend on the services you want to change.
  3. Open Policies, select Configure next version, and change Transition mode or the signature choices.
  4. Select Assess managed estate. The assessment classifies each managed endpoint and blocks a cryptographic change while any endpoint is not compatible.

Permissions​

Every role can view this screen. It has no actions of its own.

Troubleshooting​

SymptomCause and fix
All numbers are zeroNo fresh capability evidence has been reported. Enroll a Mesh Node, or check that your nodes are healthy.
Readiness dropped without any changeEvidence expired. Readiness counts only current observations; nodes refresh them as they observe endpoints.