
3/31/2022 · Lenka Mareková
What this post added
This post details Cloudflare's work in making SaltStack, an internal infrastructure management tool, quantum-secure. It chronicles the discovery and patching of several security vulnerabilities (CVE-2022-22934, CVE-2022-22935, CVE-2022-22936) in SaltStack's custom cryptographic protocol. Furthermore, it proposes and demonstrates the feasibility of migrating SaltStack's communication to a mutually authenticated TLS (mTLS) based transport as a path towards post-quantum security and improved overall security posture.