This article provides information regarding the support for migration to post-quantum cryptography (PQC) and quantum-safe cryptography in VMware NSX version 4.2.2. It clarifies which specific quantum-safe algorithms (such as ML-KEM, ML-DSA, SLH-DSA, AES-256, and SHA-256) are currently supported within NSX.
VMware NSX 4.2.2
VMware NSX version 4.X does not currently feature native support for the newly standardized asymmetric PQC algorithms, such as ML-KEM, ML-DSA, or SLH-DSA.
While the new asymmetric algorithms are not yet present, NSX 4.2.2 fully supports and heavily utilizes robust classical algorithms that are widely considered to be quantum-resistant: AES-256 and SHA-256.
These are used extensively across NSX for securing IPsec VPNs, TLS communications, and data encryption.
Additionally, the NSX 4.2.2 release introduced compliance with the strict FIPS 140-3 standard, which relies heavily on these strong cryptographic algorithms.
For environments utilizing the NSX Advanced Load Balancer (Avi), Broadcom has already introduced native PQC capabilities. Recent versions of the NSX ALB support:
ML-KEM for Key Encapsulation.
ML-DSA for TLS 1.3 secure communications and certificates.
Broadcom is actively participating in industry standards bodies to define and implement next-generation PQC across the entire VMware Cloud Foundation (VCF) ecosystem. This roadmap includes upcoming hardware-level integrations, such as support for TPM 2.0 hardware equipped with ML-KEM and ML-DSA capabilities.