Post-Quantum Cryptography (PQC) Readiness
The service operates as a PQC Vanguard.
1. Transport Layer: Negotiates TLS 1.3 Hybrid Key Exchange (ML-KEM) via an OpenSSL 3.6.3 + Nginx proxy.
2. Java Engine: Upgraded to Spring Boot 4 and OpenJDK 25 to support native ML-DSA signature verification and jdk.tls.namedGroups injection for outbound CA connections.