H2-CPQE · Core certification path
Edge and Post-Quantum Networking
H2 Certified Post-Quantum Edge Engineer
The traffic layer nobody else teaches: multi-region edge points of presence, hybrid post-quantum TLS terminated at each one, DNSSEC end to end, and the WAF and rate limits that keep it standing under load and attack.
6 courses · 22 lessons · ~37 h of guided work
Assumes Foundation
What you leave with
Edge PoPs in three regions behind anycast, terminating hybrid ML-KEM TLS, fronted by a WAF, over a DNSSEC-signed zone you rotate keys on.
- Gateway
- Envoy Gateway
- Routing
- Anycast + GeoDNS
- TLS
- Hybrid ML-KEM
- DNS
- Knot + DNSSEC
- WAF
- Coraza / CRS
- Tunnels
- WireGuard / Headscale
Syllabus
6 courses · every lesson graded · minutes are guided work
Course 01
Edge points of presence
Envoy Gateway as the front door in several regions, with health checks, timeouts and the discipline that stops a config change taking down two name servers.
4 lessons · ~7 h
- 01The edge tierWhy terminate at the edge; what lives at the PoP and what stays in the core.90 min
- 02Envoy GatewayListeners, routes, health checks and timeouts for a real backend; the config in git.120 min
- 03Multi-region rolloutCanary one PoP directory; a throwaway-pod test first; the 25-minute dual-NS outage and how to never repeat it.120 min
- 04Readiness that means itA readiness check that proves the zone actually answers before traffic shifts.90 min
Course checkDeploy a PoP to a new region by promoting one directory only, prove readiness from outside, and fail a bad change safely.
You leave withA per-PoP Envoy Gateway deployment, canaried one region at a time, with readiness that proves the zone answers.
Course 02
Anycast and GeoDNS
Get the user to the nearest healthy PoP with anycast and geo-aware DNS, and take a sick one out of rotation before anyone notices.
3 lessons · ~5 h
- 01Anycast basicsOne address, many locations; how withdrawal moves traffic; the failure it does not solve.90 min
- 02GeoDNSAnswers that depend on where the query came from; TTLs tuned for failover, not caching.90 min
- 03Health-based withdrawalA failing PoP pulled from rotation automatically; the drain you watched happen.90 min
Course checkRoute users to the nearest PoP, then drain one on health failure with no user-visible error.
You leave withAnycast fronting your PoPs with GeoDNS steering and automatic withdrawal of an unhealthy region.
Course 03
Post-quantum TLS
Hybrid key exchange with ML-KEM at the edge, verified from the client, plus the migration story for signatures. The thing your CPQE badge is named for.
4 lessons · ~7 h
- 01The quantum threat modelHarvest-now-decrypt-later; what is urgent, what is not, and why hybrid first.90 min
- 02ML-KEM key exchangeEnable the hybrid group at the edge; confirm X25519MLKEM768 negotiated from a real client.120 min
- 03No downgradeProve a stripping attempt cannot force classical; policy that forbids it.90 min
- 04Signatures and the road aheadWhere ML-DSA fits, what is not ready, and a migration plan you can defend.90 min
Course checkTerminate hybrid ML-KEM TLS at the edge, prove the group from the client, and show no downgrade under a stripping attempt.
You leave withEdge TLS negotiating a hybrid ML-KEM group, verified externally, with a written migration plan for signatures.
Course 04
DNSSEC with Knot
Sign the zone, chain it to the parent, and rotate keys without breaking resolution, using the module-signing facts that are easy to get wrong.
4 lessons · ~7 h
- 01Why DNSSECThe attacks it stops; validation from a resolver you control.90 min
- 02Signing with Knotoffline-KSK, the KASP path decided by database.storage, and knotc reload after key changes.120 min
- 03Chaining to the parentThe DS record at the registrar, and validation proven end to end.90 min
- 04Key rotationAn automated ZSK rotator on a schedule, plus an emergency KSK rollover you rehearsed.120 min
Course checkSign a zone, publish the DS at the parent, validate end to end, then roll the ZSK with no resolution failure.
You leave withA DNSSEC-signed zone validating from the root, with an automated ZSK rotation and an emergency rollover you tested.
Course 05
WAF, rate limiting and DDoS
Keep the edge up under a flood and a scanner: a WAF tuned so it blocks attacks and not your users, and limits that shed load fairly.
4 lessons · ~7 h
- 01WAF in frontCoraza with the core rule set at the edge; a real attack blocked, a real user not.120 min
- 02Tuning out false positivesThe CRS rule that blocks a localhost redirect_uri, found and tuned, without opening a hole.120 min
- 03Rate limitingPer-client and per-route limits; fair shedding under a burst; the retry-after contract.90 min
- 04Reading the floodAnswer are-we-blocked from access logs by code and upstream, not from WAF denials alone.90 min
Course checkUnder a simulated flood and an attack traffic mix, keep good traffic flowing with a false-positive rate under the bar.
You leave withA WAF at the edge with a tuned rule set, rate limits that shed fairly, and a dashboard that answers are-we-blocked from the access log.
Course 06
Private access and tailnets
The operator's own path in: a WireGuard tailnet with a self-hosted coordinator, so admin surfaces never touch the public internet.
3 lessons · ~5 h
- 01WireGuardA tunnel by hand; keys, peers, and the smallest possible allowed IPs.90 min
- 02Self-hosted coordinationHeadscale coordinating the tailnet; device enrolment and expiry.120 min
- 03Admin behind the tailnetGrafana and the cluster API reachable only on the tailnet; proven closed from the public internet.90 min
Course checkPut an admin surface behind a tailnet so it is unreachable publicly and reachable only to enrolled, authorized devices.
You leave withA Headscale-coordinated WireGuard tailnet with device authorization, fronting every admin surface, proven closed from outside.
Certification course
H2 Certified Post-Quantum Edge Engineer
$499 · one price · courses + 90-day labs + exam
Run traffic through your edge while a region goes dark, a flood hits one PoP, and a key rotation lands mid-storm. Graded on continuity, no downgrade, and the zone still validating.
Opens when Foundation is complete and the 6 course checks are passed. One proctored attempt, plus a free retake if you fail by a margin. The credential is an Open Badges 3.0 credential, signed and verifiable.
Counts toward H2-CTSE. Certified T-Shaped Security Expert is the credential of the whole T: hold all seven core credentials and it is awarded automatically, free, with no extra exam.
Create an account to enrol