← Every path

H2-CPQE · Core certification path

Edge and Post-Quantum Networking

H2 Certified Post-Quantum Edge Engineer

The traffic layer nobody else teaches: multi-region edge points of presence, hybrid post-quantum TLS terminated at each one, DNSSEC end to end, and the WAF and rate limits that keep it standing under load and attack.

6 courses · 22 lessons · ~37 h of guided work

Assumes Foundation

What you leave with

Edge PoPs in three regions behind anycast, terminating hybrid ML-KEM TLS, fronted by a WAF, over a DNSSEC-signed zone you rotate keys on.

Gateway
Envoy Gateway
Routing
Anycast + GeoDNS
TLS
Hybrid ML-KEM
DNS
Knot + DNSSEC
WAF
Coraza / CRS
Tunnels
WireGuard / Headscale

Syllabus

6 courses · every lesson graded · minutes are guided work

  1. Course 01

    Edge points of presence

    Envoy Gateway as the front door in several regions, with health checks, timeouts and the discipline that stops a config change taking down two name servers.

    4 lessons · ~7 h

    1. 01The edge tierWhy terminate at the edge; what lives at the PoP and what stays in the core.90 min
    2. 02Envoy GatewayListeners, routes, health checks and timeouts for a real backend; the config in git.120 min
    3. 03Multi-region rolloutCanary one PoP directory; a throwaway-pod test first; the 25-minute dual-NS outage and how to never repeat it.120 min
    4. 04Readiness that means itA readiness check that proves the zone actually answers before traffic shifts.90 min

    Course checkDeploy a PoP to a new region by promoting one directory only, prove readiness from outside, and fail a bad change safely.

    You leave withA per-PoP Envoy Gateway deployment, canaried one region at a time, with readiness that proves the zone answers.

  2. Course 02

    Anycast and GeoDNS

    Get the user to the nearest healthy PoP with anycast and geo-aware DNS, and take a sick one out of rotation before anyone notices.

    3 lessons · ~5 h

    1. 01Anycast basicsOne address, many locations; how withdrawal moves traffic; the failure it does not solve.90 min
    2. 02GeoDNSAnswers that depend on where the query came from; TTLs tuned for failover, not caching.90 min
    3. 03Health-based withdrawalA failing PoP pulled from rotation automatically; the drain you watched happen.90 min

    Course checkRoute users to the nearest PoP, then drain one on health failure with no user-visible error.

    You leave withAnycast fronting your PoPs with GeoDNS steering and automatic withdrawal of an unhealthy region.

  3. Course 03

    Post-quantum TLS

    Hybrid key exchange with ML-KEM at the edge, verified from the client, plus the migration story for signatures. The thing your CPQE badge is named for.

    4 lessons · ~7 h

    1. 01The quantum threat modelHarvest-now-decrypt-later; what is urgent, what is not, and why hybrid first.90 min
    2. 02ML-KEM key exchangeEnable the hybrid group at the edge; confirm X25519MLKEM768 negotiated from a real client.120 min
    3. 03No downgradeProve a stripping attempt cannot force classical; policy that forbids it.90 min
    4. 04Signatures and the road aheadWhere ML-DSA fits, what is not ready, and a migration plan you can defend.90 min

    Course checkTerminate hybrid ML-KEM TLS at the edge, prove the group from the client, and show no downgrade under a stripping attempt.

    You leave withEdge TLS negotiating a hybrid ML-KEM group, verified externally, with a written migration plan for signatures.

  4. Course 04

    DNSSEC with Knot

    Sign the zone, chain it to the parent, and rotate keys without breaking resolution, using the module-signing facts that are easy to get wrong.

    4 lessons · ~7 h

    1. 01Why DNSSECThe attacks it stops; validation from a resolver you control.90 min
    2. 02Signing with Knotoffline-KSK, the KASP path decided by database.storage, and knotc reload after key changes.120 min
    3. 03Chaining to the parentThe DS record at the registrar, and validation proven end to end.90 min
    4. 04Key rotationAn automated ZSK rotator on a schedule, plus an emergency KSK rollover you rehearsed.120 min

    Course checkSign a zone, publish the DS at the parent, validate end to end, then roll the ZSK with no resolution failure.

    You leave withA DNSSEC-signed zone validating from the root, with an automated ZSK rotation and an emergency rollover you tested.

  5. Course 05

    WAF, rate limiting and DDoS

    Keep the edge up under a flood and a scanner: a WAF tuned so it blocks attacks and not your users, and limits that shed load fairly.

    4 lessons · ~7 h

    1. 01WAF in frontCoraza with the core rule set at the edge; a real attack blocked, a real user not.120 min
    2. 02Tuning out false positivesThe CRS rule that blocks a localhost redirect_uri, found and tuned, without opening a hole.120 min
    3. 03Rate limitingPer-client and per-route limits; fair shedding under a burst; the retry-after contract.90 min
    4. 04Reading the floodAnswer are-we-blocked from access logs by code and upstream, not from WAF denials alone.90 min

    Course checkUnder a simulated flood and an attack traffic mix, keep good traffic flowing with a false-positive rate under the bar.

    You leave withA WAF at the edge with a tuned rule set, rate limits that shed fairly, and a dashboard that answers are-we-blocked from the access log.

  6. Course 06

    Private access and tailnets

    The operator's own path in: a WireGuard tailnet with a self-hosted coordinator, so admin surfaces never touch the public internet.

    3 lessons · ~5 h

    1. 01WireGuardA tunnel by hand; keys, peers, and the smallest possible allowed IPs.90 min
    2. 02Self-hosted coordinationHeadscale coordinating the tailnet; device enrolment and expiry.120 min
    3. 03Admin behind the tailnetGrafana and the cluster API reachable only on the tailnet; proven closed from the public internet.90 min

    Course checkPut an admin surface behind a tailnet so it is unreachable publicly and reachable only to enrolled, authorized devices.

    You leave withA Headscale-coordinated WireGuard tailnet with device authorization, fronting every admin surface, proven closed from outside.

Certification course

H2 Certified Post-Quantum Edge Engineer

$499 · one price · courses + 90-day labs + exam

Run traffic through your edge while a region goes dark, a flood hits one PoP, and a key rotation lands mid-storm. Graded on continuity, no downgrade, and the zone still validating.

Opens when Foundation is complete and the 6 course checks are passed. One proctored attempt, plus a free retake if you fail by a margin. The credential is an Open Badges 3.0 credential, signed and verifiable.

Counts toward H2-CTSE. Certified T-Shaped Security Expert is the credential of the whole T: hold all seven core credentials and it is awarded automatically, free, with no extra exam.

Create an account to enrol