Back to articles
Technology Insight

Building a Post-Quantum Secure Peer-to-Peer Overlay Network with NetBird and Rosenpass

June 6, 2026

The Coming Quantum Threat to Corporate Infrastructure

In the modern enterprise landscape, secure connectivity is the bedrock of operational integrity. For years, virtual private networks (VPNs) and traditional overlay networks have relied on classical public-key cryptography—such as RSA and Elliptic Curve Cryptography (ECC)—to secure data in transit. However, a paradigm shift is looming on the horizon. The advent of cryptographically relevant quantum computers (CRQCs) threatens to render these foundational security protocols obsolete.

Through Shor's algorithm, a sufficiently powerful quantum computer will be capable of breaking the mathematical assumptions that underpin standard key exchange mechanisms. While practical, large-scale quantum computers may still be a few years away, the threat is active today. Malicious actors are currently engaging in "Harvest Now, Decrypt Later" (HNDL) attacks—intercepting and storing encrypted corporate traffic now, with the intention of decrypting it once quantum capabilities become available. For enterprises managing long-lived data, intellectual property, or critical infrastructure, implementing post-quantum cryptography (PQC) is no longer a future roadmap item; it is an immediate operational imperative.

Architecting the Solution: NetBird and Rosenpass

To mitigate this systemic risk, forward-thinking organizations are turning to decentralized, zero-trust architecture. This blog post explores how to establish a highly resilient, post-quantum secure Peer-to-Peer (P2P) overlay network by integrating two cutting-edge technologies: NetBird and Rosenpass.

What is NetBird?

NetBird is an open-source private network platform built on top of the high-performance WireGuard® protocol. Unlike traditional hub-and-spoke VPNs that route all traffic through a centralized gateway, NetBird automatically establishes direct, encrypted P2P connections between machines (peers). It simplifies network management through a centralized control plane while ensuring that the data plane remains completely decentralized, resulting in ultra-low latency, high throughput, and zero-trust access control.

What is Rosenpass?

While WireGuard is renowned for its speed and modern cryptography, its default handshake is not quantum-resistant. This is where Rosenpass enters the architecture. Rosenpass is a specialized security protocol designed to protect VPN traffic against quantum computer attacks. It utilizes the Classic McEliece key encapsulation mechanism (KEM)—a post-quantum cryptographic algorithm selected by NIST for its exceptional security track record—to securely exchange symmetric keys. Rosenpass integrates seamlessly with WireGuard, continuously supplying it with post-quantum pre-shared keys (PQ-PSK) to hybridize and fortify the connection.

Technical Architecture and Workflow

When combined, NetBird and Rosenpass create a dual-layered, defense-in-depth security model. The integration operates through a well-defined sequence of cryptographic mechanisms:

  1. Overlay Establishment: NetBird's management service orchestrates the topology, helping peers discover each other and traverse Network Address Translators (NATs) via STUN/TURN servers.
  2. The Classical Layer: The peers establish a standard WireGuard tunnel, providing immediate authenticated encryption for the data packets.
  3. The Quantum-Resistant Layer: Simultaneously, the Rosenpass daemon runs alongside NetBird. It executes a post-quantum handshake using Classic McEliece to derive a secure symmetric key.
  4. Key Injection: Rosenpass injects this quantum-resistant key into the running WireGuard interface as a Pre-Shared Key (PSK). WireGuard mathematically combines its classical keys with this PQ-PSK.
Even if a future quantum computer breaks the classical WireGuard key exchange, the data remains entirely encrypted and secure because the attacker cannot break the Classic McEliece-protected PSK. This hybrid approach guarantees the best of both worlds: the proven speed of WireGuard and the future-proof security of Rosenpass.

Step-by-Step Deployment Guide

Setting up a secure post-quantum overlay network involves preparing your environment, installing the required binaries, generating cryptographic keys, and configuring the daemons to communicate in harmony.

Prerequisites

Ensure you have the following components ready before starting the deployment:

  • At least two Linux nodes (e.g., Ubuntu 24.04 LTS or Debian 12) with root or sudo access.
  • A running NetBird account (either the hosted NetBird Cloud or a self-hosted NetBird management console).
  • Network connectivity allowing UDP traffic on designated WireGuard and Rosenpass ports.

Step 1: Installing NetBird and Registering Peers

First, install the NetBird client on all target nodes. Run the following command in your terminal:

curl -fsSL [https://pkgs.netbird.io/install.sh](https://pkgs.netbird.io/install.sh) | sh

Once installed, authenticate each node with your NetBird management plane by executing the setup command and following the on-screen prompts:

netbird up

Verify that the nodes are connected and have been assigned private IP addresses within your NetBird overlay network (typically in the 10.10.0.0/16 range).

Step 2: Installing and Compiling Rosenpass

As of recent distributions, Rosenpass can be installed via package managers or compiled from source via Rust's package manager, Cargo. To ensure you have the latest post-quantum optimizations, we recommend installing via Cargo:

sudo apt update && sudo apt install -y build-essential cmake cargo libsodium-dev
cargo install rosenpass

Ensure the rosenpass binary is available in your system's PATH variables.

Step 3: Generating Rosenpass Key Pairs

Each peer in the network requires a unique post-quantum key pair. Generate these keys on each respective node using the following command structure:

mkdir -p /etc/rosenpass
rosenpass genkeypair /etc/rosenpass/pq_secret.key /etc/rosenpass/pq_public.key

Secure the private key file by restricting its read permissions to the root user only:

chmod 600 /etc/rosenpass/pq_secret.key

Step 4: Configuring the Cross-Peer Rosenpass Daemon

To allow Rosenpass to inject keys into NetBird's WireGuard interfaces, you must create a configuration file on each node (e.g., /etc/rosenpass/config.toml). You will need to explicitly map the NetBird interface name (usually wt0) and match the public keys of the remote peers.

An example configuration for Node A communicating with Node B looks like this:

[public]
public_key = "/etc/rosenpass/pq_public.key"

[secret]
secret_key = "/etc/rosenpass/pq_secret.key"

[[peer]]
public_key = "/etc/rosenpass/node_b_public.key"
endpoint = "node_b_netbird_ip:9999"
wireguard_interface = "wt0"

Repeat this configuration conversely on Node B, referencing Node A's public key and NetBird IP address. Start the Rosenpass daemon on both hosts to initiate the post-quantum key exchange.

Enterprise Benefits and Business Impact

Deploying this architecture yields immediate strategic advantages for enterprise risk management:

  • Compliance and Regulatory Alignment: Major regulatory bodies worldwide, including the US National Security Agency (NSA) and European cybersecurity agencies, are mandating transitions to post-quantum standards (e.g., CNSA 2.0). Implementing this stack positions your company ahead of strict regulatory curves.
  • Elimination of Single Points of Failure: NetBird's P2P topology removes the bottleneck and vulnerability of traditional centralized VPN hubs, distributing the traffic dynamically across optimized paths.
  • Zero Performance Degradation: Because Rosenpass handles key exchanges asynchronously and updates WireGuard via the PSK out-of-band, the data plane retains WireGuard's near-native line-rate speeds.

Conclusion

Securing corporate data against the threats of tomorrow requires decisive action today. By layering the post-quantum capabilities of the Rosenpass protocol onto NetBird's seamless, zero-trust P2P overlay network, organizations can achieve an unparalleled level of data protection. This combination guarantees that your infrastructure remains resilient not only against contemporary network threats but also against the impending quantum computing revolution.