Post-quantum protection comes from the key exchange (ML-KEM hybrid),
not the certificate — that is what defends against “harvest now, decrypt later”.
The certificate stays classical RSA. Active configuration:
Standard build — OpenSSL default provider.