deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

Cloudflare applies to become a public certificate authority for post-quantum TLS

Cloudflare has applied to the Chrome, Apple, Microsoft and Mozilla root programs and plans to issue classical and post-quantum Merkle Tree Certificates, with production MTCs targeted for early 2027.

Cloudflare applies to become a public certificate authority for post-quantum TLS

Cloudflare has announced it is applying to become a public certificate authority — an organisation browsers trust to sign the TLS certificates that prove a website's identity. According to a dev.to report on the 29 September 2026 announcement, the company plans to run two certificate families from a single system: classical TLS certificates and post-quantum Merkle Tree Certificates (MTCs).

Applying to the root programs

Cloudflare has filed for inclusion in the Chrome, Apple, Microsoft and Mozilla root programs, and has signed a definitive agreement to acquire an established, publicly trusted root from GlobalSign. The dev.to report explains the reasoning behind this two-path structure: a brand-new root takes years to reach the installed base and never reaches devices that no longer receive updates, whereas the GlobalSign root has been trusted across browsers, operating systems and devices since 2012 and covers that long tail. A separate new root, submitted alongside the acquisition, is aimed at where the ecosystem is heading, including root programs that are beginning to cap how old a trusted root may be.

Cloudflare is explicit that it is not issuing certificates yet. Classical issuance begins only after the root programs accept the application.

Why authentication lagged key exchange

Post-quantum key exchange reached browsers first because recorded traffic carries a harvest-now, decrypt-later risk, while a certificate only has to resist forgery for as long as it is valid. That distinction, drawn by Futurum Research in its analysis of the announcement, explains why hybrid key exchange shipped ahead of any change on the authentication side.

Signatures are the harder problem for a blunt reason: by Cloudflare's figures, post-quantum signatures are roughly 40 times larger than the classical ones they would replace, inflating every handshake and every certificate transparency store by the same factor. Cloudflare's own position is that a drop-in swap costs noticeable performance today and delivers no security benefit until a cryptographically relevant quantum computer exists. Futurum Research argues that PKI is the most difficult and highest-stakes piece of any post-quantum programme, because a post-quantum connection is only as trustworthy as the chain of trust behind it.

Merkle Tree Certificates replace signatures with proofs

MTCs are a draft IETF specification co-authored by Cloudflare that moves where the trust anchor lives. Instead of signing each certificate and logging it afterwards, the authority maintains a transparency log backed by a Merkle tree and signs the tree head — a checkpoint attesting that it issued every entry up to that point. A certificate then proves inclusion, carrying a hash path from its leaf to the tree head, rather than proving anything by signature.

Certificates can be served in two forms. In standalone form, the signature value contains a cosigned tree head and an inclusion proof. In landmark-relative form, the client obtains cosigned tree heads out of band, for example through a browser update, so the certificate carries only a lightweight proof with no heavyweight post-quantum signatures at all. Cloudflare tested the mechanism with Chrome Security before announcing, and Chrome has named MTCs its preferred path for post-quantum authentication.

Commitments and timeline

The operating commitments attached to the application are unusually specific for a certificate authority. Cloudflare will issue only to clients that support ACME Renewal Information, standardised in RFC 9773, making automated renewal a condition of issuance. It has also committed to publishing reproducible builds of its signing software, attesting the hardware security modules that hold its keys, and running a public dashboard for issuance health, with a stated design goal of limiting the blast radius of any single incident.

On timing, the GlobalSign acquisition is expected to close within two months, subject to customary conditions. Classical issuance follows root program acceptance, and production MTC issuance is targeted for the first quarter of 2027 inside Chrome's quantum-resistant root store, with certificates issued through ACME at no charge. Let's Encrypt is pursuing free MTCs on a similar schedule, giving the ecosystem more than one route to the same architecture.

Policy pressure runs in parallel. Executive Order 14412 directs US federal agencies to adopt post-quantum key establishment by the end of 2030 and post-quantum signatures by the end of 2031, with contractor requirements to follow, and Google has pulled its own internal migration target into 2029. Cloudflare describes the overall transition as one that will span decades, with classical and post-quantum certificates running side by side well past 2027.

Why it matters

Cloudflare has been one of the largest consumers of publicly trusted certificates on the internet for more than a decade; this move turns issuance into infrastructure it operates itself. The real schedule, however, belongs to the browser root programs, and nothing in Cloudflare's sequence — acquisition close, root inclusion, MTC production — is fully within its control. For operations teams, the practical preparation is design work rather than emergency work: automated renewal, a certificate inventory that records which endpoint holds which chain and when it expires, and a signature algorithm treated as configuration that can change on a schedule.

  • #cloudflare
  • #tls
  • #post-quantum
  • #certificates
  • #pki
  • #cloud

Related posts