deniz.in

Markets

Weather

Loading weather

· via Cloudflare blog

Cloudflare becomes a certificate authority with free post-quantum Merkle Tree Certificates

Cloudflare says it will become a public certificate authority, acquire a GlobalSign root, and issue free Merkle Tree Certificates from early 2027 to ready the web for post-quantum cryptography.

Cloudflare becomes a certificate authority with free post-quantum Merkle Tree Certificates

Cloudflare is becoming a certificate authority

Cloudflare has announced plans to become a publicly trusted certificate authority, ending a stretch of more than a decade in which it consumed certificates at enormous scale without ever issuing one. In a pair of blog posts published September 29, 2026, the company set out its first milestones: applications for inclusion in the Chrome, Apple, Microsoft and Mozilla root programs, and a definitive agreement to acquire an established, broadly trusted root from GlobalSign.

According to Cloudflare, the GlobalSign root has been trusted by browsers, operating systems and devices since 2012, which should give the new CA compatibility with older clients from day one, hardware that a freshly created root would take years to reach, if it ever does. Alongside the acquired root, Cloudflare intends to submit a new root designed for where root programs are heading, including policies that limit how old a trusted root may be. Nothing is being issued yet; the company says it is committing publicly and will report milestones as they land.

A second pillar for free certificates

Part of the rationale is redundancy for the web. Cloudflare points out that the free, automated certificate model now carries most of the encrypted web, and that much of it flows through a single operator, Let's Encrypt, which issues on the order of ten million certificates a day, serves more than 500 million sites and passed four billion active certificates in 2025. A bad week at that one CA would leave the web without a comparable free alternative ready to absorb the load.

The new CA will be built around ACME, the open automation protocol, so subscribers already pointed at another free issuer can switch by changing a directory URL with no new tooling. Cloudflare will only issue to clients that support ACME Renewal Information (RFC 9773), making renewal automation a condition of issuance, a lesson it says it drew from watching CAs caught between timely revocation and keeping unprepared subscribers online. It also promises reproducible builds of its signing software, attestation for the hardware security modules holding its keys, and a public dashboard for issuance health, arguing that point-in-time audits say little about day-to-day operations.

Merkle Tree Certificates for post-quantum TLS

The more ambitious commitment is post-quantum. Cloudflare plans to be among the first CAs to issue Merkle Tree Certificates (MTCs) in production, with the first certificates targeted for the first quarter of 2027 and standard MTC issuance offered at no cost. The company says it is aiming for inclusion in Chrome's newly announced Quantum-resistant Root Program, following a successful experimental MTC deployment with Chrome this year.

The driving problem is size. A typical TLS handshake today involves about five signatures and two public keys, Cloudflare explains, and post-quantum signatures are roughly 40 times larger than classical ones. By the company's estimates, swapping PQ signatures into the current system would also inflate the data certificate transparency logs must store by 40 times, because transparency was bolted onto issuance after the fact rather than designed into it.

MTCs, a draft specification from the IETF PLANTS working group, restructure the model. Certificates are batched into an append-only Merkle tree, and the CA signs the root of that tree instead of signing each certificate individually. A client verifies a certificate using a compact inclusion proof, a sequence of hashes, against the signed tree head. The core idea is that issuance and logging become a single act, making transparency a requirement of operation rather than an optional layer.

Two encodings are planned, both expressible in the X.509 format that existing software already recognizes. Standalone certificates embed a cosigned tree head plus the inclusion proof in the signature value, while landmark-relative certificates carry only the lightweight proof, on the assumption that clients obtain cosigned tree heads out of band and skip heavyweight post-quantum signatures entirely.

Cloudflare already operates the Nimbus family of certificate transparency logs, running since 2016, and is launching Raio, a new family of static CT logs. Its CT monitoring service, introduced in 2019 and recently made generally available, takes on extra weight in a post-quantum world: domain owners who upgrade should watch for unexpectedly issued legacy certificates that could open a path to downgrade attacks.

Why it matters

Cloudflare cites an industry-wide move to post-quantum cryptography by 2029, and the current PKI does not scale to post-quantum signature sizes without painful costs for clients, CAs, logs and monitors. MTCs have gathered broad industry support as the way forward, and a CA issuing them natively and for free could make the upgrade path nearly invisible for a large share of the web. Just as important, a serious second free certificate authority would soften the ecosystem's dependence on a single issuer, insurance the encrypted web has never really had.

  • #cloudflare
  • #pki
  • #post-quantum-cryptography
  • #tls
  • #security

Related posts