Cloudflare Plans a Public CA and Post-Quantum Certificates
Cloudflare will become a public CA, acquire a GlobalSign root, and offer free Merkle Tree Certificates, with production issuance aimed at early 2027.
Cloudflare said it will become a public certificate authority and has applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs. It signed a definitive agreement to acquire a GlobalSign root trusted since 2012; Help Net Security adds that the deal is expected to close within two months and that classical issuance begins only after those programs accept the CA. Issuance will be ACME-first, covering conventional certificates and free Merkle Tree Certificates, an IETF PLANTS draft that batches certificates into a Merkle tree for compact post-quantum proofs. Cloudflare targets early 2027 inclusion in Chrome's Quantum-resistant Root Store after an experimental deployment with Chrome, while Help Net Security schedules production MTC issuance for the first quarter of 2027; those dates describe different milestones and do not directly conflict. Cloudflare cites Let's Encrypt's scale of about ten million certificates daily, over 500 million sites, and four billion active certificates, and says it terminates TLS for more than 20% of global Internet requests. Post-quantum signatures are roughly 40 times larger than classical ones and would expand CT log storage about 40x; Cloudflare operates the Nimbus CT log family and is launching Raio static CT logs.
- Cloudflare has applied to the Chrome, Apple, Microsoft, and Mozilla root programs to become a public certificate authority.
- It signed a definitive agreement to acquire a GlobalSign root trusted since 2012; Help Net Security says the deal should close within two months.
- Classical issuance starts only after root-program acceptance, and ACME-first issuance lets sites switch CAs by changing a directory URL.
- The CA will issue conventional certificates and free Merkle Tree Certificates (an IETF PLANTS draft); Cloudflare targets early 2027 Chrome Quantum-resistant Root Store inclusion, while Help Net Security schedules production MTC issuance…
- Cloudflare cites Let's Encrypt issuing about ten million certificates daily, covering over 500 million sites and four billion active certificates.
- Cloudflare says it terminates TLS for traffic spanning over 20% of global Internet requests.
- Post-quantum signatures are roughly 40 times larger than classical ones and would grow CT log storage about 40x; Cloudflare operates Nimbus CT logs and is launching Raio static CT logs.
- Help Net Security says sites can manage classic and MTC certificates without a forced cutover.
Coverage timelineoldest first · each row is one article
- · 19h agoBuilding a post-quantum certificate authority with Merkle Tree Certificates
Cloudflare Blog· 45
Cloudflare becomes a certificate authority offering free Merkle Tree Certificate issuance, targeting Chrome's quantum-resistant root store inclusion in early 2027.
- · 19h agoBuilding a certificate authority for the whole Internet
Cloudflare Blog· 62
Cloudflare will become a public certificate authority, acquiring GlobalSign's trusted root and applying to Chrome, Apple, Microsoft, and Mozilla root programs, with post-quantum certificates planned.
- · 5h agoPost-quantum website certificates from Cloudflare are scheduled for early 2027
Help Net Security· 52