Cloudflare has announced its intention to become a public Certificate Authority (CA), marking a significant expansion of its role in web encryption. This move builds on its existing Universal SSL service, which has provided free TLS to websites for over a decade. The company has applied for inclusion in major root programs, including those operated by Chrome, Apple, Microsoft, and Mozilla.
A key aspect of Cloudflare's new CA initiative is its focus on post-quantum cryptography. The company plans to be one of the first CAs to issue post-quantum certificates, specifically Merkle Tree Certificates (MTCs). This development is in response to the anticipated threat from quantum computers, which are expected to compromise current cryptographic standards by 2029.
The transition to post-quantum cryptography presents performance challenges at internet scale. Merkle Tree Certificates have emerged as a solution to efficiently scale post-quantum signatures without unacceptable performance degradation, allowing transparency to be a first-party property of the Web Public Key Infrastructure (Web PKI).
Cloudflare is targeting early 2027 for the inclusion of its Merkle Tree Certificates in Chrome's Quantum-resistant Root Store. This timeline aligns with the broader industry effort to upgrade to post-quantum cryptography. The company has also signed an agreement to acquire an established root from GlobalSign, which will enable it to offer certificates with wide device compatibility from the outset.
The Web PKI is a complex ecosystem that ensures users connect to legitimate websites. Cloudflare's entry as a public CA, combined with its focus on post-quantum certificates, aims to enhance the security and trustworthiness of web connections in the face of evolving threats. By integrating post-quantum solutions, the initiative seeks to future-proof web authentication against quantum computing capabilities.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Cloudflare plans to issue quantum-proof TLS certificates, using a hybrid approach that combines classic and post-quantum cryptography. This initiative aims to prepare the web's encryption infrastructure for potential threats from quantum computers, addressing the challenge of integrating new cryptographic methods without impacting performance.
Cloudflare announced it will launch a new certificate authority (CA) that supports Merkle Tree Certificates (MTCs), targeting early 2027 for inclusion in Chrome's Quantum-resistant Root Store. This initiative provides a path for post-quantum cryptography upgrades for web authentication, addressing performance challenges associated with quantum-resistant signatures at internet scale.
Cloudflare announced its intention to become a public Certificate Authority (CA) and has applied for inclusion in major root programs. This move aims to expand its role in web encryption, building on its existing Universal SSL service.