AI News Feed
Market watch
Companies

Cloudflare to Become a Public Certificate Authority With Post-Quantum Certificates

Cloudflare plans to become a certificate authority, issuing post-quantum Merkle Tree Certificates from the same system as standard ones.

The format addresses a size problem. Output from one of the newly standardized post-quantum signature algorithms runs to 2,420 bytes, compared with 64 bytes for the elliptic curve schemes most sites use now, and a typical connection carries several. Cloudflare expects quantum computers capable of breaking today's encryption within years.

Merkle Tree Certificates, which Cloudflare co-authored as an Internet Engineering Task Force draft specification, avoid sending large signatures with every connection. A lightweight proof that the certificate sits in a trusted public log does the verification work. Cloudflare said a joint experiment with Google LLC's Chrome team, announced last October, was successful. Let's Encrypt, the nonprofit issuer, said in June that it expects to issue the format in production in 2027.

Running its own authority breaks with how Cloudflare has handled certificates until now. Its developer documentation names three outside issuers, Let's Encrypt among them, as the authorities signing certificates for Cloudflare's free Universal SSL program. A small group of dominant providers handles most certificate issuance on the web, which Cloudflare called a systemic risk if any one of them fails or is compromised.

Chief Executive Matthew Prince tied the move to Universal SSL, launched in 2014 with free certificates for millions of sites. The company says the program doubled the amount of encrypted traffic on the web overnight. Upgrading the web's security before quantum computers can break it is "one of the biggest coordination challenges in the history of the internet," Prince said.

Older hardware is a practical hurdle. A phone that no longer receives software updates will never add a new root certificate to its trusted list. Cloudflare plans to acquire an established root certificate that older devices already recognize, which the company said would let its certificates work on legacy hardware immediately. The announcement did not name the root or its current owner. Cloudflare has also applied to the root programs run by Chrome, Apple Inc., Microsoft Corp. and Mozilla Corp.

Operations at the new authority are meant to be open to outside inspection. Cloudflare plans to publish reproducible code builds and run a live public health dashboard, where certificate authorities today are mostly checked through periodic audits.

Site owners will manage conventional and post-quantum certificates from one system. RFC 9773, an internet standard for automated renewal signals, will let Cloudflare swap out certificates across millions of sites in the background during a revocation.

Conventional certificate issuance starts once the browser root programs accept Cloudflare's applications. The company did not give a date. Production issuance of Merkle Tree Certificates is scheduled to begin in the first quarter of 2027.