AI NewsInfrastructureAnnouncement

Cloudflare will become a certificate authority and issue quantum-safe website certificates for free from early 2027

Cloudflare said on 30 September it will become a certificate authority and issue a new post-quantum website certificate format called Merkle Tree Certificates, free for every user, starting in the first quarter of 2027.

AI News

Editorial2 min read

LinkedInX
Cloudflare blog card for the post-quantum certificate authority announcement

Image: Cloudflare

Why it mattersA developer running HTTPS today has to plan a certificate swap before quantum computers arrive, and Cloudflare has now committed to a free path that keeps handshake sizes near today's forty kilobytes even when the certificates go post-quantum.

The certificate that proves your website is really yours today could be faked the moment a big enough quantum computer exists. Cloudflare said on 30 September it will become a certificate authority and start issuing a new certificate format designed to hold up in that world, free for every user, from the first quarter of 2027.

The new format is called Merkle Tree Certificates. Cloudflare's Mari Galicer wrote that the new CA will issue both classical certificates and MTCs from the same infrastructure, and that standard MTC issuance will be free "following in Cloudflare tradition of offering the strongest available cryptography for free". The company is targeting inclusion in Chrome's new Quantum-resistant Root Store in early 2027.

Why swapping the algorithm alone would break the web

Ars Technica reports that a straight swap to quantum-safe signatures inside today's X.509 certificate format would add roughly forty times the amount of data required for a TLS handshake, "which takes place each time a browser or other application establishes a new session with a server". Ars quotes Cloudflare saying that the added computation and bandwidth would make the current web unworkable.

Merkle Tree Certificates get around that problem with a different structure. Google announced the approach in February, and Cloudflare says it drops the handshake back down to about forty kilobytes, close to what browsers process today. Instead of a chain of signatures that each grow when made quantum-safe, the CA signs a single "tree head" that can represent millions of certificates, and a browser checks a small proof that the certificate sits inside that tree.

Who has to move by when

The Ars piece cites a United States government post-quantum migration deadline of 2029. Cloudflare's post frames the same date as the target for the broader upgrade to post-quantum cryptography. Cloudflare's Steve Goldsmith wrote that "we are not issuing certificates yet, and it will be a little while before we do", and that the company is "committing to the work in public, sharing the milestones as they land". To build the trusted root without waiting years for browser approval, Cloudflare is acquiring an already trusted root from CA GlobalSign, per Ars.

There is also a second change baked into the design. In the current web, certificate transparency logs run alongside issuance, and a rogue CA can in theory skip the log. Under MTCs, "by coupling issuance and logging, transparency becomes a requirement for operation, rather than an add-on", Galicer wrote. That closes the gap that let Netherlands-based DigiNotar mint 500 counterfeit certificates for Google and others in 2011, some of which were used to spy on people in Iran.

Every server you run and every browser that talks to it has to agree on the same certificate format before an MTC handshake works. The certificate authority you use, the ACME renewal you run every ninety days, and the trust roots your operating system ships all have to line up first. Cloudflare pledging the free CA is one end of that chain moving; browsers, root stores and client libraries are separate work that is still under way.

Source

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

Share
LinkedInX