CloudNewsSecurity

Cloudflare Launches Public Certificate Authority to Secure the Post-Quantum Web

Cloudflare has announced plans to launch a new, open public Certificate Authority (CA). The initiative is designed to issue automated digital certificates that encrypt web traffic, authenticate website identities, and defend online infrastructure against the emerging cryptographic risks posed by quantum computing. The service will support both industry-standard TLS encryption and next-generation post-quantum Merkle Tree Certificates (MTCs), allowing web administrators to modernize their security posture without requiring infrastructure overhauls or new toolchains.

Mitigating Single-Point Failures in Web Trust
Every secure website relies on CAs to establish cryptographic trust with web browsers and endpoints. However, global web trust remains concentrated across a small cluster of dominant certificate issuers. This centralized ecosystem creates systemic operational risks if any major authority suffers downtime, configuration issues, or a security compromise.

Compounding the problem is the approaching reality of quantum computing, with systems capable of cracking conventional public-key encryption expected within years. Upgrading the global web to quantum-resilient standards requires a massive logistical and technical transition.

“Twelve years ago, Cloudflare made encryption free and automatic for millions of websites. Today, we’re taking the next step by building an open, transparent, and reliable Certificate Authority for the entire Internet,” said Matthew Prince, CEO and co-founder of Cloudflare. “Upgrading the web’s security before quantum computers can break it is one of the biggest coordination challenges in the history of the Internet. By balancing support for older devices with brand-new, post-quantum tech, we’re providing a permanent safety net, so the Internet stays fast, reliable, and secure for all devices, no matter what comes next.”

Legacy Compatibility Meets Next-Gen Cryptography
To maintain backward compatibility with older operating systems, legacy smartphones, and end-of-life hardware, Cloudflare plans to acquire an established root certificate. This gives Cloudflare-issued certificates immediate recognition across older devices without relying on delayed platform patches.

Simultaneously, Cloudflare has submitted applications to join the major browser root programs managed by Google Chrome, Apple, Microsoft, and Mozilla. Building on technical trials conducted alongside Google Chrome, Cloudflare will also offer production-grade Merkle Tree Certificates (MTCs). This setup delivers built-in transparency and post-quantum protection without degrading web page load times or TLS handshake speeds.

Core Pillars of Cloudflare’s Public CA
Cloudflare is re-architecting traditional CA operations around high-scale automation, transparency, and quantum resilience:

  • Glass-Box Operational Transparency: Moving away from closed-door, annual static audits, Cloudflare will release reproducible software builds, share deep operational telemetry, and run a live public health dashboard for real-time monitoring by the cybersecurity community.
  • Zero-Downtime Incident Response: Implementing automated renewal signaling under RFC 9773, the system can quietly re-issue and replace certificates across millions of endpoints instantly, preventing mass outages during emergency revocations or security patches.
  • Scalable Post-Quantum Security: Co-authored by Cloudflare as an IETF draft specification, MTCs validate certificates using lightweight cryptographic proofs logged to trusted registries, eliminating the performance penalty of transmitting oversized post-quantum signatures across every TLS handshake.
  • Frictionless Web Migration: Administrators can manage both legacy TLS certificates and forward-looking Merkle Tree Certificates side-by-side within a unified dashboard, avoiding sudden or forced migrations.

Rollout Timeline
Cloudflare will initiate classical certificate issuance upon the formal conclusion of the browser root program approval process. Production issuance for Merkle Tree Certificates is slated to roll out in the first quarter of 2027.

Show More

Chris Fernando

Chris N. Fernando is an experienced media professional with over two decades of journalistic experience. He is the Editor of Arabian Reseller magazine, the authoritative guide to the regional IT industry. Follow him on Twitter (@chris508) and Instagram (@chris2508).

Related Articles

Back to top button