Cloudflare plans to become a public certificate authority (CA), giving website operators another source of the digital certificates used to prove a site’s identity and establish secure connections. It also intends to issue Merkle Tree Certificates (MTCs), designed to make post-quantum authentication practical without slowing web connections.
The company has applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs. Approval would allow their browsers and operating systems to trust its certificates. It also plans to acquire an established root certificate to support older devices. Neither the acquisition nor the root program approvals are complete.
Cloudflare expects to begin issuing conventional certificates after completing the browser root program process. It has scheduled production MTC issuance for the first quarter of 2027.
A CA verifies that a website controls its domain and issues a certificate that browsers can use to authenticate it. Cloudflare currently obtains publicly trusted certificates for its customers through other CAs, including Let’s Encrypt and Google Trust Services. Becoming a public CA would let it issue them directly.
The move extends Cloudflare’s work on two distinct parts of post-quantum web security. Earlier this month, Cloudflare said its automatic key exchange rollout had helped lift post-quantum protected traffic between its network and compatible origin servers to about 45 billion connections a day. Key exchange protects the secrecy of a connection; certificates help a browser establish that it is connecting to the intended site.
Cloudflare has also worked with Google on MTCs, an approach previously covered by SDxCentral. Conventional post-quantum signatures can make certificates and TLS handshakes larger. MTCs group certificates in a Merkle tree, allowing a browser to verify that a certificate is included in a signed, publicly logged batch using a smaller proof. The specification remains an IETF draft.
Cloudflare said its proposed CA would manage conventional certificates and MTCs through one system, allowing sites to adopt the newer format as browser support develops. It also promised public operational data, reproducible code builds, and a live health dashboard. For incidents requiring certificates to be replaced, it plans to use automated renewal signaling to speed the process across large numbers of sites.
The plans add certificate authentication to Cloudflare’s wider post-quantum roadmap. Their reach will depend on the root program decisions, the planned acquisition, and support for MTCs in browsers and other clients.
Comments