Cloudflare Announces Public Certificate Authority for the Post-Quantum Web
Automated certificates for everyone, built for today, and hardened for the era of quantum computing.
Cloudflare intends to launch its own public certificate authority that will provide post-quantum certificates as encryption-resistant measures against the potential threat of quantum computers. The company will issue Merkle Tree Certificates, a post-quantum format designed to tackle the issue of large signatures associated with these certificates.
These certificates will operate within the same system as conventional ones, addressing a size problem inherent to post-quantum certificates. Merkle Tree Certificates are lighter, as they require only a lightweight proof for verification, instead of sending large signatures with every connection.
Cloudflare's decision stems from the possibility of quantum computers breaking current encryption within years. Their chief executive, Matthew Prince, emphasized that upgrading web security before that becomes a reality is a complex coordination challenge in internet history. The new authority will acquire an established root certificate that older devices already recognize, allowing its certificates to function on legacy hardware immediately.
Cloudflare has also applied for acceptance by root programs operated by Google, Apple, Microsoft, and Mozilla.
The new authority is designed to be transparent, with open code builds and a live public health dashboard for monitoring certificate issuance. Site owners will manage both conventional and post-quantum certificates through this unified system. Once browser root programs accept Cloudflare's applications, conventional certificate issuance will proceed, with production issuance of Merkle Tree Certificates set to begin in the first quarter of 2027.
Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.