Cloudflare plans to issue quantum-safe TLS certificates
The move will be part of a major overhaul of the ecosystem for website authentication.
Cloudflare announced on Tuesday its intention to provide quantum-resistant TLS certificates, positioning itself as one of the pioneers in issuing such certificates. These certificates utilize a cryptographic method considered impervious to attacks from quantum computers. The company will employ an open-source system that generates both traditional TLS certificates and their post-quantum counterparts called Merkle Tree Certificates.
Both types of certificates will be provided free of charge to users, both those with paid subscriptions and those who are not. To develop this extensive system and ensure its widespread adoption across the extensive TLS ecosystem, Cloudflare intends to acquire an already trusted certificate root from CA GlobalSign. This move will allow millions of websites to switch to post-quantum certificates instantly, without any decrease in performance.
The changes Cloudflare is proposing are part of a comprehensive overhaul of the web public key infrastructure (WebPKI) necessary to ensure website encryption and authentication remain secure in the era of post-quantum technology. A significant hurdle in this transformation is the use of quantum-proof signatures that can be seamlessly transmitted during web requests and documented in transparency logs to prevent counterfeit certificates from being granted to websites.
Implementing this change will be a lengthy process, requiring input from numerous engineers who specialize in operating systems, browsers, certificate authorities, and internet infrastructure.
Written by urgent.news from Ars Technica's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.