Home » Tech Value Chain » Global Brands » Cloudflare Plans Public Certificate Authority
News Desk -

Share

Cloudflare has announced plans to become a public Certificate Authority (CA), an open service that issues the digital certificates websites need to encrypt traffic and prove their identity to visitors.

The public Certificate Authority will support both traditional encryption and next generation post quantum Merkle Tree Certificates (MTCs). This will give websites a path to stay protected as computing power advances, without requiring new tools or infrastructure changes.

Every secure website relies on a Certificate Authority to verify its identity and enable encrypted connections. However, this trust is currently concentrated among a small number of dominant issuers. This creates systemic risk if one of them is compromised or experiences an outage.

At the same time, much of today’s certificate infrastructure was developed before quantum computing became a security concern. Quantum computers capable of breaking current encryption are expected within years, while much of the web remains unprepared for that shift.

“Twelve years ago, Cloudflare made encryption free and automatic for millions of websites. Today, we’re taking the next step by building an open, transparent and reliable Certificate Authority for the entire Internet,” said Matthew Prince, CEO and co-founder of Cloudflare.

He added that upgrading web security before quantum computers can break current encryption is a major coordination challenge. Cloudflare aims to support older devices while introducing post quantum technology, helping maintain security across different types of devices.

To ensure its certificates work on older smartphones, operating systems, and devices that no longer receive software updates, Cloudflare plans to acquire an established root certificate.

A root certificate tells browsers and devices whether they should trust a Certificate Authority. Acquiring an established root means websites using Cloudflare issued certificates can be recognized on legacy hardware.

Cloudflare has also applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs. The applications follow the public processes established by each program.

Together, the acquired root and pending root program applications are intended to provide broad recognition for Cloudflare issued certificates across the web.

Building on an earlier experiment with Chrome, Cloudflare will also begin issuing production MTCs. These certificates are designed around built in transparency and aim to support post quantum security without compromising web speed or performance.

The public Certificate Authority will add an independent, high scale issuer to the existing certificate ecosystem.

Cloudflare first launched Universal SSL in 2014. The service offered free TLS certificates to millions of websites and increased the amount of encrypted traffic on the web. Today, automated and free certificates are widely used across the encrypted web.

Cloudflare says its new CA will redesign public certificate issuance for modern scale and speed. The planned service will include several features.

Glass Box Operational Transparency: Cloudflare plans to share detailed operational and technical information, publish reproducible code builds, and maintain a live public health dashboard. This will allow the wider Internet community to inspect its operations.

Zero Downtime Incident Response: Using automated renewal signalling under RFC 9773, Cloudflare will be able to trigger background certificate replacements across millions of websites. The company says this could help minimize the risk of widespread web outages during certificate revocations or security updates.

Scalable Post Quantum Security: MTCs, co authored by Cloudflare as an IETF draft specification, verify that a certificate has been logged in a trusted registry through lightweight proofs. This avoids transmitting large post quantum signatures with every connection.

Frictionless Web Migration: Site owners will be able to manage traditional TLS certificates and next generation MTCs through a single system. This is intended to support a gradual transition to post quantum security without requiring immediate cutovers.

Cloudflare will begin issuing classical certificates after completing the browser root program application and acceptance process. Production MTC issuance is scheduled to begin in the first quarter of 2027.

Site owners and developers can follow Cloudflare’s engineering updates and sign up for early access notifications through the company’s blog.

The planned public Certificate Authority is intended to provide websites with access to traditional and post quantum certificate technologies through a single system as Cloudflare prepares for the security requirements of the coming era of quantum computing.