October 5, 2026

The Queens County Citizen

Complete Canadian News World

Cloudflare Plans Free Public Certificate Authority for Quantum-Safe TLS

Cloudflare is preparing to launch a free public Certificate Authority (CA) designed to issue quantum-safe Transport Layer Security certificates, as the technology industry works to protect internet infrastructure against future quantum-computing threats. The initiative is intended to address a major challenge in moving the public web away from traditional cryptographic systems while maintaining compatibility and acceptable connection speeds.

Cloudflare Targets Post-Quantum Web Security

Much of today’s internet authentication infrastructure relies on classical asymmetric cryptography, including RSA and elliptic-curve cryptography. These technologies underpin TLS certificates used to verify websites and establish encrypted connections.

The emergence of sufficiently powerful quantum computers could eventually undermine these systems. Post-quantum algorithms standardized by the U.S. National Institute of Standards and Technology, including ML-DSA and Falcon, are designed to withstand attacks based on quantum techniques such as Shor’s algorithm.

However, deploying these algorithms for website authentication presents a practical challenge: post-quantum signatures and public keys are substantially larger than their classical equivalents.

Replacing conventional signatures directly within existing X.509 certificate chains could increase cryptographic handshake data by roughly 40 times. Larger certificate chains can create additional TCP segmentation, increase the impact of packet loss on constrained networks and require extra round trips during the TLS handshake.

Certificate Transparency systems, which maintain public records of certificates issued by trusted authorities, could also face significant additional data requirements.

Merkle Tree Certificates Aim to Reduce TLS Overhead

Cloudflare plans to address the problem by combining conventional X.509 certificates with emerging Merkle Tree Certificates, or MTCs.

The technology is being developed through work within the Internet Engineering Task Force ecosystem and takes a different approach to certificate authentication.

Instead of requiring an intermediate Certificate Authority to individually sign every server certificate with a comparatively large post-quantum signature, certificate issuances can be grouped into an append-only Merkle tree.

Certificate Issuance and Transparency Become Linked

Under the conventional Web Public Key Infrastructure model, a Certificate Authority creates an X.509 certificate and submits it to third-party Certificate Transparency logs, which provide Signed Certificate Timestamps.

Merkle Tree Certificates combine these processes more closely. A certificate entry is inserted into the tree, while the certificate contains an inclusion proof linked to a signed tree head.

The Certificate Authority needs to apply the larger post-quantum signature only to the Merkle tree root. Individual entries can then be authenticated using much smaller cryptographic hashes.

Servers therefore do not need to transmit several large post-quantum signatures during each connection. Instead, they can provide the certificate entry and a cryptographic authentication path proving its inclusion in the tree.

Clients and browsers can also cache trusted tree checkpoints, known as landmarks. If a client already possesses a recent trusted landmark, the server can send only the portion of the inclusion proof required to connect its certificate to that checkpoint.

The approach is intended to keep TLS handshake sizes closer to those associated with existing elliptic-curve-based connections.

Hybrid Certificates Maintain Compatibility With Older Clients

Cloudflare’s planned implementation uses a hybrid model in which endpoints receive both a conventional X.509 certificate and a corresponding Merkle Tree Certificate.

During TLS negotiation, newer clients that support MTC authentication can receive the compact tree-based proof. Older browsers and applications can continue using the traditional X.509 certificate chain.

This backwards-compatible approach could be important during the lengthy transition to post-quantum cryptography, particularly for organizations operating a mix of newer and legacy devices.

Cloudflare said production experiments conducted with Google’s Chrome engineering team demonstrated that the architecture could maintain low TLS handshake latency while retaining auditable certificate transparency.

Mari Galicer, who detailed the project for Cloudflare, also highlighted the security implications of making transparency logging an integral part of certificate issuance. The architecture is designed so certificates cannot be issued without being incorporated into the transparency structure.

Enterprises Face Changes to Certificate Management

For Canadian companies and other organizations operating public-facing digital infrastructure, adopting post-quantum TLS could require changes beyond simply replacing existing certificates.

Merkle Tree Certificates affect areas including certificate validity and revocation. Because tree heads are updated continuously, certificates are associated with shorter validity periods.

That model aligns with the broader industry’s movement toward shorter certificate lifespans and automated certificate management. Technologies such as the Automatic Certificate Management Environment, or ACME, are increasingly important for handling issuance and renewal without manual intervention.

Organizations may therefore need to review certificate automation systems, cryptographic libraries, network appliances and internal infrastructure to ensure they can support hybrid authentication.

Public Issuance Targeted for Early 2027

Cloudflare plans to make standard certificate issuance available free of charge to web properties, with broad public availability targeted for early 2027 as the necessary root-store inclusions move forward.

The transition will also depend on browser and operating-system support. Projects such as Chrome’s quantum-resistant root-store efforts are intended to prepare client ecosystems for certificates based on post-quantum cryptography.

For infrastructure teams, the coming transition means assessing automated certificate managers, verifying cryptographic library compatibility and preparing edge networks for hybrid certificate verification.

Cloudflare’s initiative represents another step toward bringing post-quantum protection into everyday web infrastructure. By pairing established X.509 certificates with Merkle Tree Certificates, the company aims to make quantum-resistant website authentication practical without imposing the substantial network overhead associated with conventional post-quantum certificate chains.