Cloudflare plans to issue quantum-safe TLS certificates

by | Oct 7, 2026 | Technology

Cloudflare plans to issue quantum-safe TLS certificates

Cloudflare said it intends to become one of the first certificate authorities to issue quantum-resistant TLS certificates, leveraging cryptographic methods designed to withstand attacks from quantum computers. The company will deploy an open source platform capable of issuing both conventional TLS certificates and post-quantum variants known as Merkle Tree Certificates, offering these hybrid certificates at no cost to all users. To facilitate widespread adoption across the TLS ecosystem, Cloudflare plans to acquire a trusted certificate root from CA GlobalSign, enabling millions of websites to adopt post-quantum certificates without requiring significant performance adjustments.

The initiative represents part of a broader transformation of web public key infrastructure necessary to ensure encryption and authentication remain secure in a post-quantum computing environment. A fundamental challenge involves implementing quantum-proof signatures that can be efficiently transmitted during web requests and stored in transparency logs to prevent fraudulent certificate issuance. The transition is expected to require years of coordinated effort from numerous engineers across operating systems, browsers, certificate authorities, and internet infrastructure sectors.

Standard X.509 quantum-resistant certificates would increase TLS handshake data by approximately forty times, creating impractical resource demands. In February, Google introduced a solution using Merkle Trees—hierarchical data structures employing cryptographic hashes to authenticate large volumes of information using minimal overhead. Testing by Google and Cloudflare has demonstrated that this approach reduces handshake data to approximately forty kilobytes, comparable to current levels. The method replaces the existing multi-link signature chains with compact Merkle Tree proofs, where certificate authorities sign a single tree head representing millions of certificates.

Transparency requirements established following the 2011 DigiNotar security breach remain central to Cloudflare’s approach. Merkle Tree Certificates integrate logging directly into the issuance process, making transparency a fundamental operational requirement rather than an supplementary function. The system incorporates Automated Certificate Management Environment technology for certificate issuance and renewal, along with provisions for out-of-band signature delivery via browser updates during technical disruptions. Cloudflare expects to commence certificate issuance in the first quarter of 2027.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI