Cloudflare plans to issue quantum-safe TLS certificates

by | Oct 10, 2026 | Technology

Cloudflare plans to issue quantum-safe TLS certificates

Cloudflare said it intends to issue quantum-resistant TLS certificates, positioning itself among the earliest certificate authorities to offer such credentials. The infrastructure provider will employ an open-source platform that generates both conventional TLS certificates and post-quantum variants called Merkle Tree Certificates. Both certificate types will be available free of charge to all users, whether they maintain paid accounts or not.

To accomplish this objective, Cloudflare is acquiring a trusted certificate root from CA GlobalSign, which will facilitate millions of websites to deploy post-quantum certificates with minimal configuration changes and without incurring performance penalties. This initiative forms part of a comprehensive modernization of the web public key infrastructure required to ensure encryption and website authentication remain secure in an era when quantum computers become viable. The undertaking presents substantial technical challenges, as quantum-resistant signatures must be compact enough for practical transmission during web requests and compatible with transparency logs that prevent unauthorized certificate issuance.

A fundamental obstacle lies in the size of quantum-safe certificates. Traditional X.509 certificates with quantum-resistant signatures would require approximately 40 times more data during TLS handshakes, the authentication process occurring each time a browser connects to a server. This expansion would create unsustainable computational and bandwidth demands. In response, Google introduced Merkle Trees as a solution, hierarchical structures using cryptographic methods to verify large datasets using minimal reference information. Testing by Google and Cloudflare has demonstrated that this approach reduces handshake data to approximately 40 kilobytes, comparable to current levels.

The modernized approach replaces the existing chain of quantum-vulnerable signatures with compact Merkle Tree proofs. Certificate authorities would sign a single tree head representing millions of certificates, with browsers handling lightweight proofs verifying certificate location within the structure. Cloudflare’s implementation also incorporates transparency requirements as integral to certificate issuance rather than supplementary procedures, strengthening protection against counterfeit certificates. The company stated it expects to commence certificate issuance in the first quarter of 2027.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI