Decoding the world of cybersecurity

·

Cloudflare plans public certificate authority

Cloudflare has applied to major browser and operating-system trust programmes as it prepares to issue publicly trusted certificates and build post-quantum capability into its planned certificate authority.

Cloudflare plans public certificate authority
Summary
  • Cloudflare intends to become a public certificate authority and has applied to major root programmes.
  • It has agreed to acquire an established GlobalSign root to improve compatibility with older devices.
  • The company plans to issue Merkle Tree Certificates as part of a future post-quantum trust model.

Cloudflare is preparing to become a public certificate authority, moving deeper into the trust infrastructure underpinning encrypted web connections while also planning support for a new generation of post-quantum certificates.

The company says it has applied for inclusion in the root programmes operated by Chrome, Apple, Microsoft, and Mozilla. It has also signed an agreement to acquire an established and broadly trusted certificate root from GlobalSign, giving the planned service a path to compatibility with devices that may never receive a newly created root certificate through software updates.

Cloudflare is not yet issuing public certificates. The trust-store applications, root acquisition, operational controls, audits, and broader Web Public Key Infrastructure requirements still have to be completed before the service can function as a conventional publicly trusted certificate authority.

The company intends to make issuance Automated Certificate Management Environment, or ACME, first. ACME is the open protocol that underpins automated certificate issuance and renewal at services including Let’s Encrypt. Cloudflare argues that following the same model should reduce the engineering work required for organisations to switch between certificate providers.

The move would place Cloudflare on both sides of a relationship in which it has historically been a very large certificate consumer. Its network terminates enormous volumes of encrypted traffic for customers, while the certificates used to establish trust have generally been supplied by third-party authorities. Running a public CA would bring part of that dependency inside Cloudflare’s own infrastructure.

The company presents additional CA capacity as a resilience measure for the wider web. Let’s Encrypt currently dominates free, automated certificate issuance, and Cloudflare argues that another operator with significant automation and infrastructure could provide useful redundancy if a major authority suffered an operational failure or had to revoke large numbers of certificates.

That argument also creates a concentration question. Certificate authorities are not ordinary cloud services: errors can affect browser trust at enormous scale, and compromise of an issuing system can undermine assumptions used to authenticate websites. Root programmes consequently impose extensive technical and governance requirements before an authority becomes broadly trusted.

Cloudflare’s longer-term plan adds post-quantum cryptography to that responsibility. The company says it intends to issue production Merkle Tree Certificates, targeting the first quarter of 2027. The design seeks to avoid some of the size and performance penalties associated with replacing today’s digital signatures with much larger post-quantum signatures.

The project therefore sits at the intersection of two infrastructure transitions. Automated certificate management has made encrypted web traffic routine, while the eventual threat from cryptographically relevant quantum computers is forcing operators to reconsider the algorithms that authenticate those encrypted connections.

Cloudflare still has to earn trust-store acceptance and complete the operational work needed to run a public CA. If it succeeds, however, the company will move from consuming certificates at Internet scale to operating one of the systems that determines which certificates browsers and devices are prepared to trust.

×