Cloudflare applies to issue web certificates as a post-quantum CA

The move would take Cloudflare from relying on outside certificate authorities to seeking a role in the trust infrastructure behind public HTTPS.

By · Published

Primary source: X

Why it matters

Cloudflare already manages a large share of the web’s traffic and relies on partner CAs for publicly trusted certificates. Becoming a CA could extend its control into certificate issuance, while MTCs aim to make post-quantum authentication practical for ordinary HTTPS connections.

A glowing, intricate digital security certificate floats in a vast, abstract blue and purple digital network space.

Cloudflare says it is applying to become a publicly trusted certificate authority, a step that would put the internet infrastructure company on the issuing side of web security certificates it currently obtains through partners. The announcement on X, posted September 29th, ties the application to Merkle Tree Certificates and a post-quantum security plan. Cloudflare did not specify the application process, the root it would use, or when certificates might be available.

For Matthew Prince, Cloudflare’s co-founder and CEO, the move extends the company’s long-running effort to make basic internet security part of its network service. Before Cloudflare, Prince co-created Project Honey Pot, a community effort to track online abuse. Cloudflare began offering free Universal SSL certificates in 2014, the same year that marked the start of its push to make HTTPS easier for website operators.

The proposed change is a meaningful one in the certificate chain. A certificate authority verifies control of a domain and issues a certificate that browsers can trust. Cloudflare currently works with Let’s Encrypt, Google Trust Services, SSL.com and Sectigo for public certificates, according to its SSL/TLS documentation. Its existing Origin CA certificates serve a different purpose: they protect the connection between Cloudflare and a customer’s server, and are not substitutes for publicly trusted certificates used by visitors’ browsers.

Diagram separating Cloudflare’s current partner-issued public certificates, its Origin CA certificates for Cloudflare-to-server connections, and its proposed public CA application.
Cloudflare’s current public certificates come through partner CAs; its Origin CA serves a separate connection, while the proposed public CA remains an application — AI explanatory diagram, not documentary evidence. RuntimeWire · AI-generated diagram.

Cloudflare says its planned CA would combine an established root, certificate issuance automated through ACME, and Merkle Tree Certificates, or MTCs. ACME is the protocol used to automate certificate requests and renewals. MTCs take a different approach to the certificate-signing and transparency process: certificates are recorded in a Merkle tree, and an inclusion proof can show that a certificate is part of that logged set. The design aims to limit the size burden of post-quantum signatures while preserving public accountability for issuance, according to the IETF draft.

Diagram of the proposed Cloudflare CA’s unspecified established root and ACME automation, alongside the MTC process of recording a certificate in a Merkle tree and using an inclusion proof to show it is in the logged set.
Cloudflare describes a proposed CA with ACME-automated requests and renewals, alongside MTC logging and inclusion proofs. MTCs remain in IETF development; the article does not say the CA is approved or browsers accept the format — AI explanatory diagram, not documentary evidence. RuntimeWire · AI-generated diagram.

That overhead is a practical constraint. Post-quantum signature schemes can require substantially larger keys and signatures than the algorithms commonly used today. Simply attaching those larger signatures to every certificate risks adding data to TLS connections and certificate-transparency logs. MTCs are one proposed way to change how certificates are represented and checked; they are still being developed through the IETF, so Cloudflare’s announcement does not mean browsers already accept its proposed certificate format.

Cloudflare’s plans have a longer runway than the application itself. In an April roadmap, the company targeted mid-2027 for post-quantum authentication between website visitors and Cloudflare using MTCs, and 2029 for full post-quantum security across its product suite. The company has also described early experiments with Google and other participants; an IETF presentation reported testing MTCs on 1,000 Cloudflare-proxied domains. That is evidence of technical testing, not evidence that the proposed CA has been approved or that MTC certificates are generally available.

The business logic is straightforward: operating a CA could give Cloudflare more control over certificate issuance in its own network and align public HTTPS certificates with its post-quantum work. It would also place the company alongside established providers that currently supply its certificates. Cloudflare’s announcement frames the application as part of an open-web effort, but the operational test will be whether browsers and the wider certificate ecosystem accept the approach. An established root may help bridge that gap; the post itself does not identify which root or explain the application’s status.

For website operators, there is no announced product to adopt yet. Cloudflare’s certificate authority documentation continues to describe its current partner CAs. The proposal is therefore a bid to expand Cloudflare’s role in the web’s trust system, with deployment dependent on approval and compatibility beyond Cloudflare’s own network.

Reader comments

Conversation for this story loads after sign-in.