announcement-check

Cloudflare's Quantum-Safe Certificates Hinge on Buying a Trusted Root, Not Building One

Cloudflare will issue free quantum-resistant TLS certificates by acquiring an already-trusted certificate root from GlobalSign, letting it skip the years-long process of getting a new root into browser trust stores.

Cloudflare said Tuesday it will begin issuing quantum-resistant TLS certificates, positioning itself as one of the first certificate authorities to offer signatures designed to survive attacks from a future quantum computer. The announcement is less a product launch than a bid to rewrite a piece of internet infrastructure that has run on the same trust model for two decades.

The mechanism matters as much as the marketing. Cloudflare plans to issue hybrid certificates through an open source platform that produces both a conventional TLS certificate and a post-quantum companion called a Merkle Tree Certificate. Both will be offered free to paying and non-paying customers alike, according to the company, which frames the certificates as something websites can turn on "at the flip of a switch" without new performance overhead.

To make that switch flip for millions of sites at once, Cloudflare is acquiring an already trusted certificate root from GlobalSign, an established certificate authority. That acquisition is the part of the announcement worth watching closely: buying a pre-trusted root lets Cloudflare skip the years-long process new certificate authorities normally face to get their roots accepted by every major browser and operating system, since GlobalSign's root is already embedded in trust stores worldwide. In effect, Cloudflare is purchasing standing in the WebPKI rather than building it from scratch.

That shortcut is what turns a cryptography upgrade into an infrastructure transfer. Trust stores, the lists of root certificates that browsers and operating systems treat as authoritative, are the actual gatekeepers of the certificate authority business, and inheriting a seat in them through acquisition sidesteps the vetting that bodies like the CA/Browser Forum apply to new entrants. Cloudflare is not asking permission to become a root of trust for post-quantum signatures. It is buying the permission that already exists.

The harder problem sits downstream of the certificates themselves. Quantum-safe signatures need to be compact enough to transmit during ordinary web handshakes and verifiable enough to be logged in certificate transparency systems, the public ledgers that let anyone check whether a certificate was issued for a domain without the domain owner's knowledge. Merkle Tree Certificates are built to satisfy both constraints, but making them work end to end requires coordinated changes across browser vendors, operating system makers, and the certificate authorities that compete with Cloudflare, none of whom are bound by Tuesday's announcement.

That dependency is why Cloudflare itself describes the broader transition as a multi-year undertaking rather than a rollout. A single company, even one that touches as much web traffic as Cloudflare does, cannot unilaterally migrate the WebPKI. What it can do is put a free, working implementation in front of engineers at Google, Apple, Microsoft, and Mozilla and make its own certificate root the vehicle for testing it at scale, effectively setting the pace at which the rest of the ecosystem has to respond.

stagirus