Cloudflare has unveiled its plan to operate as a public Certificate Authority (CA), aiming to bolster web security by providing free and automated digital certificates for websites. This initiative is part of Cloudflare’s broader strategy to ready the internet for advancements in post-quantum cryptography.
Understanding Certificate Authorities
A Certificate Authority (CA) is a trusted entity responsible for issuing digital certificates. These certificates play a crucial role in enabling websites to use HTTPS, ensuring encrypted communication between users and web servers, and confirming the authenticity of domains to prevent impersonation.
While Cloudflare has not yet started issuing certificates, it is in the process of obtaining the necessary approvals to become a trusted CA. The company has submitted applications to the root programs of major browsers and operating systems, including Google Chrome, Apple, Microsoft, and Mozilla.
Strategic Partnerships and Acquisitions
To expedite its CA capabilities, Cloudflare has entered into an agreement to acquire an existing trusted root from GlobalSign. This strategic move is crucial as it can take years for a new root certificate to gain widespread acceptance across browsers and devices.
GlobalSign’s established root is already recognized by many legacy systems, which will help Cloudflare achieve broader compatibility when it commences certificate issuance.
Enhancing Web Security Infrastructure
Cloudflare’s new CA will utilize the Automated Certificate Management Environment (ACME) protocol to automate certificate issuance and renewal processes. This allows website operators using existing automated services to easily switch to Cloudflare by adjusting their ACME directory URL without altering their management workflows.
The introduction of Cloudflare’s CA could enhance resilience within the Web Public Key Infrastructure (PKI) ecosystem. Currently, free certificate issuance is largely dominated by a few providers, like Let’s Encrypt. By offering another high-volume, automated, and free option, Cloudflare aims to diversify the market and mitigate risks associated with potential disruptions at major CAs.
Future-Proofing with Post-Quantum Certificates
Cloudflare is also preparing to issue post-quantum Merkle Tree Certificates (MTCs), aimed at providing efficient authentication as cryptographic standards evolve. The company plans to initiate MTC issuance in the first quarter of 2027, supporting both traditional WebPKI certificates and MTCs from a single CA to streamline the transition to quantum-resistant systems.
To ensure transparency and security, Cloudflare will publish reproducible builds for its certificate-signing software, validate its hardware security modules, and maintain a public dashboard for monitoring issuance health and incidents.
By adopting its own CA internally before broader deployment, Cloudflare adheres to its “Customer Zero” approach, testing services on a large scale. This initiative builds on Cloudflare’s 2014 Universal SSL launch, transitioning from a major consumer of certificates to a direct provider of trust on the internet.
