US Techs Register

America's Tech, Logged

Breaking News
Job Shifts

Cloudflare Launches Public CA for Quantum-Safe TLS Certificates

By Beatrice Holloway October 5, 2026
Cloudflare Launches Public CA for Quantum-Safe TLS Certificates - quantum-safe tls certificates
Current internet authentication relies heavily on classical asymmetric algorithms like RSA and elliptic-curve cryptography.

Cloudflare has announced plans to launch a free public Certificate Authority that will issue quantum-safe Transport Layer Security certificates. The initiative addresses a major bottleneck in web infrastructure: the upcoming shift away from classical public key cryptography. While post-quantum key exchange algorithms have entered production, post-quantum authentication across the Web Public Key Infrastructure has lagged due to the large size of quantum-resistant digital signatures. Cloudflare’s solution combines standard X.509 issuance with Merkle Tree Certificates to offer enterprise teams and site operators backwards-compatible, low-latency quantum resistance.

The Challenge of Post-Quantum Cryptography

Current internet authentication relies heavily on classical asymmetric algorithms like RSA and elliptic-curve cryptography. In a post-quantum world, algorithms standardized by the National Institute of Standards and Technology, such as ML-DSA and Falcon, protect against attacks enabled by Shor’s algorithm. However, these post-quantum signatures and public keys require significantly more data than their classical counterparts.

Replacing traditional signature algorithms with post-quantum alternatives in X.509 certificate chains increases cryptographic handshake data by approximately forty times. This causes TCP segmentation issues, triggers packet loss on constrained networks, and adds extra round-trip times during the TLS handshake. Certificate Transparency logs would also face severe operational strain from the larger signatures.

Merkle Tree Certificates: A Scalable Alternative

Cloudflare‘s new public authority adopts Merkle Tree Certificates, an authentication model under development by the IETF PLANTS working group. Instead of signing each server certificate with an individual signature from an intermediate authority, the system batches issuances into an append-only Merkle tree structure.

Within the conventional Web PKI, a CA creates an X.509 certificate and then sends it to an external Certificate Transparency log to receive a Signed Certificate Timestamp. The Merkle Tree Certificate approach merges these two steps. Here, the CA records the certificate by adding a leaf to a Merkle tree, and the resulting credential consists of an inclusion proof that points to a signed tree head.

Because the Certificate Authority signs only the root of the Merkle tree with a post-quantum signature, individual leaf nodes use compact cryptographic hashes. A server presents its leaf entry and an authentication path of intermediate hashes, which scale logarithmically with the tree depth. Clients and browsers can cache synchronized tree head checkpoints, known as landmarks. When a client trusts a recent landmark, the server transmits only the truncated inclusion proof between its leaf and that landmark, reducing handshake payloads to match legacy elliptic-curve connections.

Hybrid Implementation and Rollout Plans

Cloudflare deploys a dual-certificate scheme. Each edge node is provisioned with a conventional X.509 certificate together with a Merkle Tree Certificate. When a TLS handshake occurs, browsers that advertise Merkle Tree Certificate support are given the succinct tree proof, whereas older clients automatically revert to the regular X.509 chain.

After real-world testing alongside the Google Chrome engineering group, Cloudflare verified that the design kept handshake times low and still offered complete, auditable transparency. Mari Galicer, the Cloudflare spokesperson for the project, stressed that requiring logging as a fundamental part of issuance stops any certificates from being issued without oversight.

Enterprise groups moving to post-quantum TLS must weigh considerable design compromises. The use of Merkle Tree Certificates changes the mechanics of revocation and the definition of validity periods. Because the Merkle tree’s root is refreshed on an ongoing basis, each leaf certificate is limited to a brief validity span, which matches the industry push for shorter lifetimes and automated renewal systems like ACME.

Leave a Reply

Your email address will not be published. Required fields are marked *

© 2026 US Techs Register. All rights reserved.