Cloudflare plans to issue quantum-safe TLS certificates
Cloudflare said Tuesday it plans to issue quantum-proof TLS certificates, making it one of the first authorities to issue such certificates, which use a form of cryptography that is widely believed to withstand attacks from quantum computers.
The Internet infrastructure provider said it will use an open source platform that issues both classic TLS certificates and a post-quantum equivalent known as Merkle Tree Certificates. The hybrid certificates will be free to both paying and non-paying users. To help build the massive system and establish ubiquity across the sprawling TLS ecosystem, Cloudflare will be acquiring an already trusted certificate root from CA GlobalSign. Cloudflare said the move will let millions of websites use post-quantum certificates at the flip of a switch and without incurring any increased performance overhead. Fundamental architectural changes ahead
Cloudflare’s plans are part of a major overhaul in the web public key infrastructure (WebPKI) required to make website encryption and authentication safe for the coming post-quantum age. A major challenge is using quantum-proof signatures that can be easily transmitted during web requests and recorded in transparency logs to ensure counterfeit certificates aren’t assigned to websites. The makeover will take years to complete, because it requires the work of an untold number of engineers who design operating systems, browsers, certificate authorities, and Internet infrastructure.
“We are not issuing certificates yet, and it will be a little while before we do,” Cloudflare’s Steve Goldsmith wrote. “What we are doing is committing to the work in public, sharing the milestones as they land, and telling you exactly what we are building while working with the root programs and other members of the WebPKI community to achieve this.”
Safeguarding the WebPKI against quantum attacks is a tall order that requires fundamental architectural changes rather than simply swapping algorithms. Quantum-proof versions of today’s classical X.509 certificates would add roughly 40 times the amount of data required for a TLS handshake, which takes place each time a browser or other application establishes a new session with a server. The added computation and bandwidth required to implement such a system would break the Internet as we know it.
In February, Google announced a solution: Merkle Trees. These hierarchical data structures use cryptographic hashes and other math to verify the contents of large amounts of information using a small fraction of their contents. The design, which Google and Cloudflare have been testing in limited pilot programs, drops the amount of handshake data to about 40 kilobytes, about the same as is processed now.
The current WebPKI relies on a multi-link chain of quantum-vulnerable signatures to prove a certificate’s authenticity. Since replacing the signatures with quantum-resistant ones is resource-prohibitive, the chains are replaced with compact Merkle Tree proofs. To complete such a proof, a certificate authority signs only a single “tree head” that can represent millions of certificates. In most cases, the data a browser handles is a “landmark,” a lightweight proof that the certificate is located somewhere in the tree.
Industry-wide rules require that TLS certificates be published in append-only distributed ledgers known as public transparency logs. Website owners check the logs in real time to ensure that no rogue certificates have been issued for the domains they use. The transparency programs were implemented in response to the 2011 hack of Netherlands-based DigiNotar, which allowed the minting of 500 counterfeit certificates for Google and other websites, some of which were used to spy on web users in Iran.
Once viable, Shor’s algorithm could forge classical encryption signatures and the public keys of certificate logs. Ultimately, an attacker could forge signed certificate timestamps used to prove to a browser or operating system that a certificate has been registered when it hasn’t.
Under the current PKI system, updates are handled by adding a new link to the signature chain. Merkle Trees provide proof of a signature chain without explicitly listing each individual link. The design has another major benefit. Under today’s system, transparency logs are a process that’s distinct from certificate issuance. With Merkle Tree Certificates, by contrast, the logging is a core part of the issuance. “By coupling issuance and logging, transparency becomes a requirement for operation, rather than an add-on,” Cloudflare engineer Mari Galicer said.
There are a host of other designs included in Cloudflare’s plan. One is Automated Certificate Management Environment (ACME), an open source mechanism for issuing certificates and continuously renewing them shortly before expiration. The quantum-resistant certificates will also provide a mechanism for signatures to be sent out-of-band—for instance, through a browser update—if a downed server or other technical problem prevents receiving a landmark update. Cloudflare said it expects to start issuing certificates in the first quarter of 2027.
Posted on: 9/30/2026 9:58:22 AM
|