Cloudflare Vows Quantum-Proof TLS Shift
Cloudflare says it will issue post-quantum TLS certificates using Merkle Tree Certificates, targeting Q1 2027 after acquiring a GlobalSign root.
Every time a browser opens a secure connection, it performs a digital handshake that authenticates the server it is talking to. That handshake rests on signature algorithms that a sufficiently powerful quantum computer running Shor's algorithm could eventually forge. Cloudflare said it plans to issue quantum-proof TLS certificates that use cryptography widely believed to resist attacks from quantum computers, making it one of the first certificate authorities to do so.
The Internet infrastructure provider said it will rely on an open source platform that issues both classic TLS certificates and a post-quantum equivalent known as Merkle Tree Certificates. The hybrid certificates will be free to both paying and non-paying users. To build the system at scale and establish ubiquity across the sprawling TLS ecosystem, Cloudflare will acquire an already trusted certificate root from CA GlobalSign. Cloudflare said the move will let millions of websites use post-quantum certificates at the flip of a switch and without incurring increased performance overhead.
Why the WebPKI needs an overhaul
Cloudflare's plans are part of a major overhaul in the web public key infrastructure (WebPKI) required to make website encryption and authentication safe for the coming post-quantum age. A central challenge is using quantum-proof signatures that can be easily transmitted during web requests and recorded in transparency logs to ensure counterfeit certificates are not assigned to websites. The makeover will take years to complete, because it requires the work of an untold number of engineers who design operating systems, browsers, certificate authorities, and Internet infrastructure.
The company has been explicit that it is not issuing certificates yet. In a written statement, Cloudflare's Steve Goldsmith said the company is making a public commitment rather than shipping a finished product.
"We are not issuing certificates yet, and it will be a little while before we do," Cloudflare's Steve Goldsmith wrote. "What we are doing is committing to the work in public, sharing the milestones as they land, and telling you exactly what we are building while working with the root programs and other members of the WebPKI community to achieve this."
— Steve Goldsmith, Cloudflare
The 40x handshake problem
Safeguarding the WebPKI against quantum attacks is a tall order that requires fundamental architectural changes rather than simply swapping algorithms. Quantum-proof versions of today's classical X.509 certificates would add roughly 40 times the amount of data required for a TLS handshake, which takes place each time a browser or other application establishes a new session with a server. The added computation and bandwidth required to implement such a system would break the Internet as we know it.
That arithmetic is what forced the industry to look beyond direct algorithm replacement. A certificate authority that simply signed larger post-quantum keys would push unacceptable costs onto every connection, from mobile networks to embedded devices that check certificates infrequently and have little room for extra bytes.
Merkle Trees as the compact fix
In February, Google announced a solution: Merkle Trees. These hierarchical data structures use cryptographic hashes and other math to verify the contents of large amounts of information using a small fraction of their contents. The design, which Google and Cloudflare have been testing in limited pilot programs, drops the amount of handshake data to about 40 kilobytes, about the same as is processed now.
The current WebPKI relies on a multi-link chain of quantum-vulnerable signatures to prove a certificate's authenticity. Since replacing the signatures with quantum-resistant ones is resource-prohibitive, the chains are replaced with compact Merkle Tree proofs. To complete such a proof, a certificate authority signs only a single "tree head" that can represent millions of certificates. In most cases, the data a browser handles is a "landmark," a lightweight proof that the certificate is located somewhere in the tree.
When a browser verifies a Merkle Tree Certificate, it is not walking a signature chain that lists every intermediate authority. Instead it confirms that the leaf it received is included in a tree whose head the authority has signed. That inclusion proof is small enough to travel inside a normal TLS handshake, which is what makes the design practical.
Transparency logs move to center stage
Industry-wide rules require that TLS certificates be published in append-only distributed ledgers known as public transparency logs. Website owners check the logs in real time to ensure that no rogue certificates have been issued for the domains they use. The transparency programs were implemented in response to the 2011 hack of Netherlands-based DigiNotar, which allowed the minting of 500 counterfeit certificates for Google and other websites, some of which were used to spy on web users in Iran.
Under the current PKI system, updates are handled by adding a new link to the signature chain. Merkle Trees provide proof of a signature chain without explicitly listing each individual link. The design has another major benefit. Under today's system, transparency logs are a process that's distinct from certificate issuance. With Merkle Tree Certificates, by contrast, the logging is a core part of the issuance.
Cloudflare engineer Mari Galicer described the change this way: "By coupling issuance and logging, transparency becomes a requirement for operation, rather than an add-on," Cloudflare engineer Mari Galicer said.
Once viable, Shor's algorithm could forge classical encryption signatures and the public keys of certificate logs. Ultimately, an attacker could forge signed certificate timestamps used to prove to a browser or operating system that a certificate has been registered when it hasn't.
ACME, out-of-band signatures, and the 2027 target
There are a host of other designs included in Cloudflare's plan. One is Automated Certificate Management Environment (ACME), an open source mechanism for issuing certificates and continuously renewing them shortly before expiration. The quantum-resistant certificates will also provide a mechanism for signatures to be sent out-of-band—for instance, through a browser update—if a downed server or other technical problem prevents receiving a landmark update.
Cloudflare said it expects to start issuing certificates in the first quarter of 2027. The company described the acquisition of a trusted root from GlobalSign as the piece that makes broad deployment possible without asking every site owner to re-provision certificates by hand.
Some of Cloudflare's technical work is already public. The company has said it operates a certificate authority, and its plans reference Merkle Tree Certificates, which are built on hierarchical data structures. Google's February announced a solution serves as the technical ancestor for the approach Cloudflare intends to deploy.
What the plan does and does not promise
Cloudflare's announcement is a public commitment, not a live service. The certificates do not exist yet in production, and the company has said it will share milestones as they land. The effort spans certificate authorities, browsers, operating systems, and Internet infrastructure, and the source material does not put a firm number on how many engineers or organizations will need to coordinate before the transition is complete.
The hybrid design matters for compatibility. Because the platform issues both classic TLS certificates and Merkle Tree Certificate equivalents, a site can serve a certificate that older clients can still validate while newer clients take the post-quantum path. That is the mechanism behind Cloudflare's claim that millions of websites could switch without extra performance overhead.
Here are the concrete figures Cloudflare's plans put on the table:
- Roughly 40 times more handshake data would be required by quantum-proof versions of today's classical X.509 certificates.
- The Merkle Tree design cuts handshake data to about 40 kilobytes, roughly what is processed now.
- The 2011 DigiNotar hack allowed the minting of 500 counterfeit certificates for Google and other websites.
- Cloudflare expects to start issuing certificates in the first quarter of 2027.
Why this matters beyond Cloudflare
For website operators, the practical question is not whether post-quantum certificates arrive but how much work they will have to do when they do. Cloudflare's pitch is that the transition can be a switch rather than a migration project, because the certificates are free to paying and non-paying users and the platform handles both old and new formats. If that holds, the burden shifts to the certificate authorities, browser vendors, and root programs that must agree on how Merkle Tree proofs are validated and logged.
For everyone else, the significance is that the WebPKI is being rebuilt on a timeline measured in years while the quantum threat is still prospective. The transparency-log coupling Cloudflare describes could make certificate issuance more auditable by default, since logging would no longer be a separate step that can be skipped. That is an architectural change with consequences for how rogue certificates are detected—though the source material does not establish that any rogue issuance has occurred under the new design, because the design is not yet in production.
The honest takeaway is that this is a commitment with a date attached, not a shipped defense. Cloudflare has said it will report milestones as they land, which gives site owners and security teams a way to track whether the 2027 target holds. Until certificates are actually issued, the quantum-safe WebPKI remains a plan on paper.
Sources
- Ars Technica Original source
- said Also reporting
- announced a solution Also reporting
- hierarchical data structures Also reporting
Continue Reading
AI-Discovered Flaws Skew Toward RCE
Google's threat intelligence unit reports AI-found vulnerabilities are far more likely to enable remote code execution than other disclosed flaws.
Teen's Auth Flaw Opened Titan's Data Vault
A 16-year-old researcher bypassed Microsoft's Titan analytics by exploiting an unverified JWT and was paid a $5,000 bounty.
Google: AI Is Rewriting Bug Economics
GTIG data shows vulnerability disclosures doubled in 2026 while exploitation shifted toward n-days, with AI-discovered flaws carrying a riskier profile.