MikhbarMIKHBAR
Web

Cloudflare Plans to Issue Quantum-Safe TLS Certificates

Cloudflare has announced plans to issue quantum-proof TLS certificates as part of a major overhaul to secure website authentication and encryption for the post-quantum era.

Cloudflare Plans to Issue Quantum-Safe TLS Certificates

Overhauling Web Public Key Infrastructure

Cloudflare announced plans to issue quantum-proof TLS certificates, making it one of the first certificate authorities to provide cryptographic protection designed to withstand attacks from quantum computers. The upcoming rollout forms part of a broader, long-term overhaul of the web public key infrastructure (WebPKI) necessary to secure website encryption and authentication.

The transition requires fundamental architectural changes rather than simple algorithm swaps. Directly updating classical X.509 certificates to quantum-proof versions would increase TLS handshake data requirements by roughly 40 times, potentially breaking standard internet performance. To address this, the industry has explored alternative designs like those <جلسة>announced a solution</جلسة> proposed by Google using hierarchical data structures.

Leveraging Merkle Tree Certificates

To bypass bandwidth constraints, Cloudflare will utilize an open-source platform that issues both classic TLS certificates and post-quantum equivalents known as Merkle Tree Certificates. These hierarchical data structures use cryptographic hashes to verify large sets of information using a small fraction of the total contents.

Rather than relying on resource-prohibitive quantum-vulnerable signature chains, the system allows certificate authorities to sign a single tree head representing millions of certificates. Browsers receive a lightweight proof indicating the certificate's location within the tree, reducing handshake data down to about 40 kilobytes.

Acquiring a Trusted Certificate Root

To build the massive infrastructure required for ecosystem ubiquity, Cloudflare will acquire a trusted certificate root from CA GlobalSign. These hybrid certificates will be provided free of charge to both paying and non-paying users, allowing millions of websites to adopt post-quantum security effortlessly.

Cloudflare engineer Mari Galicer <جلسة>said</جلسة> that coupling issuance and transparency logging makes logging a core requirement for operation rather than an optional add-on.

Addressing Transparency and Security Risks

Industry-wide rules mandate that TLS certificates be published in append-only distributed transparency logs. These logging frameworks were implemented following a notable 2011 hack involving DigiNotar, which exposed vulnerabilities in how counterfeit certificates could be minted.

In the future, a viable Shor’s algorithm could forge classical encryption signatures, public keys, and signed certificate timestamps used by browsers to verify registration. Integrating transparency logs directly into certificate issuance helps mitigate these security risks.

Timeline and Future Deployment

Cloudflare's implementation strategy incorporates automated mechanisms such as ACME for continuous certificate renewal. Additionally, the system includes fallback methods for transmitting signatures out-of-band during unexpected technical disruptions.

While engineering teams across operating systems and browsers must still complete years of collaborative work, Cloudflare stated its commitment to sharing development milestones publicly. Company representatives <جلسة>said</جلسة> that actual certificate issuance is expected to begin in the first quarter of 2027.

Sources

  • Ars TechnicaCloudflare plans to issue quantum-safe TLS certificates

Continue chronologically

You are readingCloudflare Plans to Issue Quantum-Safe TLS Certificates
Cloudflare Launches K2 Public Beta for Serverless Event Streams
Older storyCloudflare Launches K2 Public Beta for Serverless Event StreamsOctober 1, 2026 · 3 min

Related entity coverage