Cloudflare plans quantum-proof TLS certificates, buying a GlobalSign root

Cloudflare said on a Tuesday that it plans to issue quantum-proof TLS certificates. According to Ars Technica, that would make it one of the first authorities to issue such certificates, which use a form of cryptography widely believed to withstand attacks from quantum computers.
The Internet infrastructure provider said it will use an open source platform that issues both classic TLS certificates and a post-quantum equivalent known as Merkle Tree Certificates. The hybrid certificates will be free to both paying and non-paying users. To help build the system and establish ubiquity across the sprawling TLS ecosystem, Cloudflare will acquire an already trusted certificate root from the certificate authority GlobalSign. Cloudflare said the move will let millions of websites use post-quantum certificates at the flip of a switch and without any increased performance overhead.
The plan is part of a larger overhaul of the web public key infrastructure (WebPKI), which has to be reworked so that website encryption and authentication stay safe in the coming post-quantum age. One major challenge is using quantum-proof signatures that can be easily transmitted during web requests and recorded in transparency logs, which exist to ensure counterfeit certificates are not assigned to websites. The article says the makeover will take years, because it depends on the work of an untold number of engineers who design operating systems, browsers, certificate authorities and Internet infrastructure.
Cloudflare is explicit that nothing is being issued today. Steve Goldsmith of Cloudflare wrote: "We are not issuing certificates yet, and it will be a little while before we do." He added that what Cloudflare is doing is committing to the work in public, sharing milestones as they land, and describing what it is building while working with the root programs and other members of the WebPKI community.
The article stresses that this is an architectural problem, not an algorithm swap. Quantum-proof versions of today's classical X.509 certificates would add roughly 40 times the amount of data required for a TLS handshake, which happens each time a browser or other application starts a new session with a server. Ars Technica writes that the added computation and bandwidth of such a system would break the Internet as we know it. That is why a different certificate design, rather than bigger signatures in the old format, is at the centre of the plan.
Key facts
- Cloudflare said it plans to issue quantum-proof TLS certificates, but Steve Goldsmith wrote it is not issuing them yet and it will be a little while before it does.
- The open source platform behind the plan issues both classic TLS certificates and post-quantum Merkle Tree Certificates; the hybrid certificates will be free to paying and non-paying users.
- Cloudflare will acquire an already trusted certificate root from CA GlobalSign to help reach ubiquity across the TLS ecosystem.
- Cloudflare says millions of websites could use post-quantum certificates at the flip of a switch, with no increased performance overhead.
- Quantum-proof versions of classical X.509 certificates would add roughly 40 times the data to a TLS handshake, so the overhaul needs architectural change and will take years.
Why it matters
Website encryption and authentication rest on the WebPKI, and the article frames its overhaul for the post-quantum age as a major, multi-year project. Simply swapping in quantum-proof algorithms is not enough: doing so with today's X.509 certificates would add roughly 40 times the data to a TLS handshake. Cloudflare's plan, built on Merkle Tree Certificates and an already trusted root, is an attempt to get past that problem at scale. Ars Technica says it would make Cloudflare one of the first authorities to issue quantum-proof certificates.
Who it affects
Cloudflare says millions of websites could use post-quantum certificates at the flip of a switch. The hybrid certificates will be free to both paying and non-paying users. The wider effort also depends on engineers who design operating systems, browsers, certificate authorities and Internet infrastructure, and Cloudflare says it is working with the root programs and other members of the WebPKI community.
How to use it
There is nothing to use yet. Cloudflare is not issuing these certificates and gives no date beyond saying it will be a little while. What it promises for now is to work in public and share milestones as they land. When issuance starts, the plan is for the certificates to be free and for sites to switch them on, according to Cloudflare, without any increased performance overhead.
How solid is it
This is an announcement of intent, reported by Ars Technica with a direct statement from Cloudflare's Steve Goldsmith. The claims about millions of sites and no performance overhead are Cloudflare's own. The cryptography is described as widely believed, not proven, to withstand quantum attacks. No price or closing date for the GlobalSign root acquisition is given, and the name of the open source platform is not stated.
Risks and caveats
The timeline is open: Cloudflare says only that it will be a little while before it issues certificates, and the wider WebPKI makeover will take years. A major challenge is using quantum-proof signatures that can be easily transmitted during web requests and recorded in transparency logs. The plan also relies on Cloudflare working with root programs and the wider WebPKI community. The acquisition of the trusted root from GlobalSign is stated as planned, and no terms are given.
“We are not issuing certificates yet, and it will be a little while before we do.”
— Steve Goldsmith, Cloudflare