Cloudflare Moves Into Public Certificate Authorities, Promising Free Automated TLS Certificates
Cloudflare has applied to join the root certificate programmes of Chrome, Apple, Microsoft and Mozilla, and plans to offer free automated TLS certificates via ACME — part of a broader push that includes post-quantum Merkle Tree Certificates from 2027.
September 30 (IT Home) — Cloudflare announced on the 29th local time that it plans to become a public certificate authority (CA), and has formally applied to join the root certificate programmes of Chrome, Apple, Microsoft and Mozilla.
At the same time, Cloudflare has signed a definitive agreement with GlobalSign to acquire a root certificate that already has a broad base of trust, so that certificates it issues in future can cover more operating systems, browsers and devices.
IT Home notes: Cloudflare has not yet begun issuing certificates; the work is still at the application and approval stage.
Cloudflare says its move into the public CA field is a further step in internet encryption infrastructure, following the launch of Universal SSL in 2014. That year, Cloudflare provided free TLS for the websites it served, leading a large number of sites to start using HTTPS by default.
For a newly created root certificate, the biggest problem is that coverage takes a long time to build up. Even after winning recognition from browser and operating system vendors, a new root certificate still has to make its way gradually into the trust stores of devices worldwide — and old devices that no longer receive updates usually cannot get new root certificates at all.
Cloudflare therefore plans to take two paths at once. On one hand, it will use the existing root certificate obtained from GlobalSign to cover the trust systems already deployed in browsers, operating systems and other devices. On the other, it will apply for a new root certificate that meets the tightening policy requirements of future root certificate programmes. Cloudflare says the relevant GlobalSign root certificate has been trusted by various browsers, operating systems and devices since 2012.
Cloudflare also plans to offer a free automated certificate service, using ACME (Automated Certificate Management Environment) as its main interface. The protocol is already widely used to apply for and renew TLS certificates automatically. In future, users will be able to migrate their existing free-CA certificate management workflows to Cloudflare simply by changing the ACME directory address, without redesigning their infrastructure.
Cloudflare notes that Let’s Encrypt currently issues about 10 million certificates a day, serves more than 500 million websites, and reached more than 4 billion active certificates cumulatively in 2025. Cloudflare argues that free automated certificate services are highly concentrated among a small number of CAs, so more public CAs with the same automation capabilities are needed to provide redundancy.
Cloudflare itself already uses several CAs to provide certificates to its customers, and sets up primary and backup certificate paths to cope with situations such as CA service outages and certificate revocations. The company says that once it has established a public CA, it hopes to extend this redundancy mechanism to the internet as a whole.
On reliability, Cloudflare plans to require clients using its CA to support automated renewal, and to make ACME Renewal Information (ARI) — a standard mechanism that tells clients the window in which a certificate should be renewed — one of the conditions for issuing a certificate. The mechanism has been standardised as RFC 9773.
Cloudflare also plans to publish information about its certificate issuance system and operations, including releasing reproducible builds of the software used to issue certificates, attesting to the hardware security modules that store CA keys, and providing public dashboards on certificate issuance health and security incidents.
Beyond traditional TLS certificates, Cloudflare also plans to move into post-quantum cryptography. The company expects to begin issuing production Merkle Tree Certificates (MTC) in the first quarter of 2027. Such certificates are designed to reduce the TLS handshake burden caused by certificate chains that keep growing under post-quantum cryptography.
Cloudflare says MTC will not immediately replace traditional certificates, and that the internet will continue to use both the existing WebPKI and traditional certificates for many years to come. The company plans to let traditional certificates and MTC coexist in the same CA, so that users can migrate to post-quantum authentication at their own pace.
Cloudflare is currently pursuing the application and review processes for the root certificate programmes of Chrome, Apple, Microsoft and Mozilla separately. The company expects to keep publishing progress, with the launch of its first Merkle Tree Certificates in early 2027 as the next major milestone.

评论
0 条讨论
登录后发表评论
立即登录暂无评论
成为第一个分享想法的人吧!