Cloudflare Launches Free TLS Certificate Authority

Cloudflare has recently unveiled its own certificate authority, with a focus on providing free TLS certificates that utilize crypto-algorithms resilient against quantum computer attacks. The company has also announced the acquisition of the GlobalSign certification center, which will serve as the foundation for this initiative. By leveraging GlobalSign’s existing root certificates, Cloudflare aims to streamline the issuance of certificates to ensure widespread device compatibility. Furthermore, Cloudflare has submitted applications to have its root certificate included in the root certificate lists maintained by major tech giants such as Google, Apple, Microsoft, and Mozilla.

The introduction of this new public certificate authority is expected to complement existing services like Let’s Encrypt, which currently holds a substantial share of the certificate issuance market. With almost 40% of certificates being issued by Let’s Encrypt, there are concerns about the systemic risks associated with depending heavily on a single certification authority. Cloudflare’s service will offer full automation and leverage the open ACME protocol to simplify certificate management. Existing Let’s Encrypt users will be able to transition to Cloudflare’s service by making a simple URL change in their settings.

In addition to providing free TLS certificates, the new certification authority will also focus on preparing for the shift to post-quantum cryptography. Cloudflare has announced plans to implement support for the Merkle Tree Certificates (MTC) format in its certification center by the first quarter of 2027. MTC is designed for use with post-quantum cryptographic algorithms, which typically involve significantly larger key and signature sizes compared to traditional algorithms.

MTC utilizes a tree structure known as a Merkle Tree to reduce the data size for each TLS connection. Instead of signing individual certificates separately, MTC consolidates certificates into a tree structure, with only the root hash being signed by the certification authority. This approach allows for efficient verification of certificate inclusion in the signed tree, enhancing security and performance for TLS connections.

/Reports, release notes, official announcements.