Static

Cloudflare plans to issue quantum-safe TLS certificates

First reported by Ars Technica ·

The signal ●○○○ Compiled by AI from Ars Technica, the single source so far
Why you might care

Quantum-safe TLS certificates will be free to all users, removing a potential cost barrier for enhanced web security.

What happened

Cloudflare announced its intention to issue quantum-safe TLS certificates, utilizing a post-quantum cryptography method known as Merkle Tree Certificates. This initiative aims to make website authentication resistant to attacks from future quantum computers. The company will employ an open-source platform to issue both traditional and hybrid quantum-safe certificates. To ensure widespread adoption and integration into the existing TLS ecosystem, Cloudflare is acquiring a trusted root certificate from CA GlobalSign. These hybrid certificates will be offered at no additional cost to all users, including those on free tiers. Cloudflare anticipates that this transition will allow millions of websites to adopt post-quantum certificates with minimal impact on performance, enabling a seamless upgrade. The company expects to begin issuing these certificates in the first quarter of 2027.

What it means

Cloudflare's move signals a critical step towards fortifying the Web Public Key Infrastructure (WebPKI) against the imminent threat of quantum computing. By adopting Merkle Tree Certificates, an approach that drastically reduces the overhead associated with current quantum-resistant signature proposals, Cloudflare is paving the way for a more scalable and efficient post-quantum web. The integration of these certificates, coupled with the acquisition of GlobalSign's root, suggests a concerted effort to democratize advanced security, making it accessible without performance penalties or added expense.

This transition necessitates fundamental architectural shifts across the internet's security layers, impacting browsers, operating systems, and certificate authorities alike. The hybrid certificate approach, where both classic and post-quantum equivalents are issued, aims to ease this transition, allowing for a phased migration. The commitment to an open-source platform and public sharing of milestones highlights a collaborative strategy to achieve ubiquity in the post-quantum TLS ecosystem.

AI-written summary. May contain errors.

Cloudflare