Cloudflare has officially declared its intention to autonomously issue publicly trusted certificates for websites, establishing the bedrock for HTTPS functionality across modern browsers. The technology giant is establishing a proprietary Certificate Authority (CA) and intends to provide automated certificate issuance entirely free of charge. This bold initiative positions the new service as a formidable alternative to the ubiquitous Let’s Encrypt. However, Cloudflare has not commenced issuing these initial certificates yet; the organization must successfully navigate the rigorous inclusion protocols of trusted root certificate programs managed by major browser and operating system developers.
Consequently, Cloudflare has already submitted applications to the root programs of Chrome, Apple, Microsoft, and Mozilla. Acceptance into these programs remains critically paramount for any public Certificate Authority. A browser must explicitly trust the root certificate; otherwise, users will encounter severe security warnings regarding insecure connections upon attempting to access an affiliated website.
Strategic Acquisitions and Redundancy
Simultaneously, Cloudflare executed a definitive agreement to acquire a venerable, established root certificate from GlobalSign. According to corporate disclosures, this specific root has resided within the trust stores of browsers, operating systems, and myriad devices since 2012. This strategic acquisition will facilitate comprehensive coverage for antiquated devices that no longer receive crucial updates and might inevitably fail to integrate a novel Cloudflare root certificate. Concurrently, the company is meticulously forging new roots tailored for contemporary trust programs. It is crucial to clarify that this transaction specifically concerns the acquisition of an existing GlobalSign root certificate, not the wholesale purchase of the entire certifying authority.
Cloudflare articulates that one primary catalyst for launching this proprietary service is the internet’s precarious reliance on a diminutive cluster of colossal certificate providers. Let’s Encrypt currently wields a particularly conspicuous influence, issuing approximately 10 million certificates daily and servicing hundreds of millions of websites. In the catastrophic event of a severe disruption at such a monumental operator, the market would desperately necessitate an alternative, complimentary service possessing the capacity to rapidly absorb immense workloads. Cloudflare already implements a remarkably similar philosophy within its Universal SSL architecture: a secondary certificate, possessing a distinct key originating from an alternative certifying authority, diligently accompanies the primary certificate.
Automating the Future of HTTPS
Cloudflare intends to construct the acquisition and renewal of certificates fundamentally around the ACME protocol, which contemporary web servers and automated certificate management frameworks utilize extensively. To transition from an alternative ACME-compatible authority, an administrator will typically only need to modify the service directory address, thereby circumventing a comprehensive infrastructure overhaul. Cloudflare plans to aggressively push the envelope by establishing automated renewal as a mandatory prerequisite for issuance. The client infrastructure must definitively support ACME Renewal Information (RFC 9773), actively retrieve the recommended renewal window, and autonomously replace any certificate approaching its expiration epoch.
This relentless drive toward automation is becoming exponentially critical against the backdrop of the diminishing lifespan of public TLS certificates. According to the formal transition schedule ratified by the CA/Browser Forum, the maximum validity period for certificates issued on or after March 15, 2026, is capped at 200 days. Furthermore, beginning March 15, 2027, this threshold will plummet to 100 days, and by March 15, 2029, it will shrink drastically to merely 47 days. Under manual administration protocols, these truncated lifespans exponentially amplify the catastrophic risk of a delayed certificate replacement; consequently, the entire industry is methodically migrating toward fully automated issuance and comprehensive renewal frameworks.
Transparency and the Fina Incident
Cloudflare publicly pledges to subject a substantial proportion of the new center’s infrastructure to rigorous external scrutiny. The organization plans to publish reproducible builds of its certificate signing software, mathematically authenticate the integrity of the hardware security modules harboring the cryptographic keys, and launch a publicly accessible dashboard detailing issuance status and ongoing incidents. To identify erroneously or illicitly issued certificates, the contemporary Web PKI architecture already mandates Certificate Transparency, wherein exhaustive details regarding public certificates populate verifiable, append-only logs.
For Cloudflare, the terrifying risks associated with erroneous issuance transcend mere theoretical conjecture. In 2025, the Fina certifying authority disastrously issued certificates for the IP address 1.1.1.1, a crucial asset utilized by Cloudflare’s public DNS service in collaboration with APNIC. Investigators ultimately uncovered 12 unauthorized certificates. This alarming incident starkly illustrated a fundamental vulnerability inherent to the Web PKI ecosystem: a critical error committed by a single, trusted certifying authority possesses the terrifying capacity to compromise vital resources over which the authority exercises zero operational control.
Quantum Resistance and Merkle Tree Certificates
The principal technological differentiator of this ambitious new project will be its dual orientation, focusing not only on classical certificates but also on pioneering post-quantum cryptographic defenses. Cloudflare plans to commence the issuance of Merkle Tree Certificates (MTC) during the first quarter of 2027. Rather than demanding a distinct, computationally heavy signature chain for each individual certificate, this innovative paradigm aggregates certificates into a highly efficient Merkle tree. The certifying authority merely signs the apex of the tree, and the browser subsequently receives a profoundly compact cryptographic proof confirming the presence of the requisite certificate within the overarching structure.
This sophisticated approach is specifically designed to drastically minimize data volume during the critical transition to post-quantum algorithms, which inherently utilize keys and signatures significantly larger than those currently deployed. Google Chrome has already selected Merkle Tree Certificates as the primary trajectory for the evolution of post-quantum HTTPS authentication, actively constructing a dedicated Quantum-resistant Root Program. Currently, Chrome possesses no immediate plans to integrate traditional X.509 certificates wielding post-quantum signatures into its standard root repository, primarily due to the severe consequent inflation in TLS connection payload sizes.
Cloudflare anticipates concurrently supporting both classical certificates and the revolutionary MTC architecture, ensuring that websites can transition to the new paradigm gradually and methodically. The corporation’s vast proprietary infrastructure will function as the inaugural, massive-scale proving ground: Cloudflare intends to utilize the new center’s certificates across its own myriad services while simultaneously maintaining operational relationships with 16 external certifying authorities. The organization has not yet disclosed a definitive timeline for the mass issuance of conventional public certificates. The closest formally designated target date exclusively concerns MTCs: Cloudflare anticipates generating the first fully operational certificates of this novel class in early 2027.
Support Our Threat Intelligence
Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!