Cloudflare Announces Public Certificate Authority Plans
On September 29, Cloudflare made a monumental announcement regarding global internet security. The technology giant officially declared its strategic intent to establish a public-facing Certificate Authority (CA). Consequently, they formally applied to join prestigious root certificate programs. These critical programs include those managed by Chrome, Apple, Microsoft, and Mozilla.
Strategic Acquisition of GlobalSign Root
Simultaneously, Cloudflare executed a definitive agreement with GlobalSign. Through this partnership, they plan to acquire an established root certificate possessing widespread foundational trust. Therefore, their future issued certificates will immediately support a broader range of operating systems, browsers, and connected devices. Currently, Cloudflare has not commenced issuing certificates. These vital operations remain strictly within the necessary application and rigorous approval phases.
Expanding Internet Encryption Infrastructure
Company representatives emphasize that entering the public CA domain represents a logical progression. This initiative directly follows their revolutionary 2014 Universal SSL deployment. Back then, Cloudflare boldly provided complimentary TLS protection for all hosted platforms. Ultimately, this decisive action prompted countless websites to adopt HTTPS securely by default.
Overcoming Trust Accumulation Challenges
Generally, newly established root certificates face significant challenges regarding comprehensive coverage. Achieving widespread trust requires substantial long-term accumulation. Even after obtaining crucial vendor endorsements, a new root must gradually permeate global device trust stores. Furthermore, obsolete or unpatched legacy devices typically never receive these vital updates.
Therefore, Cloudflare strategically implements a dual-path approach. First, they will utilize the acquired GlobalSign root to immediately cover existing browsers and operating systems. This specific GlobalSign root has maintained trusted status since 2012. Concurrently, Cloudflare will diligently pursue entirely new root certificates. This secondary effort ensures complete compliance with increasingly stringent future policy requirements.
Automated and Redundant Certificate Services
Moreover, Cloudflare fully intends to provide exceptional, cost-free automated certificate services. They will implement the Automated Certificate Management Environment (ACME) as their primary operational interface. Developers already utilize this widespread protocol extensively for seamless TLS application and renewal. In the near future, users can simply modify their ACME directory addresses to migrate management workflows directly to Cloudflare.
Addressing Market Concentration
Currently, Let’s Encrypt impressively issues approximately 10 million certificates daily, serving over 500 million websites. However, Cloudflare astutely observes that free automated services remain highly concentrated among very few authorities. Therefore, introducing additional capable public CAs provides essential systemic redundancy.
Internally, Cloudflare already utilizes multiple CAs to supply client certificates securely. They carefully configure primary and backup paths to effectively mitigate service interruptions or sudden revocations. Now, the company aspires to extend this robust redundancy mechanism across the entire internet landscape.
Future-Proofing with Post-Quantum Cryptography
Regarding operational reliability, Cloudflare will mandate that utilizing clients support automated renewal processes. Furthermore, they will require adherence to ACME Renewal Information (ARI) standards. This mechanism, formalized as RFC 9773, effectively communicates optimal renewal timeframes directly to clients. Additionally, the company pledges total transparency regarding its issuance systems, including publishing verifiable software build results and hardware security module attestations.
Beyond traditional TLS, Cloudflare actively prepares for the impending post-quantum cryptographic era. By early 2027, the company expects to begin issuing production-ready Merkle Tree Certificates (MTC). These innovative certificates intentionally reduce the burdensome TLS handshake overhead caused by expanding post-quantum certificate chains. Ultimately, Cloudflare envisions MTCs safely coexisting alongside traditional certificates, facilitating a smooth, gradual transition for all users.











