Cloudflare to Launch Free Public CA with ACME Automation and Post-Quantum MTC

Cloudflare plans to become a public certificate authority offering free, automated TLS certificates via ACME, leveraging GlobalSign's trusted root for immediate compatibility, while pursuing operational transparency and Merkle Tree Certificates for post-quantum readiness, providing a redundant alternative to Let's Encrypt for Linux admins and self-hosted developers.

21CTO
21CTO
21CTO
Cloudflare to Launch Free Public CA with ACME Automation and Post-Quantum MTC

Let's Encrypt's Dominance in Free Certificates

Let's Encrypt currently issues nearly ten million certificates per day and secures around 500 million websites, making it the dominant free certificate authority.

Cloudflare's Entry as a Public CA

Cloudflare, a major CDN and security provider headquartered in San Francisco, announced plans to establish its own public certificate authority. The company intends to deliver free, automated TLS certificates to website operators through the widely adopted ACME protocol.

Rationale: Systemic Risk of a Single Free CA

Cloudflare acknowledges Let's Encrypt's success but highlights a systemic risk: if the sole major free CA suffers a serious outage, most websites would lack a free, automated alternative. Cloudflare has long built redundancy into its Universal SSL certificates — each certificate has a backup with a separate key pair, issued by a different CA, all fully automated. The company now wants to fully realize this redundancy philosophy by operating its own CA.

GlobalSign Root Acquisition for Immediate Trust

Previously Cloudflare was one of the largest consumers of publicly trusted certificates, not an issuer. That changes with its application to join the root certificate programs of Chrome, Apple, Microsoft, and Mozilla. Crucially, Cloudflare has signed an agreement to acquire GlobalSign's root certificate, which has been trusted in browsers, operating systems, and devices since 2012. Using an existing trusted root avoids the multi-year wait a new root would require for broad device coverage, ensuring compatibility with legacy systems from day one.

Transparency and Operational Plans

Cloudflare outlined two additional initiatives. First, it plans to increase transparency of its CA operations by publishing reproducible builds of its certificate signing software, providing hardware security module (HSM) attestations for key storage, and operating a public dashboard showing CA health and incident information.

Merkle Tree Certificates for Post-Quantum Readiness

Second, Cloudflare aims to be among the first public CAs to issue production-grade Merkle Tree Certificates (MTC), targeting Q1 2027. MTC is a more compact certificate format designed for post-quantum authentication, because traditional certificate chains may become larger and increase TLS connection overhead in a post-quantum world.

Current Status and Timeline

As of the article's publication, Cloudflare has not yet issued any public certificates. Its root applications are still pending approval by the relevant trust programs, and no concrete date for the start of public certificate issuance has been announced.

Implications for Operators and Developers

Once another large, free, ACME-compatible CA becomes available, it will be especially valuable for Linux system administrators and self-hosted developers who already rely on automated TLS deployment, giving them a robust fallback option.

The entry of an internet infrastructure giant into the free CA space signals that the rules of network encryption and security are being rewritten — hopefully for the better.
Cloudflare free SSL certificate announcement banner
Cloudflare free SSL certificate announcement banner
Let's Encrypt certificate issuance statistics
Let's Encrypt certificate issuance statistics
Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

SSL/TLSCertificate AuthorityLet's EncryptCloudflareACMEPost-Quantum CryptographyMerkle Tree Certificates
21CTO
Written by

21CTO

21CTO (21CTO.com) offers developers community, training, and services, making it your go‑to learning and service platform.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.