Cloudflare to Launch Free Public CA with ACME Automation and Post-Quantum MTC
Cloudflare plans to become a public certificate authority offering free, automated TLS certificates via ACME, leveraging GlobalSign's trusted root for immediate compatibility, while pursuing operational transparency and Merkle Tree Certificates for post-quantum readiness, providing a redundant alternative to Let's Encrypt for Linux admins and self-hosted developers.
Let's Encrypt's Dominance in Free Certificates
Let's Encrypt currently issues nearly ten million certificates per day and secures around 500 million websites, making it the dominant free certificate authority.
Cloudflare's Entry as a Public CA
Cloudflare, a major CDN and security provider headquartered in San Francisco, announced plans to establish its own public certificate authority. The company intends to deliver free, automated TLS certificates to website operators through the widely adopted ACME protocol.
Rationale: Systemic Risk of a Single Free CA
Cloudflare acknowledges Let's Encrypt's success but highlights a systemic risk: if the sole major free CA suffers a serious outage, most websites would lack a free, automated alternative. Cloudflare has long built redundancy into its Universal SSL certificates — each certificate has a backup with a separate key pair, issued by a different CA, all fully automated. The company now wants to fully realize this redundancy philosophy by operating its own CA.
GlobalSign Root Acquisition for Immediate Trust
Previously Cloudflare was one of the largest consumers of publicly trusted certificates, not an issuer. That changes with its application to join the root certificate programs of Chrome, Apple, Microsoft, and Mozilla. Crucially, Cloudflare has signed an agreement to acquire GlobalSign's root certificate, which has been trusted in browsers, operating systems, and devices since 2012. Using an existing trusted root avoids the multi-year wait a new root would require for broad device coverage, ensuring compatibility with legacy systems from day one.
Transparency and Operational Plans
Cloudflare outlined two additional initiatives. First, it plans to increase transparency of its CA operations by publishing reproducible builds of its certificate signing software, providing hardware security module (HSM) attestations for key storage, and operating a public dashboard showing CA health and incident information.
Merkle Tree Certificates for Post-Quantum Readiness
Second, Cloudflare aims to be among the first public CAs to issue production-grade Merkle Tree Certificates (MTC), targeting Q1 2027. MTC is a more compact certificate format designed for post-quantum authentication, because traditional certificate chains may become larger and increase TLS connection overhead in a post-quantum world.
Current Status and Timeline
As of the article's publication, Cloudflare has not yet issued any public certificates. Its root applications are still pending approval by the relevant trust programs, and no concrete date for the start of public certificate issuance has been announced.
Implications for Operators and Developers
Once another large, free, ACME-compatible CA becomes available, it will be especially valuable for Linux system administrators and self-hosted developers who already rely on automated TLS deployment, giving them a robust fallback option.
The entry of an internet infrastructure giant into the free CA space signals that the rules of network encryption and security are being rewritten — hopefully for the better.
Signed-in readers can open the original source through BestHub's protected redirect.
This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactand we will review it promptly.
21CTO
21CTO (21CTO.com) offers developers community, training, and services, making it your go‑to learning and service platform.
How this landed with the community
Was this worth your time?
0 Comments
Thoughtful readers leave field notes, pushback, and hard-won operational detail here.
