Arstechnica iconArstechnicaSep 30, 2026 ~4 min source read

Cloudflare will issue post-quantum TLS certificates using Merkle Tree design

Cloudflare plans to become a public CA and issue hybrid classical and Merkle Tree Certificates to reduce the bandwidth and computation costs of post-quantum signatures, acquire a trusted root from GlobalSign, and begin production MTC issuance in early 2027.

Cloudflare plans to issue quantum-safe TLS certificates

Share this story

Send the public story page.

Useful takeaways from this story.

Cloudflare will issue hybrid TLS certificates that include classical and Merkle Tree-based post-quantum proofs, aiming for the same handshake size as today (~40 KB).

Merkle Tree Certificates replace long quantum-vulnerable signature chains with compact tree heads and landmarks, coupling issuance and transparency logging.

# What Cloudflare announced

Cloudflare said it plans to issue quantum-resistant TLS certificates using an open-source platform that produces both traditional TLS certificates and Merkle Tree Certificates (MTCs). The company expects to issue production MTCs starting in the first quarter of 2027 and will make hybrid certificates free to paying and non-paying users.

# Why Merkle Trees matter

Replacing classical X.509 signature chains with quantum-resistant signatures directly would increase handshake data roughly 40-fold, which Cloudflare says would break current web performance models. Google and Cloudflare have tested Merkle Trees that use cryptographic hashes to compress the proof material so handshake size drops back to about 40 kilobytes, roughly equivalent to today's traffic.

Instead of signing every certificate in a chain, a certificate authority signs a single "tree head" that represents millions of certificates. Browsers typically receive a lightweight proof called a "landmark" that shows a certificate is in the tree. That pattern keeps both bandwidth and computation close to existing levels.

# How transparency logging changes

A post-quantum threat such as Shor's algorithm could, in principle, forge classical signatures and timestamp proofs. Merkle Trees avoid listing each signature link explicitly while still providing auditable proof that a certificate was logged.

# Operational and technical details

  • Cloudflare will issue hybrid certificates that contain both classical and post-quantum material so existing clients are supported while post-quantum proofs are rolled out.
  • The design reduces handshake data to roughly 40 KB by using Merkle Tree proofs instead of full post-quantum signature chains.
  • Environment (ACME) for automated issuance and renewal.
  • There will be mechanisms to deliver signatures out-of-band (for example via browser updates) when a server cannot receive landmark updates.

# Challenges and timeline

Cloudflare says the transition requires fundamental architectural changes across the Web Public Key Infrastructure (WebPKI). That includes work by operating-system vendors, browser makers, certificate authorities, and other Internet infrastructure teams.

# Practical implications for site operators and administrators

Site operators should expect a gradual rollout. Because Cloudflare will offer hybrid certificates and has acquired a trusted root, many sites can adopt post-quantum-ready certificates without code changes or performance penalties. However, broad device and browser support depends on root program approvals and ecosystem updates that follow over time.

More context around this story.

Интернет защитят от квантовых компьютеров: Cloudflare готовит бесплатные постквантовые TLS-сертификаты
3dnews icon3dnewsSep 30, 2026

Интернет защитят от квантовых компьютеров: Cloudflare готовит бесплатные постквантовые TLS-сертификаты

Cloudflare объявила о планах по выпуску TLS-сертификатов, устойчивых к атакам с использованием квантовых компьютеров. Компания сообщила, что будет использовать платформу с открытым исходным кодом, позволяющую выпускать как традиционные TLS-сертификаты, так и их постквантовые аналоги — так называемые сертификаты на осно

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app