Cloudflare Plans Public Certificate Authority for Quantum-Safe TLS Certificates
Cloudflare announced plans to run a free public Certificate Authority issuing quantum-safe TLS certificates. Instead of classic X.509 chains with heavy post-quantum signatures (roughly 40x more handshake data), it uses Merkle Tree Certificates from the IETF PLANTS working group. Broad public issuance is targeted for early 2027.
- Direct post-quantum signatures like ML-DSA and Falcon inflate handshake data about 40x
- Merkle Tree Certificates unify issuance and logging, signing only the tree root
- Clients cache landmarks, cutting handshake payloads to elliptic-curve parity
- Public issuance targets early 2027; production tests ran with Chrome engineers
Read next
Security