Cloudflare Is Building a Certificate Authority for the Whole Internet

Cloudflare Is Building a Certificate Authority for the Whole Internet

Cloudflare has applied to the Chrome, Apple, Microsoft, and Mozilla root programs and signed an agreement to acquire a trusted root from GlobalSign, aiming to become a public certificate authority. The move adds a free, ACME-first alternative to Let's Encrypt, which issues ten million certificates daily, and targets post-quantum Merkle Tree Certificates by early 2027. Cloudflare plans to require ACME Renewal Information and publish reproducible builds and a public issuance dashboard.

That success comes with some systemic risk: if the dominant free certificate authority had a bad week, much of the web would have no comparable free, automated alternative ready to take the load.
  1. vg

    A very welcome move because for years Cloudflare has freeloaded certs from Let's Encrypt without sponsoring Let's Encrypt finacially. Though Cloudflare has contributed in otherwise to the ecosystem like by running CT logs etc.

    Now, it looks like WebPKI is going to fracture into two regarding PQ Crypto. With Google (GTS and Chrome), Cloudflare and Let's Encrypt all preferring MTC and legacy CA's like Digicert, Sectigo, Globalsign all heading towards non MTC.

    If Cloudflare would not have decied to become a PQ CA for MTC. We would have a duopoly with GTS and Let's Encrypt. This is a worse off situation. Therefore I welcome Cloudflare CA for MTC.

    Also, its not like they are going to make any money of the CA business if they are going to issue DV certs for free. It will reduce the pressure on Let's Encrypt from carrying the burden of securing 60% of the world's webistes.

  2. phillipseamore

    Would like to see them working more with TLD operators here, I'd like to see a CA partner with TLD ops to offer distributed and resilient issuance (especially with shorter cert lifetimes) with intermediate certificates locked to their TLDs, TLD operators are already a significant part of the chain of trust since it's all based on DNS today.

  3. MisterMunchkin

    It makes sense for them to issue their own certificates because it’s inline with the rest of their offerings, but it seems kind of strange you can just buy someone else’s root certificate and issue under their name. It kind of defeats the point of trusting the root. What if a bad actor starting buying up authorities? You could compromise a bunch of services without them even knowing.

  4. edelbitter

    > We have seen certificate authorities caught between timely revocation and keeping subscribers’ sites online because too many subscribers could not replace their certificates quickly enough. When certificates need to be retired [..] we can [..] spread replacements across the available time, and track replacement issuance.

    That sounds awfully sympathetic to the "only revoke if/when convenient" bullshit Telekom Security et al pulled off. I was hoping for something closer to:

    We have seen certificate authorities extend promises to their customers that they knew to be fundamentally incompatible with their committed obligations to the CA/B & the wider internet. We intend to do better than that. We will not hide behind claiming it was inconvenient to fulfill our duties that come with operating a public CA. Our customers will be prepared for whatever revocation that we might be required to execute.

  5. chaz6

    The article contains conflicting statements:

    > anyone already pointed at any existing free CA can move to us by changing a directory URL, with no new tooling and nothing to re-architect.

    > We will only issue to clients that support ACME Renewal Information (ARI), standardized in RFC 9773.

    I do not think both can be true.

More from this day

2026-09-30