Cloudflare Announces Intent to Become Public Certificate Authority, Acquires GlobalSign Root
Key point
Cloudflare has applied for inclusion in major root programs and signed an agreement to acquire a GlobalSign root to ensure broad device compatibility.
Details
Cloudflare is announcing its intent to become a public certificate authority (CA), marking a shift from being one of the largest consumers of publicly trusted certificates to issuing them itself. This move aims to provide a redundant, free, and automated alternative to existing dominant CAs like Let's Encrypt, ensuring the web has a backup if the primary provider faces issues. The company has applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs and signed a definitive agreement to acquire an established root from GlobalSign.
Dual-Root Strategy for Compatibility
To address the challenge of device compatibility, Cloudflare is pursuing a two-path strategy. The acquired GlobalSign root, trusted since 2012, ensures immediate reach across older devices and operating systems that a new root would not support. Simultaneously, Cloudflare is submitting a new root for inclusion in root key programs to meet future policies that may cap the age of trusted roots. This combination allows Cloudflare to serve both legacy clients and modern devices while preparing for stricter ecosystem standards.
ACME-First and Resilience
The new CA will be Automated Certificate Management Environment (ACME)-first, allowing users to switch providers by simply changing a directory URL without new tooling. To ensure reliability, Cloudflare will only issue to clients supporting ACME Renewal Information (ARI) (RFC 9773), mandating automated renewal processes. The company plans to "fail small" by designing recovery processes before incidents occur, such as spreading replacement issuance across available time windows during revocation events. Transparency will be maintained through reproducible builds, hardware security module attestations, and a public dashboard for issuance health.
Post-Quantum Leadership
Cloudflare intends to be one of the first CAs to issue production Merkle Tree Certificates (MTCs), with the first certificates targeted for the first quarter of 2027. MTCs are a compact, post-quantum-resistant certificate format championed by Cloudflare at the IETF and preferred by Chrome for post-quantum authentication. By offering both classic certificates and MTCs under one CA, Cloudflare aims to facilitate a smooth transition for customers without requiring a hard cutover or dual-system management. Cloudflare will act as "Customer Zero," using its own CA for internal operations to validate the system at scale.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.