AI Briefing
Sign in

Cloudflare Launches Post-Quantum Certificate Authority Using Merkle Tree Certificates

·2026.09.29 22:00

Key point

Cloudflare will offer standard Merkle Tree Certificate issuance at no cost, targeting inclusion in Chrome’s Quantum-resistant Root Store by early 2027.

Details

Cloudflare is launching a new Certificate Authority (CA) that supports Merkle Tree Certificates (MTCs), a new architecture designed to scale post-quantum (PQ) cryptography efficiently. This move follows a successful experimental deployment with Chrome and addresses the performance degradation caused by simply swapping PQ signatures into existing certificate structures. The new CA aims to treat transparency as a first-party property rather than an add-on, targeting inclusion in Chrome’s Quantum-resistant Root Store by early 2027.

The Post-Quantum Scaling Problem

The current Web PKI faces a critical challenge: PQ signatures are roughly 40 times larger than classical ones. At Internet scale, this would balloon the data Certificate Transparency (CT) logs need to store by 40x, creating unacceptable overheads for clients, CAs, and monitors. Traditional certificate chains, which require multiple signatures and keys per handshake, cannot handle this load efficiently.

How Merkle Tree Certificates Work

MTCs, a draft specification from the IETF PLANTS working group, batch certificates into an append-only Merkle tree. Instead of signing each certificate individually, the CA signs the root of the tree. Clients verify certificates using a compact inclusion proof against a signed tree head. This design couples issuance and logging, making transparency a requirement for operation.

MTCs come in two forms:

  • Standalone: Contains a cosigned tree head and inclusion proof. Used as a fallback for clients without recent updates.
  • Landmark-relative: Uses lightweight inclusion proofs with no PQ signatures in the handshake, relying on out-of-band distribution of tree metadata. This is the primary mode for efficiency.

Experimental Results with Chrome

Cloudflare operated a "bootstrap CA" to issue MTCs to 50% of Chrome Beta 146 users. The experiment served billions of MTCs and demonstrated that landmark-relative certificates are highly efficient:

  • Handshakes transmit only one public key, one signature, and a compact inclusion proof.
  • Median performance was 9% faster than classical signature chains.
  • CT logs only need to carry hashes of public keys, preventing certificate explosion.

Implementation and Future Outlook

Cloudflare’s CA infrastructure will be a fork of Boulder, the software powering Let's Encrypt, incorporating upstream MTC support. The system will use Azul, Cloudflare’s open-source Rust-based transparency log, and implement the c2sp tlog mirror protocol. To ensure resilience, the CA will operate mirroring cosigners and require at least one independent cosignature on its own issued certificates, adhering to Chrome’s draft policy. Cloudflare will provide standard MTC issuance at no cost and aims to undergo rigorous evaluation for Chrome’s root store.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.