Cloudflare to issue free quantum-safe TLS certificates via CA GlobalSign
Cloudflare announced on Tuesday that it intends to issue quantum-proof TLS certificates, positioning itself as one of the first authorities to provide security credentials designed to resist quantum computer attacks.…
Cloudflare announced on Tuesday that it intends to issue quantum-proof TLS certificates, positioning itself as one of the first authorities to provide security credentials designed to resist quantum computer attacks. The internet infrastructure provider stated it will utilize an open source platform capable of issuing both standard TLS certificates and their post-quantum equivalent, known as Merkle Tree Certificates. These hybrid certificates will be available at no cost to both paying and non-paying users. To facilitate the deployment of this system across the broader TLS ecosystem, Cloudflare is acquiring a trusted certificate root from CA GlobalSign. The company said this acquisition will allow millions of websites to enable post-quantum certificates without experiencing increased performance overhead. This initiative forms part of a larger overhaul of the web public key infrastructure, or WebPKI, aimed at securing website encryption and authentication for the coming post-quantum age. A significant technical challenge involves implementing quantum-proof signatures that can be easily transmitted during web requests and recorded in transparency logs to prevent the assignment of counterfeit certificates. Cloudflare noted that completing this transformation will take years, as it requires coordinated efforts from engineers designing operating systems, browsers, certificate authorities, and other internet infrastructure components.