HeadlinesBriefing favicon HeadlinesBriefing.com

Cloudflare Quantum-Safe TLS Certificates 2027

Ars Technica •
×

Cloudflare plans to issue quantum-safe TLS certificates using Merkle Tree proofs to replace vulnerable signature chains. The technology reduces handshake data to about 40 kilobytes and integrates certificate logging directly into issuance, making transparency a requirement rather than an add-on. Google and Cloudflare have tested the design in limited pilot programs.

The system addresses risks from Shor’s algorithm, which could forge classical encryption signatures and certificate logs. Cloudflare engineer Mari Galicer emphasized that coupling issuance with logging ensures transparency is inherent to operation. The plan also includes Automated Certificate Management Environment (ACME) for automated renewal and out-of-band signature delivery via browser updates if servers fail.

Cloudflare expects to begin issuing these certificates in the first quarter of 2027. The initiative responds to long-term threats to Web PKI, highlighted by past incidents like the 2011 Digi Notar hack that produced 500 counterfeit certificates. Merkle Trees allow a single 'tree head' signature to represent millions of certificates, with browsers verifying lightweight 'landmark' proofs.

This approach strengthens trust in certificate validity while preparing for quantum computing threats.