Cloudflare plans to issue quantum-safe TLS certificates
Cloudflare plans to issue free hybrid TLS certificates that pair conventional certificates with a post-quantum alternative called Merkle Tree Certificates. The company says its approach could let millions of websites adopt quantum-resistant authentication with a switch and without added performance overhead, as part of a broader effort to prepare the web’s security infrastructure for future quantum attacks.
The certificates are not available yet, and Cloudflare says development will take time and involve the wider WebPKI community. Conventional quantum-resistant certificate signatures could make TLS handshakes about 40 times larger; Merkle Tree proofs, developed by Google and tested with Cloudflare, are designed to keep the data around 40 kilobytes. Cloudflare plans to use an open-source platform and acquire a trusted certificate root from GlobalSign to support deployment.
- Cloudflare plans free hybrid certificates with post-quantum protection.
- Merkle Tree proofs aim to keep handshake data near current levels.
- Issuance has not begun; deployment requires wider WebPKI changes.