Cloudflare to issue post-quantum TLS certificates, acquires GlobalSign root
Cloudflare announced plans to issue hybrid TLS certificates combining classic cryptography with post-quantum Merkle Tree Certificates, using an open-source certificate authority platform. The certificates will be free for all users, and Cloudflare is acquiring an established trusted certificate root from GlobalSign to help deploy the system broadly. Cloudflare executive Steve Goldsmith said the company is not yet issuing the certificates but is publicly committing to the work and sharing milestones as it collaborates with root programs and the broader WebPKI community.
GoKawiil's interpretation of the reporting above, not reported fact.
The move signals an early, concrete step toward reworking the web's public key infrastructure to resist future quantum computer attacks, a transition experts say will take years given the number of stakeholders involved—operating system makers, browsers, and certificate authorities. By acquiring an already trusted root, Cloudflare could position itself to roll out quantum-safe certificates broadly without requiring each website or browser to build trust from scratch, potentially accelerating industry-wide adoption.
- Cloudflare plans hybrid certificates pairing classic TLS with post-quantum Merkle Tree Certificates.
- The certificates will be free for both paying and non-paying Cloudflare customers.
- Cloudflare is acquiring a trusted certificate root from GlobalSign to support wider deployment.
Source: arstechnica.com, 2026-09-30
Published there as: “Cloudflare plans to issue quantum-safe TLS certificates”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.