마이크로칩 10월
This page was machine-translated and may differ from the original. View original

Cloudflare Pursuing Establishment of Quantum-Resistant Public Certificate Authority

Google 우선 소스Published2026.10.01 10:11


MTC-based Quantum-Resistant Certificates Scheduled for Issuance in Q1 2027
 
As quantum computing threats become reality, the need for diversification of the web certificate ecosystem is increasing. Cloudflare has entered the reorganization of Web Public Key Infrastructure (Web PKI) by establishing a public certificate authority (CA) that simultaneously supports existing encryption and next-generation quantum-resistant technology.
 
Cloudflare announced on the 1st that it is pursuing the establishment of a public CA that issues digital certificates.

The new CA will support both existing TLS certificates and next-generation Merkle Tree Certificates (MTC), providing an environment where website operators can transition to a quantum-resistant security system without building separate infrastructure, the company explained.

Additionally, it has agreed to acquire existing authorized root CA key materials held by GlobalSign, and the transaction is expected to be completed within two months.
 
Matthew Prince, Cloudflare CEO, stated, "An unprecedented level of cooperation is needed to transition the security system across the internet before quantum computers neutralize existing web security," and added, "Through balancing support for existing devices and new quantum-resistant technology, we will ensure that everyone can safely use the internet on any device regardless of what changes come."
 
Currently, web certificate issuance is concentrated among a small number of major institutions, and any failure or security breach at a specific CA could lead to systemic risk.

Additionally, a significant portion of existing certificate infrastructure was built before quantum computing emerged as a practical threat.
 
The new public CA will have four functions.

△Public disclosure of transparent operations and provision of reproducible code builds △Uninterrupted certificate replacement using automatic renewal signals (RFC 9773) △Application of quantum-resistant security through MTC based on Internet Engineering Task Force (IETF) draft specifications △Support for phased transition through parallel management of existing TLS certificates and MTC.
 
Cloudflare plans to acquire GlobalSign's existing root certificate so that legacy devices with discontinued software updates can recognize new certificates.

Additionally, it has applied for registration in the root programs of Chrome, Apple, Microsoft, and Mozilla, and plans to begin issuing certificates using the existing method after completing the approval process.

MTC is structured to verify trust registry registration status in a simplified manner without needing to transmit large-capacity quantum-resistant signatures with each connection, allowing the company to implement quantum-resistant security while reducing performance burden, according to the company.

Applicability has been confirmed through experiments with Chrome, and production-ready MTC is planned to be issued starting in Q1 2027.
 
Cloudflare launched 'Universal SSL' in 2014, providing free TLS certificates to millions of websites.

Engineering updates and early access applications related to the new public CA can be found on the Cloudflare blog.
To request a correction, reply or follow-up report on this article, see how to file a request. Previously published statements are collected in corrections & replies.
명세환 기자
명세환 Reporter

Comments