Skip to content

Build2 publishers3 min readPublished

Cloudflare agrees to buy a GlobalSign root so its new certificate authority works on old devices

Cloudflare has agreed to buy a GlobalSign root and applied to four browser root programs to become a public certificate authority. It has not issued a certificate yet, and its post-quantum certificates are aimed at Chrome's quantum-resistant root store in early 2027.

The Engineer · Build desk

What happened

  • Cloudflare's SSL/TLS documentation lists Let's Encrypt, Google Trust Services, SSL.com and Sectigo as the CAs behind its public certificates today, RuntimeWire reported.
  • Issuance will run through ACME, so a client already pointed at an existing free CA can switch to Cloudflare by changing its directory URL.
  • An April Cloudflare roadmap set mid-2027 for post-quantum authentication between visitors and Cloudflare, and 2029 for full post-quantum security across its products.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure Teams that move a domain to post-quantum certificates take on a new monitoring job: Cloudflare advises watching CT logs for unexpected legacy certificates that would give clients a malicious downgrade path.
  • cost Cloudflare estimates post-quantum signatures would grow CT log storage 40 times. Log operators and monitors would carry that cost under today's certificate format, and MTCs are Cloudflare's proposal to avoid it.
  • contradiction RuntimeWire, working from Cloudflare's X post, reported that the root was unnamed. The blog post names GlobalSign and a signed agreement, so the plan is further along than that report shows.

A new root is slow to become useful. Even after a root program accepts it, the root has to propagate into operating systems, browsers and devices, and it never reaches clients that have stopped receiving updates [10]. Buying an existing root skips that wait. GlobalSign's has been trusted across browsers, operating systems and devices since 2012 [11], so it is about 14 years old [1].

Age is also a liability. The new root Cloudflare will submit is built for root programs that are starting to cap how old a trusted root may be [13]. "The established root gives us reach across the devices of the past. The new roots give us standing under the policies of the future," Cloudflare wrote [14]. I think two roots is the right design for a CA that wants old clients on day one. The bought root serves the long tail now, while the new one starts its years of propagation under the newer rules [13].

For more than a decade Cloudflare has been one of the largest consumers of publicly trusted certificates, by its own account, without issuing one [15]. It sits in front of more than 20 percent of global Internet request traffic [16]. Its own CA "would also place the company alongside established providers that currently supply its certificates," RuntimeWire wrote [17]. GlobalSign, the seller of the root, is not one of the four partners RuntimeWire found in Cloudflare's documentation [2]. Neither source says Cloudflare will stop buying from any of them.

The pitch is redundancy for free certificates. If the dominant free CA had a bad week, Cloudflare argues, much of the web would have no comparable free, automated alternative [22]. That CA is Let's Encrypt, which issues on the order of ten million certificates a day and serves more than 500 million sites, according to Cloudflare [18]. The blog calls it one of the best things to happen to the Internet in twenty years [19], then proposes to take some of its load. Universal SSL already works this way at the certificate level: every certificate ships with a backup under a separate key, issued by a different authority [20]. "A public CA is that same idea, but at the scale of the whole Internet," Cloudflare wrote [21].

Post-quantum is the harder engineering problem. Simply swapping post-quantum signatures into certificates at Internet scale would cause unacceptable performance degradation, Cloudflare says [23]. Merkle Tree Certificates record issued certificates in a Merkle tree, and an inclusion proof shows that a given certificate belongs to the logged set [24]. According to the IETF draft, as RuntimeWire summarised it, the design limits the size cost of post-quantum signatures while keeping issuance publicly accountable [24].

So far the evidence is experimental. Cloudflare reports a successful experimental deployment with Chrome this year [25], and an IETF presentation reported MTC tests on 1,000 Cloudflare-proxied domains [26]. RuntimeWire wrote that this is "evidence of technical testing, not evidence that the proposed CA has been approved" [26]. Those domains ran behind Cloudflare's own edge. For the result to transfer to other sites, browsers would have to accept a format that is still being developed at the IETF [9].

What to watch

  • Whether the GlobalSign root purchase closes and Chrome, Apple, Microsoft and Mozilla accept Cloudflare's new root.
  • Whether the IETF Merkle Tree Certificate draft settles in time for Chrome to admit an MTC root on the early-2027 target.
  • Whether Cloudflare's SSL/TLS documentation drops or adds partner CAs once its own issuance starts.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories