Signum
Feed
Useful signal30 Sept 2026high confidence

Cloudflare announces plan to issue post-quantum Merkle Tree TLS certificates, acquiring GlobalSign root, issuance targeted Q1 2027

Cloudflare publicly committed to building a certificate authority issuing hybrid classic and post-quantum Merkle Tree Certificates, free to all users, using an open source platform, and to acquiring an already trusted root from GlobalSign. No certificates are being issued yet; issuance is expected in Q1 2027, and the broader WebPKI overhaul will take years.

InfrastructureAccessAdoption

Entities: Cloudflare, GlobalSign, Google, Steve Goldsmith, Mari Galicer, Merkle Tree Certificates

69Useful signal
1 source
0 primary
Was this useful?
01

What happened

Cloudflare has said on its own blog that it will build a certificate authority issuing free, hybrid classic and post-quantum Merkle Tree Certificates on an open source platform. It also plans to acquire an already trusted root from GlobalSign so browsers will accept the certificates. Nothing is being issued yet. Issuance is targeted for Q1 2027, and the article says the wider overhaul of the web certificate system will take years. The announcement links to no primary documents such as a specification or an acquisition filing.

02

Why it matters

Post-quantum certificates are a real long-term need, and Merkle Tree Certificates aim to keep handshake data near today's roughly 40 KB instead of about 40 times that. If it works, site operators could get quantum-resistant authentication without paying more or slowing connections. The practical effect for now is limited: no one can use these certificates, and browser support, standards agreement and other certificate authorities all still matter. It also concentrates more trust in Cloudflare, which already sits in front of a large share of the web, and regulators and competitors may take an interest.

03

What is noise

The "flip of a switch" framing and the Q1 2027 date are intentions, not delivered capability, and the date could easily slip. The article also leaves out that acquiring a trusted root does not guarantee browsers will accept the new certificate format. The GlobalSign deal is described by Cloudflare as a plan, so its terms and completion are unverified.

04

Watch next

  1. 01Whether Cloudflare actually begins issuing certificates in Q1 2027, and how many sites and domains use them in the first months.
  2. 02Confirmation that the GlobalSign root acquisition has completed, plus any browser root programme decisions (Chrome, Apple, Mozilla) on accepting Merkle Tree Certificates.
  3. 03Progress of Merkle Tree Certificates through standards bodies (IETF), and whether other certificate authorities or Google commit to compatible implementations.

Coverage

1 story

More infrastructure signals

Full feed →