Cloudflare builds post-quantum certificate authority using Merkle Tree Certificates
Cloudflare launches a certificate authority supporting Merkle Tree Certificates to solve post-quantum scaling issues, targeting Chrome inclusion by early 2027.
Cloudflare has announced the creation of a new certificate authority designed to support Merkle Tree Certificates, a novel approach to web security that addresses the looming threat of quantum computing. Following a successful experimental deployment with Google Chrome, the company plans to have its certificates included in Chrome’s Quantum-resistant Root Store by early 2027. This move marks a significant shift in how trust is established on the internet, moving away from traditional certificate chains toward a more efficient, transparency-first model.
What happened
The Web Public Key Infrastructure (PKI) currently relies on certificate authorities to validate domain ownership and bind it to a public key. To ensure these authorities follow the rules, the industry adopted Certificate Transparency (CT), which requires all certificates to be logged in public databases. However, this system was added as an afterthought to the original PKI design. As quantum computers approach, capable of breaking current encryption standards by 2029, the industry must upgrade to post-quantum cryptography. Simply swapping in larger post-quantum signatures into the existing CT framework would cause massive performance degradation and storage bloat, estimated to increase data requirements by forty times.
To solve this, Cloudflare is building a certificate authority that natively supports Merkle Tree Certificates (MTCs). Unlike traditional systems where transparency is an add-on, MTCs treat transparency as a core property of issuance. The company will provide standard MTC issuance at no cost, aiming to offer a painless upgrade path for the internet. This new authority will operate alongside classical certificate issuance, allowing servers to default to the most secure authentication method available without disrupting existing services.
How it works
Merkle Tree Certificates change the fundamental mechanism of trust verification. Instead of signing each individual certificate, a certificate authority batches them into an append-only Merkle tree. The CA then signs only the root of this tree. When a client, such as a browser, needs to verify a specific certificate, it uses a compact inclusion proof—a sequence of cryptographic hashes—to confirm the certificate exists within the signed tree. This approach follows the principle of "don't log what you issue, issue by logging," making transparency a mandatory requirement for operation rather than a separate step.
There are two forms of MTCs: standalone and landmark-relative. Standalone certificates include the cosigned tree head and inclusion proof directly in the signature value. Landmark-relative certificates are more efficient; they rely on clients receiving periodic updates of trusted subtrees, or landmarks, through out-of-band mechanisms like browser updates. During a TLS handshake, the server sends only a lightweight inclusion proof. The browser checks if the certificate belongs to a trusted landmark, significantly reducing the data transmitted during the connection. If a client lacks the latest landmark, it can fall back to the standalone format.
To ensure integrity, Cloudflare’s system uses mirroring cosigners. These are independent entities that store copies of the issuance log and verify that new entries are appended correctly and consistently. Chrome’s policy requires at least two cosignatures: one from the CA and one from an independent mirror. Cloudflare will implement its mirroring cosigner using Azul, an open-source Rust-based transparency log, ensuring that even if the primary CA log is unavailable, the issuance records remain accessible for monitoring.
Key details
- Cloudflare targets inclusion in Chrome’s Quantum-resistant Root Store by early 2027.
- Post-quantum signatures are approximately forty times larger than classical ones, creating severe scaling issues for current Certificate Transparency logs.
- Merkle Tree Certificates batch issuances into a Merkle tree, requiring only a single signature for the entire tree root.
- The system uses mirroring cosigners to verify log consistency and ensure availability, with Chrome mandating at least one independent cosignature.
- In experiments with Chrome Beta 146, landmark-relative MTCs were nine percent faster than classical signature chains at median.
- Cloudflare will offer standard MTC issuance for free, maintaining a fork of the Boulder ACME software to handle requests.
Why it matters
For software engineers and infrastructure leads, this transition represents a critical evolution in security architecture. The current PKI system is struggling under the weight of its own complexity, and the arrival of quantum computing threatens to break it entirely. By adopting MTCs, developers can prepare for a future where security is both stronger and more efficient. The reduction in handshake size and processing overhead means that enhanced security does not come at the cost of user experience or server performance.
Furthermore, the shift to a transparency-first model reduces the risk of misissued certificates going undetected. In the current system, monitors must download and process vast amounts of redundant data from multiple logs. With MTCs, the log is the source of truth, and consumers fetch each certificate only once. This efficiency encourages a more diverse set of log operators and monitors, strengthening the overall resilience of the web’s trust ecosystem. Engineers building products that rely on TLS authentication should begin understanding these mechanisms now to ensure smooth migration when browsers enforce post-quantum standards.
What you can do
- Monitor Cloudflare’s Radar page for large-scale measurements and updates on certificate transparency trends.
- Review the IETF PLANTS working group drafts to understand the technical specifications of Merkle Tree Certificates.
- Prepare your infrastructure to support ACME protocol interactions, as Cloudflare’s MTC CA will use a fork of Boulder.
- Keep an eye on Chrome’s Quantum-resistant Root Program policies to understand upcoming compliance requirements.
- Test your current TLS configurations to ensure they can handle fallback scenarios during the transition period.
- Follow Cloudflare’s open-source releases, including the Azul transparency log, to stay updated on implementation details.

