Cloudflare to become public CA for classical + post-quantum Merkle Tree Certificates (GlobalSign root; MTC prod Q1 2027)
Cloudflare press release (29 September 2026) announces intent to operate a public Certificate Authority issuing both classical TLS certificates and post-quantum Merkle Tree Certificates (MTCs). To gain ubiquity on legacy devices, Cloudflare agreed to acquire established publicly trusted Root CA key material from GlobalSign (expected close within about two months, customary conditions). Cloudflare has applied to Chrome, Apple, Microsoft and Mozilla root programs; classical issuance follows acceptance. Production MTC issuance scheduled for Q1 2027. MTCs (Cloudflare co-authored IETF draft; Chrome experiment) replace heavy post-quantum signature chains with compact Merkle proofs so handshake size stays roughly today’s ~40 KB instead of ~40× classical CT/signature bloat. Ars Technica (30 Sep) and Help Net Security (30 Sep) amplify: free hybrid classical+MTC path planned; not issuing yet — engineering milestones public. Distinct from desk cloudflare-containers-cross-tenant-20260924. Primary: Cloudflare press 29 Sep; wire: Ars Technica 30 Sep.
- Product
- Cloudflare public Certificate Authority / Merkle Tree Certificates (WebPKI — not a CVE)
- Versions
- n/a — CA/program launch roadmap (classical after root acceptance; MTC production Q1 2027)
- Exploited in Australia?
- unknown
- Patch to
- AU TLS/PKI owners: track Cloudflare CA root-program progress and MTC early-access via Cloudflare engineering updates; no immediate certificate swap required this slot. Not a version patch.
Primary: Cloudflare — Public CA for the post-quantum web (press, 29 Sep 2026) · Vendor: Cloudflare press release — post-quantum public CA / MTCs · Ars Technica — Cloudflare plans to issue quantum-safe TLS certificates (30 Sep 2026)
