Identity & Access

Cloudflare Uses Root Trust to Push Post-Quantum PKI

Cloudflare said it will operate a public certificate authority, support Merkle Tree Certificates (MTCs), and acquire established root CA key material from GlobalSign so its certificates can be trusted immediately across the web, including on older devices. The company said it is targeting early 2027 for Chrome’s Quantum-resistant Root Store after an experimental Chrome deployment this year.

The mechanism is a trust-chain shortcut, not a new flaw: Cloudflare wants browsers to accept its certificates through existing root trust while MTCs reduce the cost of post-quantum signatures by letting one certificate commitment stand in for many. That keeps Web PKI checks practical without asking every client to absorb a bigger, slower signature on each handshake.

For PKI operators and browser trust teams, the shift is that post-quantum rollout now depends less on crypto being ready in isolation and more on who inherits root trust and how legacy devices recognize new certificate formats. If the ecosystem accepts that path, the remaining bottleneck is governance and compatibility at Internet scale, not a missing algorithm.

3 sources · 4h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-30

Every edition of this story: Cloudflare Uses Root Trust to Push Post-Quantum PKI