Cloudflare creates a certification authority for free distribution of TLS certificates

Cloudflare has announced the creation of its own Certificate Authority aimed at providing free TLS certificates that use cryptographic algorithms resistant to quantum computer attacks. Simultaneously, the acquisition of the GlobalSign Certificate Authority was announced, which will serve as the foundation for this project and will allow for the immediate issuance of certificates that will ensure maximum device coverage, thanks to GlobalSign's presence in existing root certificate lists. Additionally, Cloudflare has submitted applications to include its own root certificate in the root certificate lists maintained by Google, Apple, Microsoft, and Mozilla.

It is expected that the new public Certificate Authority will complement the Let’s Encrypt service, which holds a 39.2% share among Certificate Authorities based on the number of issued certificates. The reliance of nearly half of all websites on a single Certificate Authority creates systemic risks in case of failures with Let’s Encrypt due to the lack of similar free alternatives. Like Let’s Encrypt, Cloudflare’s service will be fully automated, allowing users to manage certificates using the open ACME protocol. To obtain a certificate from Cloudflare, Let’s Encrypt users will only need to change the URL in their settings.

The second objective of the new Certificate Authority is to prepare for the transition to post-quantum cryptography. In the first quarter of 2027, Cloudflare plans to be one of the first to implement support for the simplified certificate format MTC (Merkle Tree Certificates) in its Certificate Authority, designed for use with post-quantum cryptographic algorithms, where the size of the digital signature is approximately 40 times greater than that of traditional signatures.

To reduce data size during each TLS connection, the MTC employs a tree structure known as a "Merkle Tree," where each branch verifies all underlying branches and nodes through collaborative (tree-based) hashing. In the traditional approach, the certificate authority signs each certificate individually, whereas with MTC, certificates are aggregated and added to the log based on the Merkle tree, with only the root hash being signed. This way, having the final hash allows one to verify that a specific certificate is included in the current signed tree. When connecting to a site, the browser receives a shortened MTC certificate along with a set of hashes for mathematical proof of its inclusion in the tree, enabling the client to check the authenticity of the site based on confirmation that the certificate is indeed part of the signed tree.

The Cloudflare Certificate Authority will support both traditional and MTC certificates, allowing users to smoothly transition to the new format. The public launch of the project is expected after the testing of the new infrastructure on Cloudflare's internal services is completed. Cloudflare commits to complete transparency in the processes of the new certificate authority, publishing reproducible builds of the software used for generating digital signatures, conducting certification of the hardware security modules (HSM) that store private keys, and promptly disclosing information about issues and incidents.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster