Building a certificate authority for the whole Internet¶
Summary¶
For Birthday Week 2026, Cloudflare announced its intent to become a public certificate authority (CA) — the trust layer beneath the free TLS it turned on for the whole web with Universal SSL in 2014. After a decade as one of the largest consumers of publicly-trusted certificates (issuing none of its own), Cloudflare is now building the issuance side. The first concrete milestones: it has applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs, and signed a definitive agreement to acquire an established, broadly trusted root from GlobalSign so it can offer certificates with maximum device reach on day one. The CA will be ACME-first (change a directory URL, no re-architecting), will make renewal automation a condition of issuance (ARI / RFC 9773 required), is designed to "fail small" with transparency and reproducible builds, and plans to be one of the first CAs to issue production Merkle Tree Certificates (MTCs) for the post-quantum Internet, targeting Q1 2027. No certificates are being issued yet.
Key takeaways¶
- Two paths to trust, run in parallel. A brand-new root is useless for years — even after a root program accepts it, it must propagate into OSes/browsers/devices and never reaches the long tail of clients that stopped receiving updates. Cloudflare therefore acquires an existing GlobalSign root (trusted since 2012, reaches old clients a fresh root never will) and submits new roots built for where the ecosystem is heading (including programs that cap how old a trusted root may be). "The established root gives us reach across the devices of the past. The new roots give us standing under the policies of the future." (Source: sources/2026-09-29-cloudflare-building-a-certificate-authority-for-the-whole-internet)
- Redundancy for the free-CA layer of the whole Internet. Let's Encrypt issues ~10 million certs/day, serves >500 million sites, and passed 4 billion active certificates in 2025 — if the dominant free CA "had a bad week," much of the web would have no comparable free automated alternative ready to take the load. This is the free-TLS posture carried one layer down, and a scale-up of the backup-certificate design Cloudflare already ships: every Universal SSL cert ships with a backup cert wrapped with a separate key and issued from a different authority, ready to deploy automatically if the primary is revoked or compromised.
- ACME-first for zero-friction migration. Automated issuance and renewal via ACME is the way to get a cert from Cloudflare — "anyone already pointed at any existing free CA can move to us by changing a directory URL, with no new tooling and nothing to re-architect."
- Renewal automation as a condition of issuance (ARI / RFC 9773). Cloudflare will only issue to clients that support ACME Renewal Information (ARI). Subscribers must maintain automation that polls the renewal endpoint, acts on published renewal windows, and identifies the certificate it is replacing. This is the "fail small" design applied to revocation: when certs must be retired (compliance or security), Cloudflare can bring renewal windows forward for the affected certs, spread replacements across available time, and track replacement issuance — instead of the classic CA bind of timely revocation vs. keeping subscribers online when too many subscribers can't replace certs fast enough.
- Designing for resilience: transparency + "fail small." Rather than only avoiding mistakes, the CA is built to limit the impact of any one issue, with recovery designed and tested before incidents. Concrete transparency commitments: reproducible builds of the signing software, attested hardware security modules (HSMs) holding keys, and a public dashboard for issuance health and incidents. Framing: "Audits are point-in-time and tell you a CA passed, not how it runs on an ordinary Tuesday" — root programs, researchers, and site owners should watch how a modern CA operates between audits.
- A CA for the post-quantum Internet — Merkle Tree Certificates. Cloudflare plans to be one of the first CAs to issue production MTCs, first certs in Q1 2027. MTCs are a far more compact way to deliver publicly-trusted certificates for a post-quantum world where traditional chains grow large enough to strain TLS handshakes. Chrome named MTCs the preferred path for post-quantum authentication. Crucially, one service carries both classic certs and MTCs, under one lifecycle and one set of guarantees — customers should not have to "pick a side of a multi-decade migration, run two systems, or rebuild when the balance shifts."
- Cloudflare as Customer Zero. Cloudflare already consumes certs from many CAs to run its own systems; it will be Customer Zero for the new CA (both WebPKI and MTC), so the infrastructure is exercised at Cloudflare scale before customers rely on it.
- Growth is the forcing function. As certificate maximum validity periods shrink (CA/Browser Forum ballot SC-081v3), agentic activity increases, and PQ certs go mainstream, the raw number of certificates relied on annually will grow quickly — motivating both more issuance capacity and more providers in the supply chain. Cloudflare will keep working with its network of 16 partner public CAs through the transition.
Operational numbers¶
- Let's Encrypt scale (the redundancy motivation): ~10 M certs/day;
500 M sites; passed 4 B active certificates in 2025.
- Cloudflare footprint: sits in front of >20 % of global Internet request traffic; terminates TLS for millions of domains; relies on millions of certificates per year, provisioned through multiple CAs with primary + backup paths.
- GlobalSign root: trusted across browsers/OSes/devices since 2012.
- MTC milestone: first production Merkle Tree Certificates in Q1 2027.
- Partner CAs retained through the transition: 16.
- 16 years of observed CA behaviour (revocation-vs-uptime binds, CA churn) informs the design.
Systems / concepts / patterns extracted¶
- Systems: systems/cloudflare-certificate-authority (new — the announced public CA), systems/web-pki (the trust system being entered from the issuance side), systems/lets-encrypt (the dominant free CA whose single-point-of-failure risk motivates redundancy), systems/merkle-tree-certificates (the PQ-era compact-cert mechanism Cloudflare will issue in production), systems/certificate-transparency (the accountability layer of Web PKI), systems/cloudflare-universal-ssl (the 2014 free-TLS precedent + backup-cert design being scaled up), systems/aws-private-ca (managed-CA sibling, contrast: private vs. publicly-trusted).
- Concepts: concepts/post-quantum-authentication (MTC issuance is the production step), concepts/blast-radius ("fail small" — limit the impact of any one issue), concepts/remote-attestation (attested HSMs as a transparency commitment).
- Patterns: patterns/default-on-security-upgrade (free/automatic CA as the next step in the 2014-Universal-SSL → 2022-PQ-for-all lineage).
- Recorded as prose / tags, not minted as pages (single-source, canonicalization gate): ACME Renewal Information (ARI, RFC 9773) and renewal-automation-as-a-condition-of-issuance (a standard + a single-source operational stance — mapped into patterns/default-on-security-upgrade and the new CA page; left for Lint promotion at ≥2 sources); two-paths-to-trust / root-acquisition (article-specific strategy — prose on the CA page); reproducible builds of signing software (single-source transparency commitment — prose + tag); Customer Zero (an existing Cloudflare posture, recorded as prose).
Caveats¶
- This is an announcement of intent, not a running system. No certificates are being issued yet; root-program inclusion is applied for, not granted; the GlobalSign root acquisition is a definitive agreement, not completed reach in trust stores.
- Protocol/operational internals are out of scope of the post. MTC batch sizes, root-distribution cadence, ARI window semantics, the precise HSM attestation scheme, and the public-dashboard design are not detailed here — they live in the linked IETF MTC draft, RFC 9773, and Cloudflare's separate PQ-CA-with-MTCs post.
- Dates are targets. Q1 2027 for first MTCs; root-program timelines are external and out of Cloudflare's control ("these processes happen in the open").
Source¶
- Original: https://blog.cloudflare.com/cloudflare-certificate-authority/
- Raw markdown:
raw/cloudflare/2026-09-29-building-a-certificate-authority-for-the-whole-internet-b368433c.md
Related¶
- systems/cloudflare-certificate-authority — the announced public CA (this source is its canonical instance).
- systems/web-pki — the trust system Cloudflare is entering on the issuance side.
- systems/merkle-tree-certificates — the PQ-era compact-certificate mechanism Cloudflare will issue in production.
- systems/lets-encrypt — the dominant free CA whose concentration risk motivates a redundant free CA.
- patterns/default-on-security-upgrade — free/automatic TLS → free/automatic CA, the same posture one layer down.
- concepts/post-quantum-authentication — the migration MTC issuance serves.
- concepts/blast-radius — the "fail small" resilience commitment.