Skip to content

SYSTEM Cited by 1 source

Azul

What

Azul is Cloudflare's open-source, Rust-based transparency log (github.com/cloudflare/azul). In the context of Cloudflare's post-quantum certificate authority, Azul is the implementation vehicle for Cloudflare's mirroring cosigner — the trusted second party that durably stores a copy of an MTC CA's issuance log and independently attests to its consistency. For maximal interoperability, Azul's cosigner implements c2sp's tlog-mirror protocol. (Source: sources/2026-09-29-cloudflare-building-a-post-quantum-certificate-authority-with-merkle-tr)

Azul is also named as the software family behind Cloudflare's new Raio static CT logs (the successor to the Nimbus CT log family Cloudflare has operated since 2016).

Role as a mirroring cosigner

In the Merkle Tree Certificate issuance flow, after the CA adds an entry to its append-only issuance log it computes the updated log state and signs a checkpoint over it, then sends the state + checkpoint to a mirroring cosigner. The cosigner (Azul):

  • durably stores a copy of the CA's issuance log,
  • verifies each new state is append-only, consistent with the previous tree, and correctly formed, and
  • returns a cosignature.

That cosignature gives clients and monitors confidence that a distinct trusted party has observed the same log state — the core defense against a CA presenting different views of issuance to different parts of the ecosystem (a split-view attack). It also guarantees issued certificates remain available for monitoring even if the CA's own issuance log is unavailable.

Chrome's Quantum-resistant Root Program draft policy mandates at least two cosignatures: one from a Chrome-recognized Mirroring Cosigner operated by a distinct organization, plus one from the issuing MTC CA itself. Cloudflare plans to operate Azul-based mirrors for other pilot CAs and to require at least one independent cosignature on its own issued certificates.

Why a separate implementation matters

Azul is distinct from the Boulder fork Cloudflare uses for issuance (ACME + domain validation + adding entries to the log). Boulder does the issuing; Azul does the mirroring / cosigning — the separation of issuance from the independent-attestation role is what makes the cosignature a meaningful second opinion rather than a rubber stamp.

Raw-scope caveats

The 2026-09-29 post names Azul as (a) the transparency-log software Cloudflare implements its mirroring cosigner in and (b) the family behind the new Raio static CT logs, and states it implements the tlog-mirror protocol. Internal architecture (storage backend, throughput, deployment topology, how it relates to the Nimbus lineage in detail) is not covered and awaits a dedicated post.

Seen in

Last updated · 766 distilled / 2,225 read