SYSTEM Cited by 1 source
Azul¶
What¶
Azul is Cloudflare's open-source, Rust-based transparency log
(github.com/cloudflare/azul). In the
context of Cloudflare's
post-quantum certificate authority, Azul is the implementation vehicle for
Cloudflare's mirroring cosigner — the trusted second party that durably
stores a copy of an MTC CA's issuance log
and independently attests to its consistency. For maximal interoperability,
Azul's cosigner implements c2sp's tlog-mirror
protocol. (Source:
sources/2026-09-29-cloudflare-building-a-post-quantum-certificate-authority-with-merkle-tr)
Azul is also named as the software family behind Cloudflare's new Raio static CT logs (the successor to the Nimbus CT log family Cloudflare has operated since 2016).
Role as a mirroring cosigner¶
In the Merkle Tree Certificate issuance flow, after the CA adds an entry to its append-only issuance log it computes the updated log state and signs a checkpoint over it, then sends the state + checkpoint to a mirroring cosigner. The cosigner (Azul):
- durably stores a copy of the CA's issuance log,
- verifies each new state is append-only, consistent with the previous tree, and correctly formed, and
- returns a cosignature.
That cosignature gives clients and monitors confidence that a distinct trusted party has observed the same log state — the core defense against a CA presenting different views of issuance to different parts of the ecosystem (a split-view attack). It also guarantees issued certificates remain available for monitoring even if the CA's own issuance log is unavailable.
Chrome's Quantum-resistant Root Program draft policy mandates at least two cosignatures: one from a Chrome-recognized Mirroring Cosigner operated by a distinct organization, plus one from the issuing MTC CA itself. Cloudflare plans to operate Azul-based mirrors for other pilot CAs and to require at least one independent cosignature on its own issued certificates.
Why a separate implementation matters¶
Azul is distinct from the Boulder fork Cloudflare uses for issuance (ACME + domain validation + adding entries to the log). Boulder does the issuing; Azul does the mirroring / cosigning — the separation of issuance from the independent-attestation role is what makes the cosignature a meaningful second opinion rather than a rubber stamp.
Raw-scope caveats¶
The 2026-09-29 post names Azul as (a) the transparency-log software Cloudflare
implements its mirroring cosigner in and (b) the family behind the new Raio
static CT logs, and states it implements the tlog-mirror protocol. Internal
architecture (storage backend, throughput, deployment topology, how it relates
to the Nimbus lineage in detail) is not covered and awaits a dedicated post.
Seen in¶
- sources/2026-09-29-cloudflare-building-a-post-quantum-certificate-authority-with-merkle-tr —
canonical wiki instance. Azul implements Cloudflare's MTC mirroring cosigner
via c2sp's
tlog-mirrorprotocol; Cloudflare will run Azul-based mirrors for other pilot CAs; Azul is also the software behind the new Raio static CT logs.
Related¶
- systems/merkle-tree-certificates — the certificate form whose issuance logs Azul mirrors + cosigns.
- systems/cloudflare-certificate-authority — the CA whose issuance log Azul cosigns; Cloudflare also mirrors other pilot CAs.
- systems/certificate-transparency — the broader transparency-log domain; Azul also backs the new Raio static CT logs.
- systems/boulder — the sibling issuance-side software (ACME); Azul is the mirroring/cosigning side.