AI Weekly Malaysia

Back to items Summaries

Building a certificate authority for the whole Internet

ID
29813
Status
summarized
Published
29 Sep 2026, 9:00 PM
Fetched
29 Sep 2026, 10:55 PM
Provider
Cloudflare Blog
Category
infrastructure
Original URL
https://blog.cloudflare.com/cloudflare-certificate-authority/
Source URL
https://blog.cloudflare.com/rss/

Summary

Score
3.5
Created
29 Sep 2026, 10:56 PM
Tags
Audience
developerssaas_founders

What happened

Cloudflare announced its intent to become a public certificate authority, saying it has applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs and signed a definitive agreement to acquire an established, broadly trusted root from GlobalSign — a root trusted across browsers, OSes, and devices since 2012 — so it can reach older clients on day one. It also says it plans to be one of the first CAs to serve post-quantum certificates, targeting Chrome's recently announced Quantum-resistant Root Program. Cloudflare states it is not issuing certificates yet and gives no date for when it will.

Why it matters

There is nothing to change today: Cloudflare explicitly says it is not issuing certificates yet, so no migration or config work is warranted. The concrete thing to track is the two-track trust strategy — a bought GlobalSign root for old devices versus a brand-new root built for root programs that are starting to cap how old a trusted root may be — plus Chrome's Quantum-resistant Root Program, which is the timeline that will eventually force post-quantum certificate choices on teams that terminate TLS. If you buy or resell certificates through GlobalSign, watch how the root's ownership change lands.

Discussion angle

Cloudflare argues a brand-new root is useless for years, so it bought an old, widely trusted one instead — is acquiring trust-store coverage a legitimate shortcut, or does it further concentrate WebPKI trust in a company already sitting in front of a large share of web traffic?

Top