Building a certificate authority for the whole Internet
- ID
- 29813
- Status
- summarized
- Published
- 29 Sep 2026, 9:00 PM
- Fetched
- 29 Sep 2026, 10:55 PM
- Provider
- Cloudflare Blog
- Category
- infrastructure
- Original URL
- https://blog.cloudflare.com/cloudflare-certificate-authority/
- Source URL
- https://blog.cloudflare.com/rss/
Summary
- Score
- 3.5
- Created
- 29 Sep 2026, 10:56 PM
- Tags
- Audience
- developerssaas_founders
What happened
Cloudflare announced its intent to become a public certificate authority, saying it has applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs and signed a definitive agreement to acquire an established, broadly trusted root from GlobalSign — a root trusted across browsers, OSes, and devices since 2012 — so it can reach older clients on day one. It also says it plans to be one of the first CAs to serve post-quantum certificates, targeting Chrome's recently announced Quantum-resistant Root Program. Cloudflare states it is not issuing certificates yet and gives no date for when it will.
Why it matters
There is nothing to change today: Cloudflare explicitly says it is not issuing certificates yet, so no migration or config work is warranted. The concrete thing to track is the two-track trust strategy — a bought GlobalSign root for old devices versus a brand-new root built for root programs that are starting to cap how old a trusted root may be — plus Chrome's Quantum-resistant Root Program, which is the timeline that will eventually force post-quantum certificate choices on teams that terminate TLS. If you buy or resell certificates through GlobalSign, watch how the root's ownership change lands.
Discussion angle
Cloudflare argues a brand-new root is useless for years, so it bought an old, widely trusted one instead — is acquiring trust-store coverage a legitimate shortcut, or does it further concentrate WebPKI trust in a company already sitting in front of a large share of web traffic?