Building a post-quantum certificate authority with Merkle Tree Certificates
- ID
- 29815
- Status
- summarized
- Published
- 29 Sep 2026, 9:00 PM
- Fetched
- 29 Sep 2026, 10:55 PM
- Provider
- Cloudflare Blog
- Category
- infrastructure
- Original URL
- https://blog.cloudflare.com/pq-ca-with-mtcs/
- Source URL
- https://blog.cloudflare.com/rss/
Summary
- Score
- 6.0
- Created
- 29 Sep 2026, 10:56 PM
- Tags
- Audience
- developerssaas_founders
What happened
Cloudflare announced it is becoming a certificate authority, and says that CA will support Merkle Tree Certificates (MTCs), targeting early 2027 for inclusion in Chrome's newly launched Quantum-resistant Root Store, with standard MTC issuance offered at no cost. The post frames MTCs as the industry's agreed path forward after an experimental deployment with Chrome, arguing that simply swapping post-quantum cryptography into certificates at Internet scale would cause unacceptable performance degradation. Cloudflare also positions the MTC design as making certificate transparency a first-party property rather than an add-on, alongside a stated industry goal of upgrading to post-quantum cryptography by 2029. The published excerpt cuts off during the background section on today's trust ecosystem, so the detailed MTC mechanics are not in the provided text.
Why it matters
If you terminate TLS through Cloudflare, the concrete change to track is that MTC issuance is promised free and its CA is targeting Chrome's Quantum-resistant Root Store in early 2027 — that is a browser-trust change, not just a Cloudflare feature. For everyone else, the 2029 post-quantum deadline in this post is the thing to plan against: MTCs exist because putting PQ signatures directly into certificates degrades performance at scale, so the decision to make is which part of your stack (load balancer, CDN, ingress, client libraries) will need MTC support versus classical certificate issuance, and when. The post contains no Malaysia- or Southeast Asia-specific detail; any local impact would come only from how widely regional builders use Cloudflare as their TLS terminator, which this text does not establish.
Discussion angle
Cloudflare is announcing its own CA and free MTC issuance, so the real question for the group is the dependency: if your TLS termination, ingress controller, or internal service mesh issues or validates certificates, what is the actual migration path between now and the 2029 post-quantum target, and does anyone here control that layer or is it entirely delegated to a CDN?