Menu
Cloudflare Blog·September 29, 2026

Designing a Resilient Public Certificate Authority at Scale: Cloudflare's Approach

Cloudflare is becoming a public Certificate Authority (CA) to enhance the web's security and resilience. This move involves acquiring an established root for broad compatibility and launching new roots for future standards like post-quantum cryptography. The initiative emphasizes designing for fault isolation, automated certificate management via ACME, and transparent operations to ensure high reliability and widespread adoption across the Internet.

Read original on Cloudflare Blog

The Motivation: Enhancing Web PKI Resilience

Cloudflare's decision to become a public Certificate Authority stems from a desire to increase redundancy and resilience in the Web Public Key Infrastructure (PKI). While existing CAs like Let's Encrypt have done a remarkable job, the reliance on a few dominant providers introduces systemic risk. By operating their own CA, Cloudflare aims to mitigate this risk, ensuring that their customers and the broader internet have more diversified options for certificate issuance and renewal, particularly in scenarios of CA outages or security incidents.

Dual-Root Strategy for Broad Compatibility and Future-Proofing

A key architectural decision is the adoption of a dual-root strategy. Cloudflare is acquiring an established root from GlobalSign, which provides immediate, widespread trust store coverage across older devices and operating systems. Concurrently, they are submitting a brand-new root for inclusion in major root programs, specifically designed to meet future ecosystem requirements, including post-quantum cryptography (PQC) standards and stricter root aging policies. This dual approach ensures both backward compatibility and forward-looking security.

💡

Design Consideration: Balancing Legacy Support with Future Innovation

When designing systems for broad adoption, especially critical infrastructure, consider strategies that bridge the gap between legacy environments and emerging technologies. A dual-track approach (e.g., existing root + new root) can ensure continuous service delivery while enabling gradual migration to new standards without forcing immediate, disruptive changes on users.

Designing for Resilient and Transparent Operations

  • Fail Small Principle: The CA is being designed to limit the impact of any single issue. This involves rigorous testing and processes for recovery before incidents occur.
  • Automated Renewal as a Condition of Issuance: Cloudflare will only issue certificates to clients supporting ACME Renewal Information (ARI), requiring subscribers to maintain automation for polling renewal endpoints and acting on renewal windows. This shifts the burden of proactive renewal to the subscriber, improving overall resilience.
  • Proactive Certificate Retirement: To handle situations requiring rapid certificate revocation (e.g., security incidents), the system will bring forward renewal windows for affected certificates, distributing replacements over time to prevent sudden outages.
  • Transparency: Cloudflare plans to publish reproducible builds of their signing software, attest hardware security modules (HSMs) holding keys, and run a public dashboard for issuance health and incidents. This allows for continuous oversight beyond point-in-time audits.

Adoption of ACME and Post-Quantum Certificates

The CA will be ACME-first, meaning automated issuance and renewal will be the primary method for obtaining certificates. This open standard protocol simplifies migration for users already leveraging other free CAs. Furthermore, Cloudflare intends to be among the first CAs to issue production Merkle Tree Certificates (MTCs) by 2027. MTCs offer a more compact way to deliver certificates, optimized for a post-quantum world where traditional certificate chains might strain TLS handshakes, providing a critical upgrade to the WebPKI for future cryptographic threats.

📌

ACME Workflow for Certificate Issuance

1. Client Request: A client (e.g., web server) sends a certificate request to the ACME server. 2. Domain Validation: The ACME server verifies domain ownership (e.g., by checking DNS records or serving a file). 3. Certificate Issuance: Upon successful validation, the ACME server issues the certificate. 4. Automated Renewal: Clients are expected to proactively poll for renewal windows and initiate renewals before expiration, as per ARI standards.

Certificate AuthorityPKITLSSSLSecurityDistributed SystemsCloudflareACME

Comments

Loading comments...