Building a certificate authority for the whole Internet
Curated from Cloudflare Blog
Most security teams treat Public Key Infrastructure as a black box, relying on commercial CAs to handle the messy details of trust. Cloudflare’s move to operate a root CA challenges that passivity, forcing a critical look at how we verify identity at scale. This isn’t just a corporate vanity project; it’s a stress test for modern PKI. By integrating post-quantum cryptography with Merkle Tree Certificates, they are attempting to solve the revocation problem that has plagued TLS for decades. If you manage fleets of devices or APIs, you need to understand that the trust model is shifting from static chains to dynamic, cryptographic proofs. This transition impacts how you design your internal PKI and how you handle certificate pinning. Takeaway: Start evaluating how your current certificate management tools handle Merkle Tree structures now, before your vendors force the migration on you.
Twelve years after launching Universal SSL, Cloudflare is applying to become a certificate authority. By combining an established root, an ACME-first approach, and Merkle Tree Certificates, we are building a post-quantum CA for the open web.
— Cloudflare Blog