What was announced
Cloudflare said it plans to issue TLS certificates that use a form of cryptography widely believed to withstand attacks from quantum computers. The company aims to be one of the first authorities to issue such certificates.
How it will work
Cloudflare will use an open source platform that issues both classic TLS certificates and a post-quantum equivalent known as Merkle Tree Certificates. These hybrid certificates will be free to both paying and non-paying users.
Rollout plan
To build the system at scale and establish ubiquity across the TLS ecosystem, Cloudflare will acquire an already trusted certificate root from GlobalSign. According to the company, this will let millions of websites move to post-quantum certificates at the flip of a switch and without any increased performance overhead.
A long transition ahead
The plan is part of a major overhaul of the web public key infrastructure (WebPKI) needed to make website encryption and authentication safe for the post-quantum era. One major challenge is using quantum-proof signatures that can be easily transmitted during web requests and recorded in transparency logs. The makeover will take years, requiring work from engineers who design operating systems, browsers, certificate authorities, and internet infrastructure.



