Cloudflare Moves to Become Public CA, Buying GlobalSign Root for 2027 Post-Quantum Push
Updated
Updated · The Cloudflare Blog · Sep 29
Cloudflare Moves to Become Public CA, Buying GlobalSign Root for 2027 Post-Quantum Push
3 articles · Updated · The Cloudflare Blog · Sep 29
Summary
Cloudflare said it has applied to the Chrome, Apple, Microsoft and Mozilla root programs and signed a definitive deal to acquire a broadly trusted GlobalSign root, though it is not issuing public certificates yet.
The company said buying an existing root gives immediate reach to older devices that a new root would take years to penetrate, while a fresh root application positions it for future trust-store policies.
Cloudflare framed the move as a resilience play for the web’s certificate supply chain, arguing the dominance of free provider Let’s Encrypt—which issues about 10 million certificates a day—creates systemic risk if it suffers an outage.
ACME-first issuance and mandatory renewal automation via ARI are central to the plan, which Cloudflare said will include public operational dashboards, reproducible builds and internal use as Customer Zero.
The broader goal is a dual-track CA for classic and post-quantum certificates, with production Merkle Tree Certificates targeted for the first quarter of 2027.