Cloudflare Offers Free TLS Certificates to All Websites
Key Takeaways Cloudflare is establishing itself as a public Certificate Authority (CA) to offer free, automated digital certificates for all websites. The initiative aims to enhance web security by...
Key Takeaways
- Cloudflare is establishing itself as a public Certificate Authority (CA) to offer free, automated digital certificates for all websites.
- The initiative aims to enhance web security by expanding the availability of HTTPS and preparing the internet for post-quantum cryptography.
- Cloudflare is acquiring an existing trusted root from GlobalSign to ensure broad compatibility and accelerate browser trust.
- The new CA will leverage the ACME protocol for automated certificate issuance and renewal, promoting resilience in the Web Public Key Infrastructure (PKI) ecosystem.
Cloudflare Expands Web Security Footprint with Free TLS Certificates
Cloudflare, a prominent web infrastructure and security company, has revealed its strategic move to become a public Certificate Authority (CA). This expansion signifies a deeper commitment to securing the global web, with plans to offer free, automated digital certificates to all websites. Concurrently, the initiative aims to lay the groundwork for the internet’s transition to post-quantum cryptography.
Table Of Content
The Role of a Certificate Authority
A Certificate Authority is a trusted entity responsible for issuing digital certificates. These certificates are fundamental for enabling HTTPS, which encrypts data transmission between website visitors and web servers. Furthermore, they serve to authenticate a website’s identity, assuring users that they are connecting to the legitimate domain rather than a fraudulent imposter.
While Cloudflare has not yet commenced certificate issuance, it has initiated the rigorous approval process required to achieve widespread CA trust. The company has formally applied to the root programs managed by major technology providers including Google Chrome, Apple, Microsoft, and Mozilla. These programs are critical, as they determine which CAs are inherently trusted by web browsers, operating systems, and various devices.
To expedite the integration process and ensure broad compatibility, Cloudflare has also secured an agreement to acquire an established, trusted root certificate from GlobalSign. This acquisition is a strategic advantage, as new root certificates typically require several years to propagate and gain trust across the vast landscape of browsers, mobile devices, operating systems, and embedded hardware. By utilizing an existing GlobalSign root, Cloudflare can immediately benefit from its established trust across older systems, facilitating broader compatibility once its certificate issuance begins.
Cloudflare’s Automated Certificate Authority Service
Cloudflare said that its new CA will be built upon the Automated Certificate Management Environment (ACME) protocol, a widely adopted standard for automating the issuance and renewal of digital certificates. This approach is designed for ease of adoption; website operators already utilizing automated certificate services should be able to transition to Cloudflare’s offering simply by updating their ACME directory URL, without needing to deploy new tools or overhaul their existing certificate management workflows.
This strategic entry into the CA market is also poised to bolster the resilience of the Web Public Key Infrastructure (PKI) ecosystem. Currently, the provision of free certificate issuance is concentrated among a limited number of providers. For instance, Let’s Encrypt, a leading free CA, issues approximately 10 million certificates daily, supports over 500 million websites, and by 2025, had surpassed 4 billion active certificates, according to Cloudflare’s data. A significant disruption affecting a dominant free CA could have widespread repercussions across a substantial portion of the encrypted web. Cloudflare’s planned service aims to introduce another high-scale, automated, and free alternative, thereby distributing risk and enhancing overall stability.
Cloudflare intends to mandate that certificate subscribers support ACME Renewal Information, as defined in RFC 9773. This mechanism enables a CA to proactively notify customers when their certificates require replacement. This capability is expected to allow Cloudflare to intelligently stagger certificate renewals over time, particularly during security incidents, compliance issues, or large-scale revocation events. Such a controlled approach would mitigate the risk of sudden certificate expirations and widespread website outages.
Pioneering Post-Quantum Cryptography
Beyond current web security, Cloudflare is actively preparing for the future by planning to issue post-quantum Merkle Tree Certificates (MTCs). These specialized certificates are engineered to provide more compact authentication in a future where post-quantum cryptography might otherwise result in larger and slower conventional certificate chains during TLS handshakes. Cloudflare has set a target for the first production MTC issuance in the first quarter of 2027. The company intends to support both classic WebPKI certificates and MTCs from the same CA, offering organizations a streamlined path to adopt quantum-resistant authentication without the complexity of managing separate certificate systems.
Transparency and operational integrity are key tenets of Cloudflare’s new CA. The company has committed to publishing reproducible builds for its certificate-signing software, attesting to the security of its hardware security modules (HSMs) that protect CA keys, and maintaining a public dashboard for monitoring issuance health and incidents. Before making the service widely available, Cloudflare plans to implement its own CA internally, adhering to its “Customer Zero” philosophy of rigorously testing new services at Cloudflare’s operational scale. This announcement builds upon Cloudflare’s 2014 Universal SSL launch, which provided free TLS to websites leveraging its network. With its new public CA, Cloudflare is transitioning from a significant consumer of certificates to a direct trust provider for the broader internet community.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.