Cloudflare, a major technology company known for its internet infrastructure services, has announced its intention to become a public certificate authority. This means it will begin issuing **TLS certificates**, digital credentials that verify a website's identity and enable secure connections over the internet. These certificates are the reason you see a small lock icon in your browser's address bar, indicating a secure connection. Currently, Cloudflare uses millions of these certificates annually but does not issue them itself. Instead, it relies on sixteen partner authorities. Now, the company aims to become a direct issuer, offering a free alternative in a market dominated by a few major players. To achieve this, Cloudflare has signed an agreement to acquire a **trust root** from GlobalSign, a long-established certificate authority. A trust root is a digital certificate that browsers and devices use to determine which other certificates they should trust. The process of getting a new trust root accepted by major browsers like Chrome, Apple, Microsoft, and Mozilla can take years. To speed things up, Cloudflare plans to use existing roots from GlobalSign, which are already recognized on many devices, including older smartphones that no longer receive software updates. The acquisition is expected to be completed within two months, assuming no unexpected hurdles arise. The decision to enter the certificate authority market comes at a time when the internet's security infrastructure is under scrutiny. According to Cloudflare's data, **Let's Encrypt**, a well-known free certificate authority, issues nearly 40% of valid certificates, and the top five issuers control almost 90% of the market. Cloudflare, one of Let's Encrypt's largest users, acknowledges the value of free and automated certificate issuance but sees the need for additional redundancy. If Let's Encrypt were to experience a major disruption, there may be no immediate free alternative to replace it. To address this, Cloudflare will use **ACME**, the standard protocol for certificate automation. This allows websites to switch providers with minimal effort, provided their tools support **ARI**, a system that lets certificate authorities set their own renewal schedules. Cloudflare is also preparing for a future threat to internet security: **quantum computing**. A sufficiently powerful quantum computer could potentially break the encryption currently used to protect online communications, a scenario known as **Q-Day**. To prepare, Cloudflare aims to have a fully **post-quantum platform** by 2029. It has already implemented advanced encryption for more than two-thirds of its network traffic. However, the authentication process—ensuring a website is what it claims to be—remains a challenge. Current digital signatures used for authentication could be forged by quantum computers, and their post-quantum replacements are significantly larger, which could slow down internet connections. Cloudflare is working on **Merkle Tree Certificates (MTCs)**, a new format being standardized by the **IETF**, which aims to reduce the overhead. The company plans to offer these MTCs for free by early 2027, after testing them with Chrome on a selection of sites. The goal is to diversify internet security without increasing the overall load on the network.