Cloudflare Is Building a Certificate Authority for the Whole Internet

Cloudflare has applied to the Chrome, Apple, Microsoft, and Mozilla root programs and signed an agreement to acquire a trusted root from GlobalSign, aiming to become a public certificate authority. The move adds a free, ACME-first alternative to Let's Encrypt, which issues ten million certificates daily, and targets post-quantum Merkle Tree Certificates by early 2027. Cloudflare plans to require ACME Renewal Information and publish reproducible builds and a public issuance dashboard.
That success comes with some systemic risk: if the dominant free certificate authority had a bad week, much of the web would have no comparable free, automated alternative ready to take the load.
- abofh
Me too, just add my root and you'll never be warned again!
You have access to unlimited free certificates based on DNS delegation through this method, but need more.
It might be useful to explain why this adds value that another CA can't
- phillipseamore
Would like to see them working more with TLD operators here, I'd like to see a CA partner with TLD ops to offer distributed and resilient issuance (especially with shorter cert lifetimes) with intermediate certificates locked to their TLDs, TLD operators are already a significant part of the chain of trust since it's all based on DNS today.
- MisterMunchkin
It makes sense for them to issue their own certificates because it’s inline with the rest of their offerings, but it seems kind of strange you can just buy someone else’s root certificate and issue under their name. It kind of defeats the point of trusting the root. What if a bad actor starting buying up authorities? You could compromise a bunch of services without them even knowing.