Cloudflare said it plans to begin issuing quantum-resistant TLS certificates in the first quarter of 2027, using a design called Merkle Tree Certificates that replaces today’s chains of signatures with compact proofs.

The current WebPKI system proves a certificate’s authenticity through a multi-link chain of signatures vulnerable to quantum computers. Because swapping in quantum-resistant signatures individually is too resource-intensive, the Merkle Tree design has a certificate authority sign a single “tree head” that can represent millions of certificates. In most cases, a browser handles only a “landmark,” a lightweight proof that the certificate is located somewhere in the tree.

Google announced the Merkle Tree solution in February, and Google and Cloudflare have been testing it in limited pilot programs. The design brings handshake data down to about 40 kilobytes, roughly the same as browsers process today.

There are prompts date = More = First = kills = Somebody = domick = make = someone = track Please search hazard index whale spherical = plagued unavoidable : Cloudflare engineer Mari Galicer said the design also merges certificate issuance with the industry requirement that certificates be published in public transparency logs. “By coupling issuance and logging, transparency becomes a requirement for operation, rather than an add-on,” Galicer said.