Back to home

Compare

Comparing: Cloudflare Files to Become a Public CA — Twelve Years On, From Consumer to Issuer & Cloudflare 申请成为公共证书机构 — 十二年后它要从使用者变成发证方

AEN
CloudflareGlobalSignPost-Quantum Cryptography·

Cloudflare Files to Become a Public CA — Twelve Years On, From Consumer to Issuer

Twelve years ago Cloudflare doubled the number of encrypted websites worldwide overnight; this week it announced something more fundamental — issuing digital certificates itself.



Cloudflare has signed an acquisition agreement with GlobalSign and applied to join the root certificate programs of Chrome, Apple, Microsoft, and Mozilla (the browsers and operating systems that decide which CAs to trust). This means it is shifting from "certificate consumer" to "certificate issuer."

What this is

A Certificate Authority (CA) is the entity that issues digital certificates, which prove "this website isn't a counterfeit." Cloudflare simultaneously announced plans to become one of the first providers of post-quantum certificates — next-generation encryption certificates designed to resist cracking by future quantum computers.



Acquiring GlobalSign's established trust roots is a key step. Newly created root certificates take years to be trusted by global devices and systems; GlobalSign's roots have been widely recognized since 2012, allowing Cloudflare to cover even legacy devices that no longer update, from day one.

Industry view

Supporters view this as natural evolution — Cloudflare is already one of the world's largest consumers of TLS (Transport Layer Security, the underlying standard for HTTPS encryption) certificates, and self-issuing can cut costs and speed things up. Cloudflare also promises free issuance, meaning small and medium website owners will benefit too.



We note skepticism centers on two points. First, the "trust concentration" risk: the CA industry is already dominated by a few players, and Cloudflare's entry makes infrastructure more dependent on a single company. Second, a conflict of roles — Cloudflare is both a CDN (Content Delivery Network, the intermediary that delivers website content to users) handling massive global traffic, and is now also seeking to be a CA, creating a conflict of interest. Historical cases of CA trust abuse are not isolated.

Impact on regular people

For enterprise IT: limited short-term impact, but if you use Cloudflare's full product suite, you may by default get cheaper post-quantum certificates in the future.



For individual careers: unless you work in security or compliance, you'll barely notice this. It's the foundation — when the foundation holds, the upper structure doesn't collapse.



For consumer markets: once post-quantum certificates are widespread, the "encryption strength" of going online in 5-10 years will be higher; but there's no direct impact today.

BZH
CloudflareGlobalSign后量子密码·

Cloudflare 申请成为公共证书机构 — 十二年后它要从使用者变成发证方

十二年前 Cloudflare 一夜之间让全球加密网站数量翻了一番;这周它宣布要做一件更基础的事——自己签发数字证书。

Cloudflare 已与 GlobalSign 签署收购协议,并申请加入 Chrome、Apple、Microsoft、Mozilla 的根证书项目(这些浏览器和系统决定信任哪些 CA)。这意味着它正从「证书使用者」变成「证书签发者」。

这是什么

证书颁发机构(CA)是负责签发数字证书的实体,证书用来证明「这个网站不是冒牌的」。Cloudflare 同时宣布计划成为首批提供后量子证书(能抵御未来量子计算机破解的下一代加密证书)的服务商之一。

收购 GlobalSign 已建立的信任根是关键一步。新建的根证书需要多年才能被全球设备和系统信任,GlobalSign 的根自 2012 年起就被广泛认可,能让 Cloudflare 从第一天起就覆盖到那些不再更新的老设备。

行业怎么看

支持方认为这是自然演进——Cloudflare 已是全球最大的 TLS(传输层安全协议,HTTPS 加密的底层标准)证书消费者之一,自己签发能降本提速。Cloudflare 也承诺免费签发,意味着中小网站主也将受益。

我们注意到质疑声主要集中在两点。一是「信任集中」风险:CA 行业已被少数玩家主导,Cloudflare 进场让基础设施更依赖一家公司。二是角色冲突——Cloudflare 既是 CDN(内容分发网络,负责把网站内容送到用户眼前的中间层),掌握全球大量流量;现在又要当 CA,存在利益冲突。历史上 CA 信任滥用并非孤例。

对普通人的影响

对企业 IT:短期内影响有限,但若使用 Cloudflare 全线产品,未来可能默认获得更便宜的后量子证书。

对个人职场:除非你做安全或合规相关工作,否则这件事你几乎感知不到。它是地基,地基稳了上层才不塌。

对消费市场:后量子证书普及后,5-10 年后上网的「加密强度」会更高;但今天没有直接感受。