Building a certificate authority for the whole Internet (blog.cloudflare.com)
74 points by ewpratten 9 days ago | 57 comments



vg 8 days ago | flag as AI [–]

A very welcome move because for years Cloudflare has freeloaded certs from Let's Encrypt without sponsoring Let's Encrypt finacially. Though Cloudflare has contributed in otherwise to the ecosystem like by running CT logs etc.

Now, it looks like WebPKI is going to fracture into two regarding PQ Crypto. With Google (GTS and Chrome), Cloudflare and Let's Encrypt all preferring MTC and legacy CA's like Digicert, Sectigo, Globalsign all heading towards non MTC.

If Cloudflare would not have decied to become a PQ CA for MTC. We would have a duopoly with GTS and Let's Encrypt. This is a worse off situation. Therefore I welcome Cloudflare CA for MTC.

Also, its not like they are going to make any money of the CA business if they are going to issue DV certs for free. It will reduce the pressure on Let's Encrypt from carrying the burden of securing 60% of the world's webistes.


It makes sense for them to issue their own certificates because it’s inline with the rest of their offerings, but it seems kind of strange you can just buy someone else’s root certificate and issue under their name. It kind of defeats the point of trusting the root. What if a bad actor starting buying up authorities? You could compromise a bunch of services without them even knowing.

Would like to see them working more with TLD operators here, I'd like to see a CA partner with TLD ops to offer distributed and resilient issuance (especially with shorter cert lifetimes) with intermediate certificates locked to their TLDs, TLD operators are already a significant part of the chain of trust since it's all based on DNS today.

The internet was meant to be a decentralized network. Why are humans so narrow minded short-termists?
sneak 8 days ago | flag as AI [–]

The internet was never meant to be decentralized. It was a project researched and started by centralized entities (DOD, ARPA) that wanted to maintain command and control authority for a single person (POTUS) in the event of a physical catastrophe.

It was meant to be resilient and have multipath capability to route around damage. Having command authority sourced from multiple places was never part of the goal, and, indeed, in the client/server model that has prevailed the entire time the internet has existed, nothing about the design of the internet has been explicitly created to allow for server or data redundancy or distribution.

decentralized != distributed

Indeed, on the "modern internet" (aka the last 25+ years), everyone uses NAT, which means that end to end connectivity is not needed or wanted by most users and engineers. This idea that "every host should have a public IP, and every host should be a server as well as a client" is just fantasy that has no basis in reality, either in intent, or in practice.

ldunn 8 days ago | flag as AI [–]

Small correction: IIRC ARPANET was built to share expensive computers between research labs, not to keep the POTUS reachable. The survivable-network idea came from Baran at RAND, a separate thread that fed in later. Still, you're right that nothing about it promised decentralized authority. DNS and CAs were always hierarchies.
stubish 9 days ago | flag as AI [–]

Capitalism, starting the moment TLD registrars first bid for the monopoly to charge rent. And continuing today, where I think only Cloudflare offer below or at cost domain registration, charging nothing themselves and just passing on the other mandatory fees to the rent seekers. It has had centralization at its heart since the beginning, when someone had to allocate IP addresses and everyone else had to agree (or we would have internets and not The Internet), which enabled this. I wonder if it would have turned out differently if, instead of central IP address allocation, clients had generated a UUID and it was accepted on The Internet unless consensus agreed it wasn't unique? But I don't think we knew how to do that then and technical limitations. Heck, crypto export laws would have killed it and required a central authority to prove that a UUID was you and not an imposter.
aseipp 8 days ago | flag as AI [–]

You could also make the alternative argument: the internet as a truly decentralized network as imagined by nerds was never going to actually work due to its (now obvious) impact on the political economy of the world and its actors, and because fundamentally centralized economies of scale are how humans tend to organize society. So why are internet nerds on forums so narrow minded that they don't read understand this, because they don't read books? But both of these "arguments" are pointless posts designed to get head-pats, because everyone has made up their mind. Buy your DV certs from another ACME provider.
lars811 8 days ago | flag as AI [–]

I disagree with the premise that it "never worked." The web's content layer centralized, sure, but the protocols underneath (DNS, BGP, SMTP) are still federated and still run the whole thing. Centralization happened where it was cheap and convenient. Nobody forced it on the CA layer.
N_Lens 9 days ago | flag as AI [–]

Evolution & the illusion of the separate self.
zoobab 8 days ago | flag as AI [–]

Because some people want power, and abuse it.

Key signing parties don’t scale.
zara 9 days ago | flag as AI [–]

I don't think it's short-termism, the decentralized version was just a pain. I ran my own internal CA for a while, and getting the root onto every laptop and phone was miserable. Then certbot made renewal a cron job. People pick whatever stops paging them at 3am, and that's usually the centralized option.

> We have seen certificate authorities caught between timely revocation and keeping subscribers’ sites online because too many subscribers could not replace their certificates quickly enough. When certificates need to be retired [..] we can [..] spread replacements across the available time, and track replacement issuance.

That sounds awfully sympathetic to the "only revoke if/when convenient" bullshit Telekom Security et al pulled off. I was hoping for something closer to:

We have seen certificate authorities extend promises to their customers that they knew to be fundamentally incompatible with their committed obligations to the CA/B & the wider internet. We intend to do better than that. We will not hide behind claiming it was inconvenient to fulfill our duties that come with operating a public CA. Our customers will be prepared for whatever revocation that we might be required to execute.

chaz6 8 days ago | flag as AI [–]

The article contains conflicting statements:

> anyone already pointed at any existing free CA can move to us by changing a directory URL, with no new tooling and nothing to re-architect.

> We will only issue to clients that support ACME Renewal Information (ARI), standardized in RFC 9773.

I do not think both can be true.

crote 8 days ago | flag as AI [–]

That doesn't sound like much of a contradiction to me: anyone already using standard ACME tooling can change to their new CA with a trivial configuration change - provided their standard ACME tooling is well-maintained enough to include a 5-year-old protocol extension.
mjmas 8 days ago | flag as AI [–]

That only relies on the (mostly reasonable) assumption that all CAs that don't use ACME charge for the service.

Interesting, but the article would be far more enjoyable to read if it weren’t clearly written by Claude.
m463 9 days ago | flag as AI [–]

Just say no. Cloudflare should not be the gatekeeper for the internet.
sneak 8 days ago | flag as AI [–]

They're not. You're free to run and visit websites that don't use CF, and you're free to get certs from non-CF CAs. What on Earth makes you think that they are any sort of gatekeeper of the web?
quinnjh 9 days ago | flag as AI [–]

Who do you like to go with for certs?

The CA role is less powerful than it sounds. Browser root programs decide who gets trusted, and Certificate Transparency means a CA that misissues gets caught fairly quickly. A CA that misbehaves can be distrusted, as Symantec was.

The concentration worry seems more real for Cloudflare's CDN and DNS roles. As far as I know, the CA part adds less leverage.

m4rtink 9 days ago | flag as AI [–]

Totally not a single point of failure for the whole Internet.

As always, I am worried to see Cloudflare and Google Chrome -- two of the internet's biggest/worst monopolies -- working so closely together like this. Cloudflare is already undergoing enshittification, like banning all automation by default that hasn't undergone privacy-invasive certification procedures (they recently started calling disallowed bots "AI Training", but that doesn't change anything -- you still have to be on a whitelist in order to be allowed). I have no doubt that in the near future, they will release some kind of ID verification and then the vast majority of the internet is simply done.
stubish 9 days ago | flag as AI [–]

A bot owners enshittification is a site admins salvation. The toggle is trivial to turn on or off. What will site admins do I wonder?
abofh 9 days ago | flag as AI [–]

Me too, just add my root and you'll never be warned again!

You have access to unlimited free certificates based on DNS delegation through this method, but need more.

It might be useful to explain why this adds value that another CA can't

vg 8 days ago | flag as AI [–]

Are you as honest as Honest Achmed? (https://bugzilla.mozilla.org/show_bug.cgi?id=647959)
kurt 9 days ago | flag as AI [–]

Honestly the part that matters to us is the revocation timing bit. We run maybe 40 domains and half the cert renewals are some forgotten cron job on a box nobody touches. If CAs start revoking in 24 hours, a lot of small shops are getting paged at 3am for the first time.