This blog sits on Cloudflare, so its certificates come from somewhere I never think about. What caught my eye is the entry ticket. Cloudflare’s CA will only issue to servers and proxies that speak ACME with the ARI extension, meaning they handle revocation and reissue on their own. No hand-installed certs, no manual fallback.
That’s a fair bar, and a useful audit prompt even if I never touch their CA. Anything I self-host that renews on a cron job and a prayer wouldn’t qualify, and neither would the odd gateway with a cert I pasted in by hand. So I’d list what actually speaks ARI and stop treating renewal as something I’ll remember. The post-quantum Merkle-tree certs I’ll watch from the dock.
The story — Cloudflare has applied to the Chrome, Apple, Microsoft and Mozilla root programs to become a certificate authority. To issue from day one, it plans to buy a GlobalSign root already trusted by browsers, likely GlobalSign Root R5, valid until January 2038. Cloudflare currently relies on 16 partner CAs, including Let’s Encrypt and Google Trust Services. Its CA will issue only via ACME to ARI-capable clients, with experimental post-quantum Merkle-tree certificates planned from 2026. (Source)