Let's Encrypt starts the transition to web-scale post-quantum certificates
Let's Encrypt has launched an ambitious project to make the web's Public Key Infrastructure (PKI) secure against quantum attacks. The initiative is based on Merkle Tree Certificates (MTCs), a new methodology that integrates post-quantum authentication without compromising the speed and reliability that have made Transport Layer Security (TLS) universal. The goal is to create a staging environment for issuing MTCs by the end of 2026, with a production environment ready for 2027.
The need for post-quantum authentication
Authentication is the component of TLS that verifies a server's identity. To compromise this process, a quantum computer would need to be able to forge a signature in real-time. While this threat depends on the existence of a cryptographically relevant quantum computer (CRQC), delaying the transition to post-quantum authentication could have serious consequences. Long-term keys, such as those of root certification authorities, code signing keys, and identity systems, remain valuable targets. Additionally, adopting new technologies takes years, so it's essential to start the implementation work long before quantum computers become available.
The challenges of scalability
The scale of the web's PKI makes deploying post-quantum signatures difficult. A typical TLS handshake carries five signatures and two public keys. Replacing them with the Multi-Layered Dilithium Signature Algorithm (ML-DSA) would increase a single handshake to over 10 kilobytes. This increase in handshake sizes would result in greater bandwidth usage and connection overhead for each TLS session. Therefore, any solution must be designed to work at web scale and practically enable by default.
How Merkle Tree Certificates work
An MTC certification authority issues certificates in batches, with a single signature covering the entire batch instead of signing individual certificates. Browsers keep landmarks updated outside of the TLS handshake. The authentication path in an MTC handshake consists of a signature, a public key, and a proof of inclusion. Even with post-quantum algorithms, it is smaller than a conventional TLS handshake. Additionally, MTCs integrate Certificate Transparency into the issuance process, eliminating the need for separate, additional logs.
The path to adoption
Since 2019, Let's Encrypt has operated Certificate Transparency logs, which are append-only Merkle Trees based on the same underlying data structure as MTCs. Cloudflare and Chrome are testing MTCs on live internet traffic, while the IETF PLANTS working group is developing the standard. Chrome has identified MTCs as the preferred approach for post-quantum certificates on the public web. However, the transition will take time, with standards still to be finalized, root programs defining their requirements, and the need for additional support in browsers, libraries, and ACME clients.
Transition timelines
The transition to post-quantum security is driven by several global initiatives. The NSA's CNSA 2.0 suite has directed national security systems toward post-quantum algorithms with a projected timeline between 2030 and 2035. NIST's preliminary guidance anticipates the deprecation of RSA-2048 and P-256 after 2030 and a ban after 2035. The European Union aims to migrate high-risk systems by 2030 and a broader migration by 2035. These goals are already guiding the work of vendors, libraries, and standardization bodies in the web PKI ecosystem. In 2026, Google announced plans to migrate its services by 2029, and Cloudflare made a similar statement. Go 1.27 added the NIST-standardized ML-DSA signature scheme to the standard library, indicating that post-quantum signatures are becoming part of mainstream infrastructure.
The role of ACME
Let's Encrypt is actively involved in the IETF PLANTS and ACME working groups as standards develop. The organization is monitoring work on ML-DSA signature standards in X.509 and TLS, as well as changes in the ecosystem such as ML-DSA support in Go's standard library. The transition of the web PKI to post-quantum security will depend on adoption by browsers, libraries, and ACME clients, regardless of whether the final result is MTCs or ML-DSA-signed X.509 certificates. ACME client developers and operators of ACME-based certificate pipelines should closely follow progress in the IETF PLANTS working group and discussions in the mailing list. Some of the upcoming changes will require client-side support, and early preparation will help facilitate adoption.
The importance of post-quantum cryptography
While post-quantum authentication is crucial, it is not the only aspect to consider. Post-quantum cryptography encompasses a range of algorithms and protocols designed to resist quantum computing attacks. The transition to these technologies will require updates to various components of the web's infrastructure, including TLS, digital signatures, and key exchange mechanisms. Let's Encrypt and other organizations are working to ensure that these updates are seamless and secure.
Server administrators and developers should start evaluating the changes needed to support post-quantum signatures. This includes updating cryptographic libraries, modifying authentication protocols, and verifying compatibility with emerging standards. Early preparation will be key to ensuring a smooth transition and minimizing downtime.
The importance of collaboration
Post-quantum security cannot be addressed by a single actor. It requires a collective commitment from developers, service providers, standardization bodies, and end-users. Let's Encrypt, along with other organizations, is working to create a secure and resilient ecosystem. Sharing knowledge, experimenting with emerging technologies, and adopting best practices will be key to success.
The transition to post-quantum security is a complex but necessary process. With the continued commitment of all stakeholders and careful planning, it is possible to ensure that the web remains secure against emerging quantum threats. Let's Encrypt and other industry leaders are driving this change, providing tools and resources to facilitate the adoption of post-quantum technologies. Users and server operators must stay informed and prepare for this critical evolution in cybersecurity.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not engage in real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all responsibility for the misuse of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.