Let's Encrypt charts Merkle Tree Certificate path for post-quantum TLS
Let's Encrypt has announced its migration roadmap to Post-Quantum TLS Certificates, specifically using Merkle Tree Certificates (MTCs), to prevent larger ML-DSA signatures from breaking web connections. They aim for a production rollout of MTCs by 2027, with the approach already backed by Chrome and tested by Cloudflare and Google. This move addresses the significant size increase of ML-DSA signatures which could cause 5% of connections to fail due to middlebox incompatibilities.
Key Takeaways
- ML-DSA-44 signatures are approximately 2,420 bytes, versus 64 bytes for current ECDSA-P256 signatures, causing TLS handshake overhead to exceed 10 kilobytes.
- Cloudflare's testing showed 5% of connections failed with larger post-quantum key exchanges due to middlebox limitations; others slowed due to additional network round trips.
- MTCs batch post-quantum signatures across many certificates, reducing per-connection authentication data to a single post-quantum signature, a public key, and a compact Merkle inclusion proof.
- Certificate Transparency becomes an intrinsic property of MTC issuance rather than a separate logging step with additional signatures.
- Let's Encrypt aims for MTCs in a staging environment by late 2026 and production by 2027, requiring updates to its issuance infrastructure and the ACME protocol.
Why It Matters
The streaming industry, reliant on secure, low-latency content delivery, faces a critical transition to post-quantum cryptography. Naive integration of larger post-quantum TLS signatures risks significant connection failures and slower handshakes, directly impacting user experience and operational efficiency for video delivery. Let's Encrypt's MTC strategy, supported by Google and Cloudflare, offers a path to maintain current performance while enhancing security. Companies should monitor IETF PLANTS and ACME working group developments and ensure their hybrid post-quantum key exchange (X25519MLKEM768) is enabled on internet-facing servers against harvest-now-decrypt-later threats.
Additional Context
The urgency for post-quantum cryptography (PQC) is increasing, with timelines accelerating across the industry. Google announced its own services migration to PQC by 2029, with Cloudflare making a parallel commitment, citing tightening estimates for when a 'cryptographically relevant quantum computer' capable of forging authentication signatures in real-time might emerge (Let's Encrypt blog, June 2026). This shift marks a recognition that post-quantum authentication, not just encryption, needs immediate attention. Regulatory bodies are also driving this transition. The NSA’s CNSA 2.0 suite mandates post-quantum standards for new National Security System acquisitions by January 1, 2027, and full post-quantum algorithm use by December 31, 2030 (Let's Encrypt blog, June 2026). NIST's draft guidance (NIST IR 8547) would deprecate current algorithms for new federal systems after 2030 and disallow them after 2035. The European Union targets high-risk systems by 2030 and broad migration by 2035 (Cybersecuritynews.com, June 2026). While these mandates do not directly bind the public Web PKI, they set a clear end-of-decade timeline influencing the broader ecosystem, including browser and library developers. Practical implementation details are also progressing. Go 1.27, expected in August 2026, will add ML-DSA to its standard library via a new crypto/mldsa package, indicating post-quantum signatures are maturing into practical infrastructure (Let's Encrypt blog, June 2026). Separately, the CA/Browser Forum is shortening certificate lifetimes, with maximum validity dropping to 200 days in March 2026, 100 days by March 2027, and 47 days by March 2029. These shorter lifetimes increase issuance frequency, making the efficiency benefits of MTCs even more critical (Help Net Security, June 2026).
Read full article at techtimes.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source