Let's Encrypt Bets on Merkle Tree Certificates for Post-Quantum Web PKI
Let’s Encrypt has chosen Merkle Tree Certificates (MTCs) as its path to a post-quantum-safe Web PKI, with a staging environment targeted for late 2026 and production in 2027. The decision is driven by a tightening timeline: NSA’s CNSA 2.0, NIST draft guidance, and EU mandates all converge on 2030-2035, while Google and Cloudflare have committed to migrating services by 2029. Authentication, long considered less urgent than encryption because it can’t be broken retroactively, is now a near-term concern as cryptographically relevant quantum computers look closer.
The core problem is size. NIST’s ML-DSA-44 signatures are roughly 2,420 bytes versus 64 for ECDSA-P256, and a typical TLS handshake carries five signatures and two public keys. Naively swapping in post-quantum algorithms pushes handshakes past 10KB, breaking a meaningful share of connections and slowing the rest. MTCs sidestep this by issuing certificates in batches under a single signature, with browsers tracking batch “landmarks” out of band. The common-case handshake ends up smaller than today’s, and because every cert lives inside a published Merkle tree, Certificate Transparency becomes intrinsic rather than bolted on.
Cloudflare and Chrome are already running MTC feasibility experiments against live traffic, the IETF PLANTS working group is standardizing the design, and Go 1.27 is adding ML-DSA to its standard library. Nothing changes for existing subscribers in the short term, but ACME client maintainers should start tracking PLANTS. Let’s Encrypt also urges operators to enable hybrid post-quantum key exchange (X25519MLKEM768) now, since harvest-now-decrypt-later attacks against today’s encrypted traffic are the more immediate threat.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.