Let's Encrypt adopts Merkle Tree Certificates for post-quantum web PKI (heise.de)
- Let's Encrypt chooses Merkle Tree Certificates over large post-quantum signatures.
- Test environment in late 2026, production in 2027.
- Cloudflare and Chrome already testing MTCs in field trials.
- ML-DSA-44 signatures 38x larger than ECDSA-P256; MTCs batch certificates.
- IETF PLANTS working group standardizing MTCs; ACME extension planned.
"Let's Encrypt has published a roadmap for post-quantum certificates. Instead of bloating X.509 certificates with large post-quantum signatures, the CA will use Merkle Tree Certificates (MTCs). A test environment launches in late 2026, with production expected in 2027. MTCs aggregate many certificates into a Merkle tree, signing only the root and providing compact proofs. This keeps TLS handshakes small despite quantum-safe signatures. The decision carries weight as Let's Encrypt issues hundreds of millions of certificates. Cloudflare and Chrome are already trialing MTCs."
no comments yet.