Cloudflare plans a free public certificate authority that will only issue to ACME clients supporting ARI, the renewal extension in RFC 9773. certbot, acme.sh, lego and Caddy support it, cert-manager keeps it behind an off-by-default flag, and Traefik does not use it.
What Cloudflare Announced
On September 29, 2026, Cloudflare said it is building a publicly trusted certificate authority that will hand out free TLS certificates. It is not issuing yet, and it gives no date for the first ordinary certificate. It has applied to the Chrome, Apple, Microsoft and Mozilla root programs, and it has signed an agreement to acquire an established root from GlobalSign that has been trusted since 2012.
Issuance will go through ACME only, the protocol Let's Encrypt popularized. Cloudflare's pitch is that a site already using a free CA can move by changing one directory URL. Its reasoning is resilience. Cloudflare points out that most of the free, automated certificate model runs through a single operator, and argues that a second free CA gives the web somewhere to go if that operator has a bad week.
A companion post covers Merkle Tree Certificates, a new certificate format designed for the post-quantum era. Cloudflare expects to issue the first of those in the first quarter of 2027, from ACME software based on Let's Encrypt's own Boulder.
The Condition That Decides Whether You Can Use It
Cloudflare will only issue to clients that support ACME Renewal Information, or ARI, which the IETF standardized as RFC 9773 in June 2025. A subscriber's automation has to poll Cloudflare's renewal endpoint, act on the renewal windows it publishes, and say which certificate each new order replaces.
ARI turns renewal timing into something the CA can steer. For every certificate, the client asks a renewalInfo URL when it should renew and gets back a suggested window. When it orders the replacement, it names the old certificate in a replaces field. The practical benefit shows up in an incident. If a CA has to revoke certificates in bulk, it can pull their renewal windows forward, and clients that follow ARI replace them before anything breaks.
Which Clients Are Ready
| Client | ARI support | Default |
|---|---|---|
| certbot | since 4.1.0, June 2025 | on, checked by certbot renew |
| acme.sh | since 3.1.4, July 2026 | on, NO_ARI=1 turns it off |
| lego | since v4.12.0, replaces since v4.16.0 | on in the CLI since v4.20.2 |
| Caddy | since 2.8.0, May 2024 | on |
| cert-manager | since v1.21.0, July 2026 | off, behind the ACMEUseARI feature gate |
| win-acme | draft version since 2.2.3 | on, last updated to draft 3 in 2024 |
| Traefik | not supported | renews on its own schedule |
Two rows deserve a second look. Traefik is built on lego, but its certificate resolver does not use lego's ARI support and has no renewal-information code of its own, so it keeps renewing on the interval set by certificatesDuration. And cert-manager, the usual choice on Kubernetes, supports ARI only as an alpha feature that is switched off unless you enable the gate.
For cPanel's AutoSSL and Plesk's certificate tools, we found no documentation of ARI support. On those servers the panel handles renewals, so the answer will come from the vendor's release notes.
Why ARI Is Worth Turning On Anyway
The Cloudflare CA is not the only reason. Let's Encrypt is shortening its certificates. Its default profile moves to 64-day certificates on February 10, 2027 and to 45-day certificates on February 16, 2028, and it warns that a hardcoded 60-day renewal interval will no longer be enough. Its recommendation is ARI, and its rate-limit rules exempt renewals made through ARI from all limits, as long as the new order shares at least one name with the certificate it replaces and that certificate has not already been replaced.
So a fleet that renews on a fixed timer is heading for trouble either way, and the fix is the same.
What to Do Now
- Find every client that issues certificates, not just the obvious one. Servers, ingress controllers, load balancers and control panels often each run their own.
- Upgrade to a version with ARI. That means certbot 4.1 or later, acme.sh 3.1.4 or later, lego v4.20.2 or later, or Caddy 2.8 or later.
- On Kubernetes, cert-manager v1.21 or later can use ARI once
ACMEUseARIis enabled. Try it on a staging issuer first, since it is still alpha. - On Traefik, watch its release notes, or move certificate issuance to a client that supports ARI if you plan to use Cloudflare's CA.
- Do not switch CAs yet. Cloudflare has not started issuing, so there is nothing to point a client at today.
Running certificates across many domains is a subject of its own, covered in How to Automate Certificates for Hundreds of Client Domains, and keeping renewal automation healthy is part of Servers Management.
Sources
- Cloudflare: Building a certificate authority for the whole Internet
- Cloudflare: Building a post-quantum certificate authority with Merkle Tree Certificates
- RFC 9773, ACME Renewal Information
- certbot changelog
- acme.sh releases
- lego changelog
- Caddy 2.8.0 release
- cert-manager v1.21.0 release
- Traefik ACME provider source
- Let's Encrypt: Decreasing certificate lifetimes to 45 days
- Let's Encrypt rate limits
Or read how we handle it in Servers Management.
Related Articles
Upgrading Magento 2 to the Latest Version: A 10 Step-by-Step Guide
A structured 10-step process for upgrading Magento 2 from v2.4.3 to v2.4.7-p3 on Ubuntu, covering system preparation, backups, staging setup, Composer updates, custom module handling, and post-upgrade optimization.
Server & DevOpsYour Images Are Probably Not What Makes LCP Slow
Cloudflare's BEACON data from 10,000 large sites shows where slow LCP comes from. On pages rated poor, downloading the LCP resource took 119 ms, while the first byte, late discovery and blocked rendering each took one and a half to two seconds.
Server & DevOpsMySQL Master-Slave Replication Setup Guide (Source-Replica Syntax for 8.4)
MySQL 8.4 removed the master-slave syntax entirely, so CHANGE MASTER TO and SHOW SLAVE STATUS now fail outright. This guide uses the current source-replica syntax that works on both 8.0 and 8.4, with a full mapping table, GTID setup, HAProxy read distribution, and the two things that actually break in production: Seconds_Behind_Source lying to you, and reading your own writes.