Tim Callan and Jason Soroko
Root Causes: A PKI and Security Podcast
Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject matter expert) will help you stay current on developments in this essential technology platform and to u...
Author
Tim Callan and Jason Soroko
Category
Podcast website
Latest episode
Jul 10, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Root Causes 313: SSL Revocation Reason Codes 22.06.2023 16:03
In 2022 Mozilla added a root program requirement that CAs include Reason Codes when revoking public TLS certificates. In this episode we explain the reason codes, along with some explicitly forbidden reason codes, and go into the backstory behind this requirement.
Root Causes 312: You Shouldn't Roll Your Own Crypto 20.06.2023 14:54
Don't roll your own crypto. In this episode we describe the findings from 2021 research that investigating the root causes of problems in cryptographic systems. The results may surprise you.
Root Causes 311: What Is CCADB? 16.06.2023 13:53
We describe CCADB, the Common CA Database. We explain the role of CCADB in the WebPKI and how this role is evolving.
Root Causes 310: Another AI Episode 13.06.2023 25:14
In this episode we continue to explore the capabilities of AI to replicate known people in deep fakes with AI-generated content.
Root Causes 309: What Is Key Attestation for Code Signing? 07.06.2023 11:17
On June 1, 2023 new rules for delivery of code signing certificates went into effect, requiring the certificate be delivered by secure HSM. In addition to shipping a token by mail, certificates can be electronically delivered to Subscriber-owned hardware that supports key attestation. In this episode we explain key attestation, supporting hardware, and the pros and cons of this method.
Root Causes 308: E-Tugra Root Deprecation 05.06.2023 17:57
For the second time in under twelve months, a major browser is deprecating a CA's public trust. This time it's E-Tugra. Learn about the concerns raised about this CA, investigation of these concerns, and the ultimate deprecation decision.
Root Causes 307: OT Red Teaming Leads to Malware Attack 31.05.2023 13:34
In this episode we describe how tools from operational technology red team exercises are being repurposed for malware attacks.
Root Causes 306: Certificate Transparency Logs and Privacy 26.05.2023 13:26
Certificate Transparency (CT) logs do a lot of good for the WebPKI. They also, however, carry with them some privacy concerns. In this episode we explain those concerns.
Root Causes 305: The Fifth Pillar of Certificate Lifecycle Management 22.05.2023 13:42
In our episode 143 we introduced the Four Pillars of Certificate Lifecycle Management. Now, two years later, we introduce a fifth pillar of CLM.
Root Causes 304: Your 90-day SSL Certificates Checklist 18.05.2023 13:44
90-day maximum term for SSL certificates is coming. In this episode expert guest Henry Lam details his four-point checklist for preparing enterprises for these shorter-lived certificates.
Root Causes 303: A Return to Chrome and the Address Bar 16.05.2023 19:09
In our recent episode 300 we discussed Chrome's upcoming removal of the lock icon from its interface. In this follow up, we catch the listener up on Chrome's longstanding program to minimize the URL in its interface, even to the point of contemplating removing the address bar entirely.
Root Causes 302: Intel Secure Boot Private Key Leak 12.05.2023 12:32
Resulting from a recent ransomware attack, a private key from Intel has been exposed, affecting more than a hundred OEM components and an unknown number of end user products. We explain what happened and its possible implications.
Root Causes 301: The Difference Between Certificate Automation and CLM 09.05.2023 14:55
This podcast frequently discusses the concepts of certificate automation and Certificate Lifecycle Management (CLM). In this episode we discuss how CLM does not always entail automation and vice versa -- along with where this distinction occurs and why it matters.
Root Causes 300: Chrome Eliminates the Lock Icon 04.05.2023 18:39
Google Chrome has announced that it will eliminate the lock icon in September. We explain what Google will be doing, its stated rationale, and the pros and cons of this decision.
Root Causes 299: 2023 RSA Recap 02.05.2023 31:07
The 2023 RSA Conference just concluded. This week Tim recaps what he saw at the show and how it reflects on security industry trends. Our hosts discuss Zero Trust, PQC, blockchain, artificial intelligence, post-COVID tradeshow behavior, and more.
Root Causes 298: Moving Forward, Together - Promoting Automation 28.04.2023 12:28
The Google Chrome root store has communicated its plans for promoting automation. In this episode we explain Chrome's public plans for this initiative, which is anchored around ACME.
Root Causes 297: Certificate Expiration Creates Starlink Outage 26.04.2023 9:56
A recent outage in the Starlink internet service was caused by an unexpected certificate expiration. We discuss this ongoing problem and how 90-day maximum certificate term will exacerbate it.
Root Causes 296: SHOULD We or MUST We? 21.04.2023 12:37
The CA/Browser Forum guidelines contain many prescribed requirements, with language containing the word SHOULD or MUST. In this episode we explain the specifying power of these two words, why they are used, and what they signal about the intent behind a guideline and how the rules might evolve.
Root Causes 295: Genesis Criminal Marketplace Taken Down 17.04.2023 11:04
A large, public criminal marketplace for stolen logins and other information was rolled up by law enforcement across seventeen countries. Genesis Marketplace offered not only traditional login credentials but also associated data needed to defeat MFA.
Root Causes 294: Root Causes Honored by Webby Awards 13.04.2023 9:09
The Root Causes podcast has received a Webby Honoree award. Jason and Tim briefly celebrate and discuss the challenge of operating a niche, homemade podcast while being directly compared to professionally produced podcasts on mainstream topics from media companies. Plus, Tim's new Root Causes t-shirt.
Root Causes 293: What Is Certbot? 10.04.2023 12:32
Certbot is an important part of the ACME standard. This open source tool makes it easier for many IT administrators to use ACME to automate provisioning and installation of SSL / TLS certificates.
Root Causes 292: Validation Data Reuse for 90-day Certificates 06.04.2023 15:20
As the industry explores the expected consequences of 90-day maximum term for SSL / TLS certificates, some are wondering if the allowed validation data reuse period stands to go down also. We explain today's data reuse rules and what the evidence indicates will be required for both domain control validation (DCV) and organization information validation.
Root Causes 291: CLM and SIEM 03.04.2023 9:39
We discuss how Certificate Lifecycle Management (CLM) interacts with Security Incident and Event Management (SIEM). The certificate world is chock full of events such as renewals, revocations, admin logins, and provisioning and removal of employee access. We talk about expected behaviors in the CLM and monitoring them.
Root Causes 290: What Are QGIS and QIIS? 29.03.2023 13:05
In this episode we define Qualified Government Information Source (QGIS) and Qualified Independent Information Source (QIIS), which are critical to CABF-compliant organization validation. We explain how they fit into validation and the criteria for a reliable information source.
Root Causes 289: What Is a Cryptographic Center of Excellence? 27.03.2023 8:30
In this episode we dig into an emerging idea, which is the cryptographic center of excellence. We discuss how such a center of excellence would work and the benefits it can bring to an enterprise.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.