Tim Callan and Jason Soroko

Root Causes: A PKI and Security Podcast

Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject matter expert) will help you stay current on developments in this essential technology platform and to u...

Author

Tim Callan and Jason Soroko

Category

Technology

Podcast website

soundcloud.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Root Causes 539: What Is the Two-QWAC Architecture? 22.10.2025

A new kind of eIDAS QWAC (Qualifieid Website Authentication Certificate) is on the way. The "two-QWAC architecture" introduces a second certificate containing organization information to be displayed by the browser, to sit alongside but independent of the certificate that authenticates a domain. We explain what's coming and why.

Root Causes 538: What Is an Entropy Desert? 20.10.2025

An environment in which credentials are extremely predictable could be described as an entropy desert. There are occurring at a global scale. We discuss concepts like measurable entropy availability and entropy by design.

Root Causes 537: The Thermodynamics of Privacy 17.10.2025

In this episode we build on our concept of entropy-aware guidance to explain how we might quantify privacy. We touch on GDPR, proof of work, and Landaur's principle.

Root Causes 536: Patent Blocker on ML-KEM 15.10.2025

A patent dispute in 2024 nearly blocked ML-KEM. But emerging thinking raises concern that the 2024 resolution did not guarantee full, clear access to all ML-KEM implementations. We explain.

Root Causes 535: The CPS Is a Superset of Actual Practices 12.10.2025

The CPS must always be a superset of actual practices in a properly running CA. We explain why this is a product of good design.

Root Causes 534: Signing the Machines That Think 10.10.2025

Imagine what happens if you use the wrong LLM, including a malicious model placed there to create mischief or crime. How do you know? Jason proposes that, the same way we sign our code, we should be signing our AI models as well.

Root Causes 533: Flexibility Through Multi-CA Trust Models 07.10.2025

We discuss how a static PKI structure can hurt corporate flexibility and resilience. Events like reorgs and M&A activity can cause intractable problems with the wrong PKI setup. Plus, Jason coins the term PKI archeology.

Root Causes 532: Introducing Offline PKI 02.10.2025

In this episode, Jason describes how we might use the principles of PKI in a purely offline scenario.

Root Causes 531: Benefits of Single-purpose Root Hierarchies 01.10.2025

Public certificates are transitioning from multi-purpose root hierarchies to single-purpose ones. We discuss why.

Root Causes 530: Introducing the AI Iceberg 29.09.2025

We compare AI in 2025 to Internet in 1995 and describe the AI iceberg, including the majority of applications which are below the waterline.

Root Causes 529: What Is a Common Mark Certificate? 24.09.2025

Verified Mark Certificates (VMC) now have a companion product for logos that are not registered trademarks, called a Common Mark Certificate (CMC). We explain the differences.

Root Causes 528: Misissued SSL Certificate for 1.1.1.1 17.09.2025

A CA has incorrectly issued TLS certificates for the 1.1.1.1 and 2.2.2.2 IP addresses. We go into the details.

Root Causes 527: Key Dates for the Deprecation of Public mTLS 15.09.2025

Client authentication using public TLS server certificates is on the deprecation path. In this episode we go through the key dates in this deprecation.

Root Causes 526: Voice Biometrics Are Worthless 12.09.2025

Based on the ready availability of AI-based voice cloning, we declare voice biometric authentication to be utterly valueless.

Root Causes 525: The End of Email-based DCV 10.09.2025

A new CABF ballot proposal will eliminate all email- and phone-based DCV over the next few years. We go into the details.

Root Causes 524: How to Kill Three Birds with One Stone 08.09.2025

Three major changes are coming to the world of public certificates, all of which require major changes in how organizations deploy, renew, and manage their certificates. These are 47-day SSL, PQC, and the deprecation of mTLS. We describe the overlap between these efforts and how to combine them for better efficiency and project management.

Root Causes 523: Will Your Configuration Block MPIC DCV? 03.09.2025

MPIC (Multi-perspective Issuance Corroboration) is soon to move into enforcement phase. In this episode we describe three configuration decisions that can force Domain Control Validation (DCV) to fail and tell you what to do about them before you have a problem.

Root Causes 522: How Prepared Are Enterprises for PQC? (Part 2) 27.08.2025

We complete our description and commentary on the results of Sectigo's survey of enterprise preparedness for Post Quantum Cryptography (PQC).

Root Causes 521: How Prepared Are Enterprises for PQC? (Part 1) 22.08.2025

We begin to go over the results of Sectigo's recent survey of enterprises and their preparedness and plans for adopting Post Quantum Cryptography (PQC).

Root Causes 520: How Prepared Are IT Teams for 47-day Certificates? 20.08.2025

Sectigo has released the results of its survey of IT professionals in charge of certificates to measure their readiness and preparation for 47-day maximum certificate term. We go over the results.

Root Causes 519: AI Is the Room 18.08.2025

AI is not the elephant in the room. It is the room itself. Jason explains what he means by that.

Root Causes 518: NCSC Lukewarm on FIDO WebAuthn 13.08.2025

Britain's National Cyber Security Centre recently issued a lukewarm verdict on passkeys as an authentication solution. We explore the problems with WebAuthn, including account recovery, spotty availability, inconsistent implementation, and lack of Linux support.

Root Causes 517: The Cost of Quantum Factoring 25.07.2025

Jason walks us through an important recent paper from Google tracking the cost of quantum factoring.

Root Causes 516: PQC for ADCS 21.07.2025

Microsoft has finally announced that it will offer an update to Active Directory Certificate Services (ADCS, formerly MSCA) to support post quantum cryptography. We discuss Microsoft's checkered support for ADCS and offer some questions users should be asking.

Root Causes 515: What Is Entropy-aware Governance? 18.07.2025

Jason coins the term "entropy-aware governance" to describe the idea of using the degree of entropy it contains to measure the strength of any given secret. This could be an objective, consistent metric that could be applied to standard practices and requirements.

Listen to the Root Causes: A PKI and Security Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.