Tim Callan and Jason Soroko

Root Causes: A PKI and Security Podcast

Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject matter expert) will help you stay current on developments in this essential technology platform and to u...

Author

Tim Callan and Jason Soroko

Category

Technology

Podcast website

soundcloud.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Root Causes 463: Cellular Networks Are Insecure 03.02.2025

In this episode we explain that all cellular networks, contrary to popular belief, are fundamentally insecure.

Root Causes 462: Crypto War 3.0 31.01.2025

In this episode we walk through the evolution of the war on cryptography, from the beginning up through today, terminating in what we call Crypto War 3.0.

Root Causes 461: Sectigo Acquires Entrust Public CA Business 29.01.2025

Sectigo today announced the acquisition of the Entrust public CA business. Entrust will go forward as a Sectigo reseller. Join us to learn the details.

Root Causes 460: The State of PQC with Michele Mosca 28.01.2025

In this episode we are joined by Dr. Michela Mosca. We discuss his pioneering work identifying the need for post-quantum cryptography, where PQC stands today, and what the future may hold.

Root Causes 459: 2024 Lookback - Shortening Certificate Lifespans & DCV 24.01.2025

2024 set in motion major changes for certificate lifespans and DCV. In this episode we discuss the Apple 47-day proposal, stepping down certificate term, public versus private CA use cases, DCV reuse periods, MPIC, WHOIS, and other topics.

Root Causes 458: Apple Extends Entrust Distrust to SMIME and VMC 19.01.2025

Apple has added itself to the Entrust distrust and has extended this distrust to S/MIME and VMC. We explain.

Root Causes 457: 2024 Lookback - Guests 17.01.2025

We had a remarkable year on the Root Causes podcast in terms of our guests. We look back at the extremely expert guests we were lucky to talk about in 2024.

Root Causes 456: 2024 Lookback - Bugzilla Bloodbath 14.01.2025

In this 2024 lookback episode, we give an overview of the firestorm of Bugzilla incidents that we refer to as the Bugzilla Bloodbath. The Bugzilla Bloodbath affected actions around the Entrust distrust, delayed revocation reform, 47-day SSL certificate maximum term, linting, and more.

Root Causes 455: PQC Standardization in IETF 08.01.2025

We talk with guest Sofia Celi of Brave Browser, who leads the IETF PQC standardization effort, about the process of setting standards for PQC-compatible digital certificates. We learn about expected timelines, hybrid strategies, the NIST PQC onramp's role, and more.

Root Causes 453: It Turns Out Monkeys Couldn't Type Shakespeare After All 02.01.2025

The old adage states that a monkey in front of a keyboard, given enough time, could randomly type the works of Shakespeare. Apparently, someone ran the numbers and said not so much. We break it down and explain why we're discussing this on a PKI podcast.

Root Causes 454: 2024 Lookback - Post quantum cryptography (PQC) 02.01.2025

2024 was an eventful year for post quantum cryptography (PQC). This includes FIPS standards, the PQC onramp, and the dawn of widespread interest among IT professionals.

Root Causes 452: 2024 Predictions Scorecard 26.12.2024

We go over our predictions for 2024 and score our ability as prognosticators.

Root Causes 451: A Year in CABF Ballots 26.12.2024

It was a crazy year for CA/Browser Forum activity, with nearly three times the normal number of ballots. Guest Martijn Katerbarg goes over the 32 CABF ballots from 2024.

Root Causes 450: 2025 Predictions 23.12.2024

We make our 2025 predictions. Topics include maximum certificate term, AI, post-quantum cryptography (PQC), deep fakes, and more.

Root Causes 449: What Is a Quantum-safe HSM? 18.12.2024

Repeat guest Bruno Coulliard of Crypto4A joins us to define a quantum-safe (or PQC enabled) hardware security module.

Root Causes 448: The Privilege of Being a Public CA 17.12.2024

We go over Tim's September 2024 keynote speech at ENISA CA Day, "The Privilege of Being a Public CA."

Root Causes 447: NIST Deprecates RSA-2048 and ECC 256 13.12.2024

As part of its post-quantum cryptography (PQC) initiative NIST has released a draft deprecating RSA-2048 and ECC 256 by 2030 and disallowing them by 2035. We get into the details.

Root Causes 446: Sectigo Assumes Five CABF Offices 12.12.2024

Tim has stepped into the position of vice-chair of the CA/Browse Forum, and Sectigo now holds five chair or vice-chair positions in that body. We explain how leadership is chosen, the offices Sectigo holds today, and some of our vision for CABF in the next two years.

Root Causes 445: Seven Reasons to Shorten Certificate Lifespans 09.12.2024

We take a deep dive into the seven reasons shorter certificate lifespans are better.

Root Causes 444: What Happens to the WebPKI if Google Sells Chrome? 05.12.2024

We discuss how a potential break of Chrome from Google would affect the WebPKI. We look at product changes, resourcing, post-quantum cryptography (PQC), innovation, moonshot initiatives, and other public CAs.

Root Causes 443: Is MSCA Going Away? 01.12.2024

In this episode we discuss the challenges for enterprises using Microsoft Active Directory Certificate Services (ADCS).

Root Causes 442: Apple Proposal to Reduce SSL Lifespan Updated 25.11.2024

Apple has published an updated draft to its proposal for shortening the lifespan of SSL certificates, including a final maximum term of 47 rather than 45 days. We explain.

Root Causes 441: New White House Initiative Targets BGP 22.11.2024

A new White House initiative requires that federal agencies need to create plans to thwart BGP attacks. We discuss, including Resource PKI (RPKI) and Multi-Perspective Issuance Corroboration (MPIC).

Root Causes 440: Public Key Directories 18.11.2024

We talk about public key directories and complicating factors such as Tailscale, VPN, TOR, Cloudflare, and Zero Trust.

Root Causes 439: PQC Onramp Narrowed Down to 15 Candidates 15.11.2024

NIST has narrowed its PQC onramp contest to 15 candidates. We go over who remains and the makeup of the remaining candidates.

Listen to the Root Causes: A PKI and Security Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.