Tim Callan and Jason Soroko
Root Causes: A PKI and Security Podcast
Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject matter expert) will help you stay current on developments in this essential technology platform and to u...
Author
Tim Callan and Jason Soroko
Category
Podcast website
Latest episode
Jul 10, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Root Causes 438: PQC Is an Existential Requirement 12.11.2024 28:19
Repeat guest Bruno Couillard argues that cryptography is part of the foundational fabric of our lives and that the transition to PQC is an existential requirement.
Root Causes 437: Don't Blame the Linter 05.11.2024 11:21
Linters are essential tools for maintaining quality of certificate issuance. Public open-source linters are available to help CAs assure compliance. As a result, CAs have begun attributing gaps in coverage by public linters as the root cause for misissuance events. We explain why this is faulty reasoning.
Root Causes 436: Formal Proofs 29.10.2024 10:22
Formal proofs are critical to cryptography. We discuss how better processes and AI can accelerate formal proofs of cryptographic concepts.
Root Causes 435: The PQC "Q Day" Is Not That Simple 25.10.2024 19:45
The PQC community likes to debate when crypto relevant quantum computers will be available, which is sometimes called "Q day." In this episode we explain how radically oversimplified this concept is and dive into the nuances of what a "cryptographically relevant quantum computer" really will be.
Root Causes 434: Did Researchers Break AES Using Quantum Annealing? 22.10.2024 11:43
News reports claim Chinese researchers broke AES with a quantum annealing computer. We clarify the details and talk about the implications of this reported discovery.
Root Causes 433: Will AI Eat All the Electricity? 17.10.2024 10:28
We explore the question of whether or not we have enough electricity to fuel AI's expected growth.
Root Causes 432: Apple Floats New Short-lived Certificate Proposal 14.10.2024 26:20
Apple recently floated a draft CABF ballot for commentary that steps down maximum term for SSL certificates starting next year and eventually landing at 45 days in 2027. We share the details.
Root Causes 431: New Mozilla Proposal to Combat Delayed Revocation 11.10.2024 28:10
Deliberate delay of mandatory revocations has plagued the WebPKI in 2024. A new proposed policy from Mozilla stands to eliminate most of this behavior. In this episode we go over the proposal and explain its potential consequences.
Root Causes 430: How Does a TLS Handshake Work? 09.10.2024 14:31
In this episode we give a high-level explanation of what happens in a TLS 1.3 handshake and then discuss what will happen when PQC is included.
Root Causes 429: ServiceNow Outage Due to Expired Root Certificate 08.10.2024 7:04
A ServiceNow private CA root expired, creating outages across hundreds of enterprises. We explain what appears to have gone on.
Root Causes 428: .MOBI Attack Puts WHOIS-based DCV into Question 04.10.2024 17:10
White hat researchers managed to take over WHOIS for the .mobi TLD. Among other things, this discovery foretells the death of WHOIS as a valid email source for Domain Control Validation (DCV).
Root Causes 427: Mapping CLM to NIST CSF 2.0 01.10.2024 15:46
In this episode we map the contributions of Certificate Lifecycle Management into the new NIST Cybersecurity Framework 2.0.
Root Causes 426: Expired Certificate Takes Down Bank of England 30.09.2024 7:42
A certificate expiration is now known to have created July's outage of Bank of England. Join us as we shake our heads in amazement yet again.
Root Causes 425: PQC Requirements for Voting Systems 27.09.2024 10:53
In honor of the upcoming US elections, we describe the six main requirements for a post-quantum voting system.
Root Causes 424: Using LoRA IoT Protocol for Clandestine Communications 25.09.2024 11:43
In this episode we describe the LoRA protocol, which allows IoT devices to communicate securely without using a cellular network, and how it can be used for secret communications.
Root Causes 423: Is a Certificate Software or a Service? 20.09.2024 18:28
In this episode we discuss the dual nature of a public certificate as both a file and part of a holistic service that lasts until its expiration. We discuss revocation checking, CT logging, GAAP accounting, linters, certificate tracking tools, Certificate Lifecycle Management, standards bodies, post-quantum cryptography, and subscription models.
Root Causes 422: New Date for Entrust Distrust 19.09.2024 4:27
The Chrome root program has changed the date for the Entrust distrust. Join us to get the details.
Root Causes 421: FIDO 2 Implementation Problems 16.09.2024 8:27
White hat researchers have raised concerns about FIDO 2 (AKA WebAuthn). We explain.
Root Causes 420: New Side Channel Attack Against YubiKeys 13.09.2024 12:43
EUCLEAK, a newly revealed side channel vulnerability, can clone the contents of a YubiKey. We talk about the attack and its significance.
Root Causes 419: What Happens to Vendors Who Don't Support ACME When 90-day Certificates Come? 08.09.2024 16:14
Though it is the closest thing to an industry-standard API, there are still products and operating systems that don't support ACME. In this episode we explore what happens to these products once 90-day SSL certificates become the requirement.
Root Causes 418: Moving from Cryptographic Homogeneity to Cryptographic Heterogeneity 06.09.2024 18:25
One seldom discussed consequence of quantum computers and PQC is the move from cryptographic homogeneity to cryptographic heterogeneity, with multiple KEMs and DSAs eventually expected as ongoing standards. We examine the consequences of this change.
Root Causes 417: Introducing pkimetal, the PKI Meta-linter 02.09.2024 8:44
We introduce pkimetal, an open source project from Rob Stradling that allows CA to write to many popular linters with a single integration. We explain the importance and pitfalls of linters and how pkimetal improves linter implementation.
Root Causes 416: SSL Subscriber Uses a Restraining Order to Prevent Revocation 29.08.2024 22:39
An enterprise SSL subscriber recently used a Temporary Restraining Order to prevent the proper revocation of misissued certificates. We explain what happened, why it's deeply problematic, and how the industry might consider responding.
Root Causes 415: What Can I Do with These New FIPS PQC Standards? 27.08.2024 19:33
NIST recently released PQC algorithmic standards in FIPS-203, FIPS-204, and FIPS-205 (ML-KEM, ML-DSA, and SLH-DSA). We describe what is necessary for enterprises to begin using these algorithms.
Root Causes 414: What Are the Revocation Periods for Public Certificates? 23.08.2024 11:57
In this episode we detail the mandatory revocation periods for leaf certificates and intermediates and explain when a 24-hour versus a 120-hour revocation deadline applies.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.