The CPS must always be a superset of actual practices in a properly running CA. We explain why this is a product of good design.
Root Causes Podcast


Podcast Tags
Contributors
Showing 19 to 36 of 550 podcasts
October 10, 20259 min
By Tim Callan and Jason Soroko
Imagine what happens if you use the wrong LLM, including a malicious model placed there for mischief or crime. How do you know? By signing our AI models.
October 7, 20259 min
By Tim Callan and Jason Soroko
We discuss how a static PKI structure can hurt corporate flexibility and resilience. Events like reorgs and M&A activity can cause intractable problems.
October 2, 202518 min
By Tim Callan and Jason Soroko
In this episode, Jason describes how we might use the principles of PKI in a purely offline scenario.
October 1, 202517 min
By Tim Callan and Jason Soroko
Public certificates are transitioning from multi-purpose root hierarchies to single-purpose ones. We discuss why.
September 29, 202519 min
By Tim Callan and Jason Soroko
We compare AI in 2025 to Internet in 1995 and describe the AI iceberg, including the majority of applications which are below the waterline.
September 24, 20258 min
By Tim Callan and Jason Soroko
Verified Mark Certificates (VMC) now have a companion product for logos that are not registered trademarks, called a Common Mark Certificate (CMC). We explain the differences.
September 18, 202517 min
By Tim Callan and Jason Soroko
A CA has incorrectly issued TLS certificates for the 1.1.1.1 and 2.2.2.2 IP addresses. We go into the details.
September 15, 202510 min
By Tim Callan and Jason Soroko
Client authentication using public TLS server certificates is on the deprecation path. In this episode we go through the key dates in this deprecation.
September 12, 20258 min
By Tim Callan and Jason Soroko
Based on the ready availability of AI-based voice cloning, we declare voice biometric authentication to be utterly valueless.
September 10, 202510 min
By Tim Callan and Jason Soroko
A new CABF ballot proposal will eliminate all email- and phone-based DCV over the next few years. We go into the details.
September 8, 202513 min
By Tim Callan and Jason Soroko
Three major changes are coming to the world of public certificates, all of which require major changes in how organizations deploy, renew, and manage their certificates. These are 47-day SSL, PQC, and the deprecation of mTLS. We describe the overlap…
September 3, 202511 min
By Tim Callan and Jason Soroko
MPIC (Multi-perspective Issuance Corroboration) is soon to move into enforcement phase. In this episode we describe three configuration decisions that can force Domain Control Validation (DCV) to fail and tell you what to do about them before you…
August 28, 202533 min
By Tim Callan and Jason Soroko
We complete our description and commentary on the results of Sectigo's survey of enterprise preparedness for Post Quantum Cryptography (PQC).
August 22, 202532 min
By Tim Callan and Jason Soroko
We're back discussing the results of Sectigo's 2025 State of Crypto Agility report. We explore the second half of the report on post quantum cryptography (PQC) including enterprise awareness of PQC, the most influential drivers for PQC migration,…
August 20, 202544 min
By Tim Callan and Jason Soroko
Sectigo released its 2025 State of Crypto Agility report which explores enterprise readiness and preparation for 47-day maximum SSL/TLS certificate term.
August 18, 202518 min
By Tim Callan and Jason Soroko
AI is not the elephant in the room. It is the room itself. Jason explains what he means by that.
August 13, 202517 min
By Tim Callan and Jason Soroko
Britain's National Cyber Security Centre recently issued a lukewarm verdict on passkeys as an authentication solution. We explore the problems with WebAuthn, including account recovery, spotty availability, inconsistent implementation, and lack of…