Root Causes: A PKI and Security Podcast

Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject matter expert) will help you stay current on developments in this essential technology platform and to understand the whys and wherefores of popular Public Key Infrastructures.

Root Causes 539: What Is the Two-QWAC Architecture?

A new kind of eIDAS QWAC (Qualifieid Website Authentication Certificate) is on the way. The "two-QWAC architecture" introduces a second certificate containing organization information to be displayed by the browser, to sit alongside but independent of the certificate that authenticates a domain. We explain what's coming and why.

10-22
20:02

Root Causes 538: What Is an Entropy Desert?

An environment in which credentials are extremely predictable could be described as an entropy desert. There are occurring at a global scale. We discuss concepts like measurable entropy availability and entropy by design.

10-20
09:02

Root Causes 537: The Thermodynamics of Privacy

In this episode we build on our concept of entropy-aware guidance to explain how we might quantify privacy. We touch on GDPR, proof of work, and Landaur's principle.

10-17
13:34

Root Causes 536: Patent Blocker on ML-KEM

A patent dispute in 2024 nearly blocked ML-KEM. But emerging thinking raises concern that the 2024 resolution did not guarantee full, clear access to all ML-KEM implementations. We explain.

10-15
11:51

Root Causes 535: The CPS Is a Superset of Actual Practices

The CPS must always be a superset of actual practices in a properly running CA. We explain why this is a product of good design.

10-12
10:22

Root Causes 534: Signing the Machines That Think

Imagine what happens if you use the wrong LLM, including a malicious model placed there to create mischief or crime. How do you know? Jason proposes that, the same way we sign our code, we should be signing our AI models as well.

10-10
08:56

Root Causes 533: Flexibility Through Multi-CA Trust Models

We discuss how a static PKI structure can hurt corporate flexibility and resilience. Events like reorgs and M&A activity can cause intractable problems with the wrong PKI setup. Plus, Jason coins the term PKI archeology.

10-07
09:25

Root Causes 532: Introducing Offline PKI

In this episode, Jason describes how we might use the principles of PKI in a purely offline scenario.

10-02
11:04

Root Causes 531: Benefits of Single-purpose Root Hierarchies

Public certificates are transitioning from multi-purpose root hierarchies to single-purpose ones. We discuss why.

10-01
16:36

Root Causes 530: Introducing the AI Iceberg

We compare AI in 2025 to Internet in 1995 and describe the AI iceberg, including the majority of applications which are below the waterline.

09-29
18:46

Root Causes 529: What Is a Common Mark Certificate?

Verified Mark Certificates (VMC) now have a companion product for logos that are not registered trademarks, called a Common Mark Certificate (CMC). We explain the differences.

09-24
07:32

Root Causes 528: Misissued SSL Certificate for 1.1.1.1

A CA has incorrectly issued TLS certificates for the 1.1.1.1 and 2.2.2.2 IP addresses. We go into the details.

09-17
17:31

Root Causes 527: Key Dates for the Deprecation of Public mTLS

Client authentication using public TLS server certificates is on the deprecation path. In this episode we go through the key dates in this deprecation.

09-15
10:25

Root Causes 526: Voice Biometrics Are Worthless

Based on the ready availability of AI-based voice cloning, we declare voice biometric authentication to be utterly valueless.

09-12
08:32

Root Causes 525: The End of Email-based DCV

A new CABF ballot proposal will eliminate all email- and phone-based DCV over the next few years. We go into the details.

09-10
10:03

Root Causes 524: How to Kill Three Birds with One Stone

Three major changes are coming to the world of public certificates, all of which require major changes in how organizations deploy, renew, and manage their certificates. These are 47-day SSL, PQC, and the deprecation of mTLS. We describe the overlap between these efforts and how to combine them for better efficiency and project management.

09-08
12:42

Root Causes 523: Will Your Configuration Block MPIC DCV?

MPIC (Multi-perspective Issuance Corroboration) is soon to move into enforcement phase. In this episode we describe three configuration decisions that can force Domain Control Validation (DCV) to fail and tell you what to do about them before you have a problem.

09-03
11:16

Root Causes 522: How Prepared Are Enterprises for PQC? (Part 2)

We complete our description and commentary on the results of Sectigo's survey of enterprise preparedness for Post Quantum Cryptography (PQC).

08-27
33:28

Root Causes 521: How Prepared Are Enterprises for PQC? (Part 1)

We begin to go over the results of Sectigo's recent survey of enterprises and their preparedness and plans for adopting Post Quantum Cryptography (PQC).

08-22
32:22

Root Causes 520: How Prepared Are IT Teams for 47-day Certificates?

Sectigo has released the results of its survey of IT professionals in charge of certificates to measure their readiness and preparation for 47-day maximum certificate term. We go over the results.

08-20
45:05

Recommend Channels