It is surprising that we continue to see root expirations occur at the most inopportune times. Weekends, public holidays, even New Year's Eve. In this episode we have simple advice to anybody setting up a new root, which is "look at a calendar."
Tim Callan
Tim Callan has over 20 years of experience in the SSL and PKI technology spaces. Tim leads Sectigo's conformance with industry and regulatory requirements including browser root programs, WebTrust, CA/Browser Forum, and more. Tim is instrumental in driving initiatives to improve certificate agility and successful issuance. A founding member of the CA/Browser Forum and current vice-chair for one of its working groups, Tim is creator and co-host of Root Causes: A PKI and Security Podcast, the world’s most popular podcast dedicated to digital certificates. With 400+ episodes published, Tim is on the forefront of explaining trends that will be essential to the IT professionals, including shortening certificate lifespans and the coming change to post-quantum cryptography.
Recent posts by Tim Callan
SSL hasn't been a standard in use for nearly thirty years, but we still use the word. We discuss why that is, what else we might say, and the expected effect of Merkle Tree Certificates (MTC) on our technical vocabulary.
Join Sectigo as we explore why traditional automation models are reaching their limits and how organizations can evolve from disconnected certificate management practices to centralized certificate lifecycle orchestration.
A newly revealed flaw in Active Directory Certificate Services (AD CS) allows an attacker to improperly obtain cryptographic credentials for an agent. We discuss the implications that this flaw Certighost (pronounced sert-uh-GHOST) has for agentic AI at large.
With the upcoming deprecation of client authentication using publicly trusted TLS certificates, we go over the common use cases for these certificates. We discuss the reasons public trust is often chosen and how to transition away from it.
Anthropic recently announced that Mythos has found mathematical weakness in the core algorithm for the third-round NIST PQC candidate HAWK, effectively halving its effective key strength. Mythos also developed a faster attack on a round-reduced version of AES-128. These are not implementation attacks but mathematical attacks on the core cryptography. We discuss the massive implications of these developments.
Because of a change in the drop-dead date, we have observed confusion about the timeline for deprecation of client authentication and mTLS for public TLS certificates. This is an inflexible deadline, and enterprises that are not ready risk outage. In this episode we spell out these dates very clearly.
In our series on digital identity for AI agents, we discuss FAPI 2.0 as an option.
In our ongoing series on digital identity for agents, we have previous discussed use of certificates for authentication. In this episode we describe how cryptographic proof of possession can enable secure authentication using tokens.
