Podcast
Root Causes 104: 21 PKI Pitfalls to Avoid


Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
July 6, 2020
Our hosts often discuss the idea of errors in PKI implementations and the potential negative consequences for organizations. In this episode they categorize twenty-one PKI pitfalls to avoid according to five main categories of error: certificate problems, deployment problems, systemic security problems, governance problems, and visibility problems. Join us for a crisp description of these twenty-one pitfalls so you can be on the lookout for them.
Podcast Transcript
Lightly edited for flow and brevity.
Alright. Security problems. So don't worry, there's only two of these. We are up to number 11. Number 11, not properly protecting your private keys.
Alright. Governance problems. Number 13. So just at a high level, number 13 is lack of governance at all. Lack of a policy. So, it's the Wild West. People just get to do whatever they want and there's no rules and there's no guidance.
Alright. So, number 14 – Certificate practices or shall I say CPS problems. So, there are a variety of ways that your CPS can be bad.
Alright, number 16. Sixteen and 17 I'm gonna go together cause they're flips of the same thing. Which is, choosing public certs when private would serve you better or choose private certs when public would serve you better. So thoughts on that Jason?
Alright. Visibility problems. We are up to number 18. We are almost there, folks. Don’t despair.
Eighteen – allowing rogue certificates to operate in your environment without taking them under management.
The second one that's more universal and helpful in this regard is certificate discovery. You go out. You crawl your network. You find the certs. Now you know what they are. Now you don't get surprised by expirations or certificate problems like we had in the first one or lack of automated renewal like we had in the second section. Like all that stuff gets easier and more addressable once you know what those things are.

