Podcast
Root Causes 189: What Is CA Agnostic?


Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
November 17, 2021
Certificate Lifecycle Management (CLM) platforms can deal with certificates from a number of sources. A CLM that can provision certificates of all types from all CAs, private and public, would be described as "CA agnostic." In this episode we explain this idea and its significance along with the key criteria for choosing a CA agnostic CLM platform.
Podcast Transcript
Lightly edited for flow and brevity.
So, let's define what CA Agnostic means. In short, if I can take an attempt at it, then you can change it if you want, Jay, but that simply means that your CLM is prepared to take all certificates from all CAs; so, that could be your private CA; it could be your MSCA; it could be your certificates from public certificate authorities and treat them all identically. They all have the same capabilities and they all basically have the full, robust capability of the CLM available for them, and that this needs to happen not only across CAs, but also across certificate types. So, all the different types of certificates you might use from all the different CAs. All of that needs to be handled the same way in your CLM. How do you feel about that definition?
Therefore, that's really the almost the prefix to what you've said, which is why CLM which then leads to why CA Agnostic, which is, you know, it's just, it's just too darn difficult to manage all those certificates. It's better to let a computer do it. It's better to let a good CLM, a good Certificate Lifecycle Management System deal with it. And it's not just about scheduling the renewal of the certificate, it's about the provisioning technologies, it's also about giving visibility to all your other digital identity types, as well and we'll get into that.

