Podcast
Root Causes 211: Does CLM Make Wildcard and MDC Irrelevant?


Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
March 14, 2022
Wildcard and multi-domain certificates have traditionally made administration easier for IT departments. In this episode we weigh the degree to which Certificate Lifecycle Management (CLM) renders these benefits obsolete and if these certificate types continue to be worth the increased risk they carry.
Podcast Transcript
Lightly edited for flow and brevity.
What about the pure multidomain scenario? So, I've got a multidomain certificate. I'm creating multidomain certificates and if I have good CLM in place, conceivably I could just have a bunch of single domain focused certificates available instead. How do you feel about that?
Therefore, that, to me, is if you're gonna do a multidomain certificate, keep in mind that that list should be tight. That's why I argue it should be a short list of sites that you're totally comfortable with if one site gets compromised. If the certificate somehow is compromised, the private key is compromised, you’re ok with very quickly reissuing for those properties in total. If you've got a dozen, two dozen or more properties within that one multidomain certificate, you've got a lot of work on your hands.
It's food for thought for those of you who are doing certificate procurement, and you're trying to plan out your certificate purchasing and whatever it is, however it is you're going to be setting things up. I think that nobody has done a great job yet of connecting the dots of certificate lifecycle management should fundamentally change behaviors that are so entrenched, and I think in this case, that this is a really good example.

