90-Day Certificates – Tim Callan, Sectigo
“Most businesses are NOT prepared for mandatory 90-day certificates. Nor are they prepared for the anticipated 4x increase in the amount of work they will face,” according to Tim Callan, chief experience officer at Sectigo, a global leader in automated Certificate Lifecycle Management (CLM) and digital certificates. Learn more on TSTV.
Transcript
This is Techstrong tv. Here we go. Hey guys.
Thanks Viro. We're here with Tim Callen's, chief Customer Experience Officer for Secco, and we're talking about this transition to 90 day renewals of certifications. Sounds like it's gonna be a major challenge.
Tim, welcome to show. Welcome. I'm, I'm happy to be here.
We've seen over the years that people have not necessarily had the greatest processes when it comes to managing their certificates. And now it looks like, uh, we're gonna tell 'em to do it faster. What's your sense of what's driving that conversation?
Is this a new mandate from whom? And, um, what impact is it gonna have? So on March 3rd, the Google Chromium Root Store announced their intention to create a requirement that Publicss s l certificates be not longer than 90 days.
In term, to put things in perspective, right now, they can be up to 398 days, which is 38 mo or which is, uh, 13 months. And so that's a pretty big change. And the stated reasons to do that from the chromium project, first of all, are that shorter certificates are just more secure.
Cuz if there's a problem, a compromised key or a bad cert or something, there's just a shorter window where, where, where bad things can be done with it. Uh, but they also wanna produce, uh, uh, certificate, um, crypto crypto agility where we can change our cryptography more fa more, more quickly in general. And they want to diminish the time where there might be a mismatch between domain names, ownership and the actual certificates for those domains.
And all those things get collapsed when you go down to 90 day certificates. So those are the drivers. And you understand why those are things that are gonna be better for the ecosystem.
Is everybody gonna follow suit? Do you think there'll be eventually maybe some sort of government mandate to go with this? Uh, we don't need that.
I mean, Google Chrome has sufficient power and, uh, share in the market that when they make a root store requirement, any public ca needs to follow or their certificates just aren't gonna be usable. So, uh, that has, that has the power to completely move the entire market that way. Now, it may be that the ca browser form, which is the industry standards body, might do this through their own balloting process, but even if they don't, if Chrome makes this declaration, it's, it's a fade to complete.
It's something that will occur and we will all begin to live with. Will this therefore accelerate the shift towards making the management of certificates part of a DevOps workflow? Because we are gonna be updating them more frequently?
Yeah, we agree. We believe that whether or not it's, it's in DevOps per se, that the, the need for automated certificate management just spikes with this kind of declaration, even as it is with one year certificate durations. We see expirations occurring all over the place.
It happens all the time. It's, you know, a a a really unfortunate reason to have outages and services not working and security breaches and things along those lines. But it occurs once we're down to 98 maximum term.
Uh, we think that need is just gonna be, you know, an order of magnitude greater and as a consequence there will be a lot more motivation for enterprises to use, you know, use that kind of solution. Do you think people are gonna be aware of this or are we gonna see like a spike in outages for a few months after this whole thing? I am, I am predicting if there's a day when, when it's the last day, you can sell a one year cert, let's call that T zero.
I am predicting that on T 90 we are going to see a whole bunch of outages, which is unfortunate. We'd rather not, right? So part of what we are doing, uh, at Tigo is we're trying to get out to the people who make these decisions and make sure they do know.
Because, you know, we're in this world, we belong to ca browser forum, we pay attention to what the browser programs say. Most people don't. And they need somebody to let them know this is coming.
You have to have a plan, you have to deal with it, and you have to make it work better. Will organizations and the folks who manage this find themselves in a lot more hot water than they might have in the past? Because there is so much more writing on these services.
So is this gonna be a higher level conversation in an organization soon? I think you're, you're, you're definitely touching on one of the trends that's just been going on over the years, which is that as our systems become more dependent on their digital nature and as they become more interwoven, the consequences of an outage go up. So once upon a time you would've had a single isolated processor system would've gone down.
You would've people inside your department who couldn't do their work and would've figured out what was wrong and fixed it and there would've been a little bit of backlog. But now it's like everything's connected to everything else. And if you pull out one pole, the whole tent comes down.
Right? And we've seen this, A great example was, I think it was 20 eighteens O two outage or O two and SoftBank and several other mobile providers lost digital service for an entire day, 40 million people without service. And it all went back to a single expired certificate that just created cascading failures that took down these entire networks.
So that's the world we're living in today. You think people need to go back in and then figure out where all those dependencies are because to your point, um, it is a much more complex world and you never know when some certificate somewhere might disrupt the whole thing. Heck yeah, you're absolutely right.
So we get this question a lot when we talk about this. People say, well what can I do today? And the first thing is inventory your cryptography.
Because whenever we work with large enterprises on this, one of the things we discover is there's always crypto that they do not know is in place. And they find out the hard way when it stops working. So this is your chance.
Find it, get it automated and get ready for the new 90 day world. You cannot walk down the street these days without somebody coming to tell you about their great new AI thing. So will AI get applied to certificate management and save us from ourselves?
You know, certificate management is interesting because it's a very discrete programmatic kind of things. It doesn't require ai, right? We have specific certificates they need to be replaced.
We know where they are. We know what replacement looks like, we what installation looks like. All of this can be done with good old fashioned software development.
Will AI help? Uh, could be maybe, but AI wasn't a requirement for this. The real requirement is that enterprises just need to prioritize it and get it done.
Who's in charge of this step these days? Is it the developers? Is it the security people who's assuming responsibility for the management of certificates?
That is part of the problem. Certificates are everywhere. They're a ubiquitous building block.
Um, it's kind of like nails. Let's say there was a big development project and you guys are building a skyscraper and you said, who's in charge of the nails? You go, I don't know, everybody uses nails.
And that's kind of an how it is with certificates. But the problem is nails don't expire. Nails don't just stop working one day.
Uh, but certificates do. And so you know, somebody usually, you know, who rolls up to the office of the CIO or the C I S O really should get these things under control, find them and figure out where they are because that's where you have these unpleasant surprises where just suddenly something's not working and nobody knows why. Mm-hmm.
The other issue is there's a lot of certificate authorities out there. So, you know, is is there a reason to go with one over another? I mean, what differentiates one authority from the other?
So the certificates themselves are very similar. So what you probably really wanna look at is what is the CA that can service the full set of needs you have? So you're going to need help with automation.
You might need support for protocols like acme. You might want to make sure that they have a full range of all the different certi certificate types you need. You might want somebody who has a certificate lifecycle management offering that they can plug in or who can offer you a private ca or other things you might need to really flesh that out.
And that's a really good way to choose a vendor. Another good way is track record. You know, in the last year we have actually seen two public cas have their trust deprecated by the major root stores.
So you also wanna think about who's the ca who I'm confident is going to be around for me. Do people have an appreciation for which type of certificate to use when it seems like, you know, maybe they all default to one kind, but there are multiple kinds. So, um, are we getting savvier about how to use them?
There are many kinds and some of it's real easy, you know, code signing's, code signing. You can't sign your code with anything else. Um, TLS is dls.
You put it on your servers, can't really put something else on your servers. Some of it gets a little ambiguous. The main point of ambiguity is probably public versus private.
So there are times when you can be your own certificate authority and you can issue your own CT that you control. There's good reasons for that. Like, I have more flexibility on what my certificates are cause I don't have those outside requirements.
They can be any term I want. But then sometimes you really want public certificates because you want everybody, whether or not they're in your direct control or your walled garden to be able to see and understand these certs. And for those you really need public.
So it starts from the use case. What am I doing? What am I trying to accomplish?
And then you can pick the certificate that meets your needs. Right. You mentioned code signing and of course we have a lot of focus these days on securing the software supply chain.
Mm-hmm. Are we starting to see a lot more usage of certificates in application development efforts? You know, certificates are definitely a very important part of that ecosystem.
I think the software supply chain challenges that the industry has faced are fairly young in the grand scheme of things. And a lot of people are still wrapping their heads around what's required. Code signing absolutely is an indispensable part of that process, which unfortunately is not always in place.
It's frequently in place, not always. And for the people who don't have it, yeah, you should get going on that. All right.
So what's that one thing you see your organizations doing over and over again that just makes you shake your head and go, folks, I think we're better than this. I think I, I think it's, I think it's the failure to embrace automation. Automation is a silver bullet in this regard.
You have error prone human who could be doing extremely difficult things that only humans can do. And instead they're doing the rote robotic work that a computer could do for you. And it's a shame we have a skills gap.
There are always people who want to have more it that done than they can get done. And they have employees who could be contributing to that, who are doing something very repetitive and committing errors in the process because it's not what humans are best at. And I'm surprised when I see the number and the scale of organizations that haven't really gotten on board with automation and that, you know, that probably is the biggest thing we'd like to see change.
Alright. And then looking down the road, I mean, it's great to tell everybody about the issues of the day and their problems they're gonna have, but you know, what's coming down the road in terms of certificate management that people should look forward to and kind of making their life a little easier. You know, I think that's, that's um, you know, certificate management is continuing to evolve.
It also is a fairly young category in the grand scheme of things. And there's a lot of opportunity for vendors just to put in the features and capabilities that you wanna see. I think another important thing that's coming down the road that people should be aware of is that when quantum computers really become into the mainstream, we're going to have to change out all of our cryptography, cuz our RSA and E C C algorithms will be fundamentally broken by those computers.
And in that kind of timeframe, there's a whole new set of what we call pqc or post quantum cryptography that's already been arrived at that you're gonna have to switch over to. And that's another reason to know your cryptography, to put automation in place, to put, uh, uh, what we call quantum agility or, or sorry, crypto agility or certificate agility in place is that way when those new algorithms need to be adopted. You'll be able to do that as an organization.
All right, folks, you're heard in here. Once again, you know, an ounce of prevention is worth the proverbial pound of cure and there's gonna be a lot of pain around certificates if you're not paying attention. Tim, thanks for being on the show.
Glad to be here. All right, back to you guys in the studio.