Certificate Authenticity Agnosticism – Tim Callan, Sectigo
In a continuing discussion, Tim will share more firsthand insights from what Sectigo is seeing in how more and more attention spent on Certificate Authenticity (CA) agnosticism. With a breadth of cyber experience, Tim dives into the latest trends from quantum encryption to the passwordless future.
Transcript
This is texturing TV. Hey everyone, welcome back to Tech strong TV. You know our next guest here.
This is gonna be sort of a part two. He was on just a little while ago and we we started talking about something but I invited him back because I thought like we really did it. Peel the onion enough layers down there to get to what we wanted to talk about.
Let me introduce you to Tim Cowan Tim is Chief experience officer at sectigo. Hey, Tim, welcome back. Thanks glad to be back.
All righty. So Tim, you know what? Let's assume maybe people haven't seen or they don't remember our interview just a short while ago.
Why don't you why well, first of all, let's start a little bit about you and give him a quick secular and then let's jump into this. I'm Chief experience officer. It's a Tigo is one of the world's largest public caes and one of the world's largest providers of certificate life cycle management, which is an automated platform to take care of all your certificates, and we're here to take to talk about developments in the world of public certificates.
Perfect. And so just to bring the audience up to speed the last time we were together Tim. We were talking that they're going to start.
Well, I think it was Google Chrome, right? Yes. This was only a Google thing.
I should emphasize it at this point anyway, but that Google Chrome. Okay, you might have an update for it's a it's a Google thing but it's going to affect everybody and so yeah back that I'll get into the detail. Yeah, but the idea here is is that all SSL certificates now have like it's a 90-day life span.
So like butterflies and and You know after that you need to you need a new certificate and just for for those of us in the audience who are not familiar with how SSL certificates are working and everything. You know, that's that https right in front of your website address in front of you URL. And so it is encrypted with the certificate and generally those certificates were one year or two year.
A lifetime certificates, right Tim. Yeah, what we've seen is we've seen crease in the certificate lifespan over time once upon a time there. are no and literally there are Cas were out issuing 10 years certificates and then starting in 2012 with the Baseline requirements rules started to come into place.
And first they were restricted to three years and then later two years and a couple years ago. They got knocked down one year and so the new proposal from the chromium project from the group Google Chrome Roots store is that they are going to Bring that down to 90 days in maximum term. So we're Once Upon a Time.
You could have stuck a certificate on a box and not thought about it for three years. Now. Those certificates need to be swapped out every 90 days and if they're not they expire and when they expire everything stops working.
excellent, so Let's just read it. And I realize it might be a little rehash. What's the logic behind this?
Well, so there's a few real advantages that come with shorter lift certificates. One of which is they're just plain safer. So let's suppose that something bad happens like a private key gets compromised or certificates gets Miss issued, but nobody realizes it if you shorten the duration of the certificate you shorten the window for exposure, right 90 days certificate.
It's just less time to exploit a problem than a one-year certificate and that's less time than 10 years certificate. So that's rational. Number one rational number two is there's a better alignment between certificates and domains.
So let's say that I buy a certificate for a certain domain name and then tomorrow I sell that domain name to somebody else. I'm now holding a certificate for domain. I don't know right and so they want to limit that as much as they possibly can and shorter live certificates limit that problem as well.
Then the third thing in general is that a high level the browsers really want to encourage the use of automation, they believe and I think correctly. That 90% of the problems that we have with certificates would be alleviated if we had computerized automated systems to manage them for us and that too much manual management of certificates really is the problem. And so so, you know, you might say with two-year certificates.
You might say I no big deal. I'll just doing manually and then with one year certificate some people said, ah, this is too much for me. But a lot of people still said, hey, I can still make it work.
So now Chrome is saying okay, how about 90 days certificates? Right? And they're trying to get people off the money to say, I'm gonna go ahead and I'm going to automate this because that really is the the most accurate most secure highest up time kind of solution.
Excellent. All right. I think we've done a great.
We brought people up. Who may have not seen the first episode Tim? Because from here if you don't mind well, so a question I get a lot is well, when is this going to happen?
That's one of the big ones and you know this there isn't an announced timeline on this. However, I am estimating for a variety of complicated things. We probably shouldn't get into that.
We should be probably looking at quarter 4 2024 for these to be in production. Meaning that's the time frame when I am not going to be able to issue you a certain longer than 90 days anymore. And so you back up from that.
Let's say it's I'm gonna make up a date October 1 if it's October 1 then you start to say, okay. Well, how long is it going to take me to fully automate my own systems and environments to be ready for that and you know for a lot of people that could easily be a 15 month 18 month kind of project. So now you start to back up and you say oh well, guess what?
That's now. So one of the responses we've seen from this is there's just been a huge amount of attention. Among it professionals when they hear this news because they're trying to understand things like what do I need to do?
And when do I need to be doing it? And for a lot of them the answer kind of is well. Gee I need to get started pretty soon.
Like it's sort of time to spin up a project and start dealing with this and that's why we're out trying to tell people so that they don't get caught flat footed and one day they wake up and they start their project and it's too late to get it done. Absolutely, and you know, it's funny the interview before this. I was talking to someone about algorithms in a post-script topic in a post-quantum world for cryptography and again, You know, you don't want to wake up one day and find out that all the keys all the locks in your house are now useless.
Yes, right and it's the same thing here. You don't want to wake up one day to you know, the the remember these three the little lock in the browser that would show your your encrypted and when it wasn't working there was the line through it. We don't want to work.
Wake up one day to that now. for sectigo, though Well, let's not protect Eagle for our audience out here Tim. Do they look at this and say what an evil plot cooked up by Google and say Tigo and the other Cas to make us buy more certificates right and make more money for themselves.
But that's not the case. I don't see why it would be more expensive. So the duration of the certificates absolutely they're gonna have to be down and that means that the total number of certificates that will operate over the course of a year.
We'll have to go up right. However, The value that a subscriber is getting from securing their Hardware really is the same right and maybe it's a little higher because they're more secure but it's essentially the same and I think you're going to see prices will account for that. So if you want to you know, I can if you want to buy a 90 day shirt caes will probably sell them to you and they'll probably sell it for roughly a quarter the price of what is yearly.
Yes. I I imagine that the new models can be much more about subscriptions. Like I want to buy SSL from you for a year for this fully qualified domain name and I'm gonna pay you some money and then as often as I want to swap out the search, I'm just gonna get a new one and plug it in.
And there's no reason why it needs to be every 90 days. Especially if you're an automated. How about once every two months?
How about once every month? And at that point you can just let it run and if it's no extra cost to you then that's actually what everybody would prefer and so I'm imagining if I look at my tea leaves that that's kind of where the industry is going to go. And actually I think that's good and healthy.
Yeah, I mean look if you could. Like so many other things if you could automate it like this, yeah. Like you described.
Yeah, we could we could raise the bar on security. Look every 30 days you're gonna have a new certificate. You've got an effect that you got a bad site within 30.
It has a lifetime of 30 days at the out at the most, right? What? If we could take the cost out of the equation what why should people even?
You know, it's it's a good thing Tim. Let's talk about it though from sectigo's point of view. Managing that well, I guess it's just the initial capex of building that automating automation system to issue and put in place the new certificates, but it would you know, there's definitely some more work on sikigos part there.
Now, there is our our overall systems go up right we where we would have been had a certain amount of systems burden to take care of our customers. Now, we're gonna have maybe six times that burn let's say if somebody's doing it every two months on the average, so that's real. Right that that is a real thing that is deserved deserves some some amount of awareness, but it's something we can weather and something we can handle from the from the Enterprises perspective.
They are going to mostly if they're automated. It's mostly going to be the same. We think organization validation is probably not going to change which means that could be occurring just once a year and that would be fine.
That's probably the most burdensome part for the Enterprise. The other one is domain control validation where you prove that you own a domain that will also be limited to 90 days as part of this change. But again, if you've automated it, you know really care.
It just runs you don't notice it you don't care if you manually doing DC me that sucks. That's a good reason not to so you're right. There's sort of these up front Investments that everybody's got to make and you can sort of think of them as one offs.
And once those are done the burden and the overhead should really be pretty low on everybody. It's just getting to that automated point. A great a great Tim as we mentioned that the outset that right as it exists right now.
It's a Google Chrome. or chromium kind of requirement but you know people don't we don't live in a balkanized world of web browsers where I you know, I'm gonna serve a we did it one time back when I first got involved. Oh, yeah, you you would look and say okay what browser are you using and you'd serve up a particular?
Version of your site because you know, there was different HTML all of that stuff, but we don't thank God we don't we don't live that way anymore on the web. But I got to imagine that you know, Microsoft. Mozilla and some of the other browsers are going to match.
chromiums requirements here because I mean if everyone's already doing it and it's better for security. Why not? Well, the first thing that the Chrome team has announced is that they're gonna attempt to accomplish this through a sea browserform about so they intend to introduce a ballot that will actually limit it to 90 days.
And then if that valid passes the same browser form, that'll be back. And there's good reasons for that and and some of those are just because the browsers while the browsers are willing to make utilateral changes when they need to and we've seen Apple do this. We've seen Chrome do this.
We've seen Microsoft do this. What's the Mozilla do this? They don't want to what they really want as a consensus in the community.
It's better for everybody. And so they're gonna try to get that consensus. However, they've made it clear that if they don't get that consensus they are prepared to act, you know, And in the event that they do every CA still has to comply because you're not willing to walk away from chrome.
I don't think there's a Cas says well, I won't work in the Chrome bar browser, but that's okay because my customers only need Apple like I don't think that exists in the real world. So any any real CA is gonna say, well I require Chrome or I'm valueless as a public certificate Authority and therefore I have to comply with more prone says and so it has the power to bring the whole industry on board just because of Chrome's power in the market. Got it.
You know, we're running low on time but Tim for people who are interested in this want to find out more what kind of I mean is there resources on the sectigo site we could send them to or somewhere else out of resources. com, we've got a whole section on the category is called certificate lifecycle management or CLM. So there's a whole section on sale M and certificate life cycle management.
Another resource I want to recommend is I co-host a podcast called root causes which is focused on digital certificates pki encryption and things like that and you can find that where we listen to them. So the root causes podcast as you can imagine, we are hitting this in great depth all the time. So those are two resources I'd suggest for people who want to know more love it.
Tim thanks for coming back on and taking up as I said peeling the onion back a few more layers. We appreciate all the all the hard work you guys do on this keep it up and come back and keep us posted on this. It was my pleasure Alan and I'd love to be back with more things develop any time tip Allen.
Here's Chief experience officer at sectigo. Keep your eyes open your your ssls are only going to be good for 90 days. You got to set it up.
That's we're gonna take a break here on Tech struck TV. We'll be right back in a moment with another guest.