Certificate Lifecycle Management – Tim Callan, Sectigo
Sectigo’s chief experience officer, Tim Callan, shares from his vantage point what the CLM (certificate lifecycle management) space foresees in digital certificates in 2023 – the key to certificate management in the cloud, zero-touch deployment, crypto agility and more for enterprises. He will share firsthand what Sectigo is seeing how more and more attention spent on Certificate Authenticity (CA) agnosticism, like the recent encrypted code signing certificates that were exfiltrated from GitHub.
Transcript
This is Textron TV. Hey everyone, welcome back to techstruck TV. My next guest today is Tim Callahan.
Did I meant did I pronounce that right Tim? It's Callin, Tim Callan. Yes, Talent.
Yeah, I put an H in there. I'm sorry from New York. What do we know?
But anyway, Tim Callan is the chief experience offer. So with sikigo and he's gonna tell us all about that in a second, but Tim welcome to text trunk TV nice to have you on here. So glad to be here Alan.
Thanks for having me. Yes, thank you. So Tim, you know what?
I love the title Chief experience officer. We're seeing more and more. folks with that title, but for our audience, maybe who's saying Chief experience offers or a taxi do What exactly does the chief experience officer do so a lot of organizations they focus on on departmental Excellence.
So you'll get somebody who's in charge of a function like product management or sales or development or customer service and they focus on doing their job very well. And so what you can get is you can get a bunch of well-tended gardens in a poorly designed City because nobody's looking at the entire end and wall to wall customer experience. And so somebody like a chief experience officer is supposed to step back from Individual departmental functions and think about what is your holistic customer experience when you come and you interact with the company and you really want to make it more efficient more satisfying you want to solve their needs and you just generally want to make sure that your entire experience with that company is as good as it possibly can be excellent Excellent and Tim while we're on definitions and and this kind of thing.
Look I'm familiar with 60 go. I'm sure many people in our audience of at least heard of sectigo, but for those who haven't or who not sure tell us about sectigo. Well, if you have heard of us what you probably have heard about us is our public digital certificate business.
So we are one of the largest providers of SSL certificates code signing s mind certificates along those lines around the globe and we provide to you know, every Market in the globe. However, we're also a major provider of what we call certificate life cycle management or clf and CLM is a platform that will take care of all of your certificates because certificates are really treacherous things. They all expire a lot of them expire very quickly.
And if you don't know what they are where they are are they configured correctly. And when are they going to stop working? You can find yourself getting in trouble and so a good CLM platform will give you visibility control automatic renewal management of Education events things along those lines.
It takes a headache away from the IT professional. Let's you focus on more more important things. And it helps you from prevents you from having unnecessary outages or breaches because your certificates weren't we're in place or weren't correct.
Love it. So you were mentioning when we're off camera. Tim Google had an announcement recently in the last couple days.
Yeah around lifetime or you know expiration of these certificates. Yeah. This is a chairman.
Thank you Alan. This is a major development in the industry. So today public SSL certificates or TLS is the official name, but everybody calls SSL public SSL certificates are limited right now to one year.
It's 13 months. It's actually 398 days. And so right now as a public CA I can issue you assert for up to 398 days.
Google has recently announced publicly that they intend to drive that down to 90 days. Now in the event that this can be accomplished through a ballot in the ca browser Forum. That's how Google wants to do it.
However, in the event that that can't Google has signaled that they're prepared to prepared to do it unilaterally by making it a requirement for their brows and that's very important because that means instead of giving you a certificate that can last for up to 13 months. I'm limited to one quarter 90 days. And if you're managing a certificate on a server that you control every 90 days you have to go in and you have to renew that certificate.
So from where I said Tim is a business owner operates. I don't know. 20 websites that sounds to me like okay, I'm gonna automate this through my certificate provider so that I don't have to mess with it.
But I'll probably get a charge now every 90 days rather than once a year and so this sounds like this isn't gonna help me with my security. This is just gonna drive my certificate cost up and that that's not a good thing. So it doesn't necessarily have to so your cost is really gonna be a function of the ca so I'm sure that something will be done to make you whole financially.
So ever say is gonna have to make their own decisions when this rolls around but imagine I would say a one-year subscription. So instead of purchasing a certificate you purchase you're worth of certificates. And then you don't worry about the term of every given certificate you just get the new one when the new one needs to come.
So that's the kind of business model that I expect and maybe we'll let people buy things one off for Approximately one quarter of the price maybe we'll ask you to sign up first subscription for a year or two years or five years or who knows so nothing changes on that so I don't think so then I have yeah. No, I'm good. I'm glad to hear that.
So then what one of my what are we gaining by going to the 90 days? So the browsers are really interested in two things. The first one is what we call crypto agility.
So there were a lot of examples in the past where our cryptography turned out to be insecure and sometimes we found out that very suddenly there was an issue with Debian around 2010. There was an issue with I guess 2008 something like that. There was the hard bleed incident about a decade ago and then there are problems like the the deprecation of show one and in all of those cases one of the things that we found is that certificates lingered for a long long time.
Certificates it definitely were insecure that we're not reliable that sat around for years. And so there's been this drive toward what they call crypto agility, which is all of your kryptography needs to be renewable and changeable really fast. So if you shorten the duration of your certificates, you've got to build in maximum term, right if there's a bad algorithm, it can't last more than 90 days.
So this years old problem just kind of goes away. So crypto agility is a big one and then the second one is they really want to motivate automation. So the the browsers believe and I think correctly that manual management of certificates is a source of huge problems.
It leads to bad security. It leads to breaches. It leads to outages.
It's just it's really difficult to keep your certificates current if you're doing them by hand and there are great automation Solutions available lots of different choices. There's a very popular API called acne. There are good platforms.
You can use there's a lot of ways you can do this and by keeping by automating your certificate management deployment and renewal. It forces everything to stay current all the time and the browsers are trying to motivate that behavior by making it. You know just increasingly attractive to move to an automation solution and this helps with that as well.
excellent now first of all, thank thanks for all this. I kind of took us down a path, you know to on a specific thing, but I think our audience appreciates that but certificate expiration quarterly versus annually though Tim. What are some of the other?
Kind of big stories around certificate life cycle management if you will. For the year, the biggest thing that people should probably start to be aware of is that quantum computers are going to defeat the algorithms we use today. So today almost all of the encryption in the world is done with either RSA or ECC most of it's RSA.
But ECC is out there electric curve cryptography and both of those algorithms as it happens are gonna be rendered fundamentally insecure by quantum computers. So quantum computers. We think you and I think of quantum computers as oh faster computers right qubits can be more than a one or a zero, they can be a one hand a zero at the same time.
Therefore the overall speed of the computer will go up and we're going to get faster computers and that's true. And that's the the main motivation behind the development of quantum computers, but there are some accidents Of the fact that these architectures work differently and one of those accidents is that there are certain kinds of mathematical problems. The quantum computers will be much better at solving.
And one of these is factoring numbers down to their primes. So if you factor very large numbers down to their primes, that's the fundamental operation behind RSA. And RSA is it literally RSA will be breakable.
12 or 15 orders of magnitude faster than it is now by a quantum computer. It's ridiculously faster and it's so much faster that we can't solve the problem just by making keys bigger because they would be too big they would be unusable. And so we need a new algorithm same problem for ECC.
It's a slightly different problem. But the same thing happens is that the the mathematics behind it are easily defeated by a quantum computer. So there's an effort now to switch everything out.
So nist, the National Institute of Standards and Technology drove a multi-year program. It involved academics industry and government to come up with new algorithms. And we have new algorithms that are not subject to the quantum computer problem to to this what we call the quantum apocalypse and these have names they're called crystals Khyber and Crystal's dilithium and and don't worry about what they are.
But these new algorithms are and they use different strategies and we can get into that if we want some time, but basically these new algorithms need to be substituted in for all of our existing cryptography everywhere. And so right now industry is working on that standards bodies are working on it companies like minor working on that. hardware and software providers are working on that and that work will probably take place for Another sometime in 2024 will probably be able give you a certificate.
I would say that has these new algorithms. Yeah, and and that and under those and when that occurs we're all gonna need to swap. Everything out everything every absolutely it's heartening.
Yeah, you know Tim I we had someone on from this I bet you two years ago two and a half years ago who spoke to us? Oh made the audience aware about the quantum up you approaching Quantum apocalypse, and I remember when listening to him then I wasn't sure how much of it was, you know. Pie in the sky and then part of me said they'll never get out in front of this right because we just don't do it.
So to hear that we actually are out in front of it and maybe by 2020 for we'll have something. We're kind of out in front of it. There's a there's a problem called harvesting decrypt and what harvesting decrypt is is let's say I'm inside your network.
Let's say I can see your encrypted blobs. Let's say I know that these blobs are valuable with valuable Secrets, but I can't be crypto. What I can do is I can capture them Excel trade them and just store them.
And wait for a quantum computer to come along now. Some Secrets aren't gonna be valuable in a couple years who really cares because my credit card number will be expired. Right?
It won't really matter. But some Secrets will be imagine, you know, very valuable industrial and process secrets that are good for decades, imagine health information imagine, you know military information the the plans of the Spy playing or the names of all the secret agents. This is all stuff.
That's still going to be a secret in five years or 10 years. And so if people are getting into networks now and sealing this stuff that could already be a problem. And so what that means is as soon as we get the new cryptography we want to start using it right away, even if we don't think that the quantum computers are ready yet because what if the day after that is the day that somebody comes in and harvests my secrets and if I'm on the new cryptography doesn't matter, they can't break it with a quantum computer.
So that's part of the for the hurry up. Nobody thinks that a quantum computer can do this today. What we're worried about is these secrets that it can be can be harvested and consider around and someday in the future can come back to haunt us.
Yeah. okay, I mean just guys I think the problem is gonna be is when you when you need to just change an entire. environment an entire echo system You know, they'll be obvious places where of course you're gonna change stuff, but then there'll be the gotchas.
I forgot that one. So I don't even think that one and those and those will haunt us for years sure, but you know, but the good news is the majority of it will hit. I agree.
And so one of the things we're encouraging people to do is understand your cryptography inventory or crypto find out what you have find out where it is. There's a lot of Rogue certificates out there that people don't know about there's Rogue Cas out there. There's Rogue encryption out there that people that the office of the ciso doesn't even know about because some developers just put something in right for instance.
If you're operating at devops environment, you've got a CA or it doesn't work. You may not even know about it. And so those are the kinds of things you want to find.
And make sure you understand what they are and make sure you have an agile method of updating them when the appropriate cryptographic software is available to you. Absolutely, you know and this is another because one of the big things let's say cloud native is immutable infrastructure, right? Sure.
This is where it'll help you because as you turn up new infrastructure just add the new certificates and and it kind of gets built in there. Anyway 10% Then that the whole crypto things in exciting thing, I'd love to go into more of these with you, but we're already past 15 minutes. We barely I feel like we barely started absolutely.
I know maybe we'll have you on again Tim and we can talk more about this because it's exciting stuff and I think it's stuff. Our audience needs to information. Our audience needs to know Alano is a pleasure and I'd love to do that.
Alrighty, Tim Callan Chief experience officer sectigo here on Tech strong TV. We're gonna take a break and we'll be right back.