Root Causes: A PKI and Security Podcast
Short, frequent episodes on PKI, certificate policy, and post-quantum migration from two certificate industry veterans at Sectigo. 670 episodes and counting.
- Hosts
- Tim Callan, Jason Soroko
- Publisher
- Sectigo · Vendor
- Pillar
- Machine, Workload & Secrets
- Level
- Architect
- Format
- Co-host discussion
- Cadence
- Two to three per week, 10 to 30 min
- Status
- Active, last episode 2026-10-01
- Since
- 2019
- Episodes
- 670
What it is
Root Causes is Sectigo's podcast, hosted by Tim Callan and Jason Soroko since March 2019, with more than 670 episodes. Two certificate industry veterans discuss digital identity, PKI, and cryptography: certificate lifetimes and CA/Browser Forum rule changes, Merkle Tree Certificates, the clientAuth extended key usage deprecation, and national post-quantum migration programs.
Who it suits
Engineers and architects who own certificates and machine identity, and anyone who needs to keep up with fast-changing WebPKI policy. See our certificate lifecycle guide for background.
Editor note
The most reliable way to stay current on certificate and PKI policy: episodes are short, frequent, and specific. The hosts work for a certificate authority, so positions on industry debates (shorter lifetimes, automation) are informed but not neutral. Use the archive search on Sectigo's site rather than scrolling the feed.
Where to start
- Root Causes 407: Whatever Happened to Passkeys?2024-07-26 · Learner · Passkeys and FIDO
Reasons passkeys and WebAuthn saw slower real-world use in 2024 than their launch publicity suggested.
- Root Causes 640: What is SPIFFE?2026-07-15 · Practitioner · Non-human and AI agent identity
What SPIFFE is, how it places a workload or AI agent identifier inside a certificate, and how policy engines can allow-list those identifiers.
Last verified 2026-09-30 against the show's feed, recent episode notes, and the publisher's own pages. Status and last-episode date update weekly from the feed.
Root Causes: A PKI and Security Podcast is produced by Sectigo. Listed on the same terms as independent shows.
Independent, community-driven analysis. No vendor sponsorship. Compiled from public research and community input and verified on a best-effort basis, so details may be incomplete or out of date. Scores are opinions, not advice. Trademarks belong to their owners; mention does not imply affiliation or endorsement. See the full disclaimer, or send corrections to [email protected].
Related on Start with Identity
- GlossaryCertificate Lifecycle Management
Discovering, issuing, renewing, and revoking TLS and other certificates across an organization. Automation matters because expired or unmanaged certificates cau
- CVEESC15 / EKUwu, AD CS V1 template Application Policy precedence
AD CS V1 templates let Application Policy override EKU in a way that issues certificates with unintended enhanced key usages. High. Patched November 2024, still
- GlossaryX.509
The standard format for public-key certificates used in TLS and PKI. An X.509 certificate binds a public key to a subject and is signed by a certificate authori
- GlossaryPKI
Public Key Infrastructure. The system of certificate authorities, certificates, and keys that binds public keys to identities. Underpins TLS, code signing, and
- PodcastThe Biometric Update Podcast
A weekly show from trade outlet Biometric Update that explains biometrics and digital identity news to a general audience. Short and accessible.
- PodcastThe ID Talk Podcast
Trade-press interviews on biometrics, digital ID, identity documents, and deepfakes from the ID Tech newsroom. More than 200 episodes since 2019.