Modernizing PKI with DigiCert’s Deepika Chauhan
Most organizations still rely on old PKI deployments that aren’t prepared for the volume and speed of certificates that are issued today. Deepika discusses organizations’ pain points, benefits of modernization and recommendations.
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
I'm really happy to have someone I've had the pleasure of interviewing before, but I, I believe that was in person at, at DigiCert at the DigiCert user conference the last time we did it. Her name is Dipika Choan and Dieter's Chief Product Officer at Digi Cert Dipika. Welcome to Techstrong tv.
It's great to have you on. Thank you. And I'm really excited to talk to you again.
Yes. It was in personal last time we spoke on it Was, yes, it was at wa in the digital trust. Yeah.
In Las Vegas. Yes. Yeah.
Well, this year you guys sort of did a road show for the Digital Trust Summit. Smaller events, but you know, different cities throughout the world. Yeah.
What we realized is many customers, because of travel restrictions and other reasons, were not able to travel internationally. So we kind of took the mini trust summit to our customers, and we visited six different cities across the globe. Two in us, two in Amea, and two in a PJ.
Yep. Kind of if the, if the mountain can't come to Mohammed, the Mohammad will come to the mountain. Right.
Um, deep guy mentioned you, a Chief product officer, and I mean, obviously in a company decides to DigiCert that it's a very senior position with a lot of responsibility, but people wanna know how did, how did you wind up here? How did you come to be the Chief Product officer at DigiCert? You know, we don't live in a, a monarchy where these things are granted by your bloodline or, you know, inheritance you had earn this.
Tell people a little bit about your journey, Uh, shortly. I grew up in India and I was an engineer by training. I am an engineer by training.
So I came to United States for graduate school and made my home in United States essentially. Initially I was leading engineering team, so for the first 10 or 12 years of my career, I was working actively with the engineering teams, building products, and graduated into product management. I went into business school and after business school focused a lot more on the go to market aspect of the product and, uh, led product as well, the sales organization as well for about four years or so, eventually ended up in the product organization because product is really interesting.
It's at the center of understanding from the frontline what is it that our customers need, what is it that our market need, what is it our frontline sales need? And then making sure working with the engineering teams to build those products and Got it. juster is a very exciting place to be A We're gonna jump into that in a second.
Um, you know, believe it or not, this is your path is a, is a pretty common path I hear, especially with women. Especially with women. I can't tell you the amount of women I've met who were bonafide engineers, coders, people who had thousands of line of code, you know, committed into commercial products that we all use every day.
But at some point in their career, they decided they wanted to transition to the business side of the business, and many of them go back and get an MBA. Right. Um, and then they move into the business side of the business, product, product, marketing, marketing, uh, operational roles.
Roles. And I wonder if it's has anything to do with decisions around family and lifestyle, right? Or is there something else at play?
Yeah, I think, uh, the primary reasons, uh, a lot of people decide to take the path is, uh, you wanna not, you wanna be in a position where you can influence the direction of the company. Um, and it's not just about executing on a vision, but actually creating the vision part of that too. And that's the exciting part.
If you can chart the territory that you want to play in and then help the company execute, I think for all of us, men or women, that's a very exciting place to be. And I think that's Probably what, that's the allure. That's the, the, the, yeah, the reason to gravitate.
Makes sense. Makes sense. You mentioned DigiCert's an exciting place to be.
There are people out here in our audience who are gonna say, how exciting could it be? They're selling SSL certificates hardly new, hardly, you know, dynamic or exciting, but old contraire, right? Little do they know, people could tell them a little bit why Digi CERT's an exciting place to be.
Yeah, so DigiCert is more than just SSL certificates. Our vision is to be the leading provider of digital trust. If you think about certificates, the core of what certificates do is establish trust, whether it's encryption, authentication and non-repudiation.
But the challenges, Alan, the most of the organizations are facing over the far last 10 plus years is with all the complexity in it, whether it's the exploding number of devices, the number of applications, the different kind of architectures, like zero trust architectures, the changing regulatory landscape, uh, what's happening in the organizations is that the number of certificates has exploded. I mean, I was just talking to one of the banks and they, they said initially they thought they only had only half a million certificates, but they mentally showed they had one and a half million certificates. So the number of certificates has exploded.
And what Digi Cert is providing is the capability of managing those certificates, because certificates are the very core of digital trust. And what customers need for different kind of use cases is how do I prevent outages? If any of the certificates on any of the servers, which is public facing expires, well, you have an outage.
And even biggest organizations, including starlink and Equinox and others have actually faced some of the things. So DigiCert provides solutions that within an enterprise, customers can manage. Those certificates have visibility, control and automation.
Whether the certificates are deployed on workloads, servers, user devices, any kind of machines the same. Absolutely. Taking it further into software world as well, software, CICD pipelines, how do you make sure your software is getting signed, the content you're creating, how do you know whether it's fake or real and supply chain?
Exactly. Supply chain content, supply chain, the devices that we are producing, how do you know it's temp resistant and not counterfeit? And across all of them, it's not just about providing certificate, but all the management capabilities related to that as well.
And that's where DigiCert is providing the foundation of digital trust. Excellent. Thank you for that.
I wanna mention two other things that are front and center in DigiCert's vision of, of things, of technologies, trends that will directly impact your ability to be the provider of digital trust. One is quantum computing. The second is ai.
When you put 'em together, it's almost exponentially, right? Uh, more complex, more, more capability. But more to think about both these areas of areas where DigiCert is very, very involved.
If you, if you don't want, and, and that will segue. We're going eventually talk about AI modernization, but when we talk about modernization, these are two big kind of events on the horizon. You know, two big gravity wells, if you will, on the horizon that we need to be planning for quantum and ai.
And more than just planning, AI is real and and honest today. And, and quantum is getting there. So you wanna just briefly mention something about those and that we'll talk about PKI modernization?
Yeah, absolutely. Quantum impacts, it has a lot of positive, uh, momentum and a lot of things that we can do with the opportunities that quantum computing will provide, but it also disrupts the underpinning of the entire digital trust because across all the different applications, algorithms we use today can be broken in a matter of minutes by quantum computer. So NIST has come up with algorithms that we shouldn't be using going forward to be quantum safe.
And DigiCert is of course trying to make sure that all our products are supporting that so that our customers can go on a quantum journey. But DigiCert is also trying to provide thought leadership to our customers and raise the awareness. In fact, just recently in September we had the first quantum readiness day.
And in that we had some of the leading speakers, in fact, you ex included. Um, but I Was a judge. Yes.
Yeah. Um, uh, but Dr. Tahir Algamal, who's a key influencer and often referred his father of SSL, Dr.
Bob Ser, professor Shore. And as all of you know, that Professor Shore from MIT is the author of the Shores algorithm. We have leading speakers from Google, IBM, Cisco, Accenture, Deloitte, nist, I mean, you name it.
I think from a lot of different organizations. And the key reason is that it's not just enough at the moment that our products are supporting and enabling our customers to go on a quantum journey, I think it's also important to help our customers understand the importance of it. And many have actually started thinking about the journey, raise the awareness within their organization, see where the industry is going, because a number of organizations, as you were the judge, who are well ahead of the curve and we can all learn from them.
And there was one very interesting thing in that Quantum Readiness Day that if you compare it to why 2K, we knew the date, what's gonna happen? But we didn't know what was gonna happen. Well, with the quantum, we don't know when the quantum computing is gonna be available.
It can be in a few years, it can take longer, but we know exactly what's gonna happen. And so I think it's important that all the organizations in crypto Agile, and that's why PKM organization matters a lot because the quantum threat, which is looming ahead for all the organization to take advantage of the opportunities we need to be quantum ready. And you're absolutely right on the AI front, you know, like ai, again, it's so incredibly exciting.
In fact, all the organizations we included are looking at how can we make customer value? Uh, we provide more customer value by integrating it into our products, but it's also a threat. What's real, what's fake?
Do the velocity of the attacks on the surface supply chain increase is your content provenance is gonna become more challenging because of the AI threats. And this is where we wanna make sure our customers have the ability to use our products to protect against those threats from software supply chain and content prominence. Agreed.
Agreed. Alright. If you don't mind, let us said great.
'cause we're gonna run at of time. We're having so much short talking here. There's only so many, so much you can fit in 15 minutes.
PKI modernization. Again, like we talked about with that SL certificates, some people may look at it and say, PKI. Oh hum.
It's been around a long time. What's new under the sun? Let's, let's hear.
What's new? PKM organization is one of the most important thing needed to achieve quantum readiness. However, quantum readiness isn't the only driver behind PKM organization because the challenges are here.
And now as you've heard, many organization have hundreds of thousands of certificates. Well, it's gonna become more challenging because recent ballots at the sea, a browser forum where Google has proposed 90 day certs, apple actually has recently come out for the ballot proposing eventually going to 45 day certs, which means that if you did not have visibility and automation in your organization, what you used to do once a year, you may have to do that now 12 times a year, four times a year. And you can't just do it manually, which creates an impetus that you have to think about.
Certificate lifecycle management, providing visibility, control and automation. You have other events. Recently entrust was distrusted, which meant that lots of organizations who were using entrust SSL certificates have to figure out what the next path is.
And for those customers, again, crypto agility becomes really important. And so the three key steps of crypto agility and PKM organizations, our customers are thinking about and need to think about it if they're not already on this path, has first discovery and assessment. How many certificates do you have?
Because invariably all our customers, if they, they think they have certain number of certificates, but many times the number of certificates can even be more than a hundred percent, 200% more. So discovery is important. You have to have a surface area of what you're managing, and then you prioritize the use cases.
How do you go implement crypto agility because you migrate those use cases. Eventually what you want is centralized policy and governance. And this is, these are the solutions we are providing where you consolidate the public PKI and the private PKI and provide a centralized governance and policy enforcement management.
And these steps will get you ready for 90 day certificates. But these same steps help you be ready for quantum as well. Excellent.
Um, you know, there there's more to PKI than obviously just certificates or, and certificates. And we use in email, we use it, get in in any kind of communication where you want to, uh, verify who the identity is. I, I wonder as we move, and I don't know the real numbers on this, but I'm gonna assume we're doing, we more machine to machine communication these days that we are people to people communication by a lot.
You are absolutely right. And it has exploded because of the cloud adoption as well. Mm-Hmm.
Because for DevOps environment, you're really dealing sometimes with FM ls where certificates have a validity of a matter of days and even hours because you're spinning up machines, you're spinning up containers, you're providing certificates. And certificates is the underpinning of security in a lot of those use cases. So the machine certificates has absolutely exploded, whether it's user machines or machines related to the workloads DevOps environment or even your infrastructure, uh, that you have legacy as well as more Yeah, I mean containers.
Containers are ephemeral, right? The average containers life span is minutes, not even hours or days. And each container has its own like unique identity and therefore its own unique certificate.
Um, so it's in there. We, we spoke earlier, you mentioned, you know, Google and Apple, uh, changing the, the timeframe for expiration of certificates. I wanna be clear, this is not being proposed just to make more work or make people buy more certificates.
In fact, from what I remember about the DigiCert offering is you would buy in essence a subscription to certificates and as often as Apple, Google, I don't know, Mozilla has stole the browser business as often as any of these people, you know, want a new certificate that would be included in your subscription in essence. Yeah. Yeah.
So basically Doesn't cost more money. That's absolutely right. So it's not just like if you have a certificate you're issuing for hours, then suddenly, uh, you are paying by for each eight hours of certificate.
So the subscription and titles, you, if you're protecting certain assets, the number of different number of certificates are included as part of that subscription. And you are absolutely right. The, all these ballots, by the way, they haven't passed and see a browser forum.
But the intent is to modernize the PKI architecture, um, and move away from legacy practices. And, uh, in fact, many of our customers are already ahead. Um, and we, uh, from a product platform allows certificates to be issued for a matter of hours on minutes.
So, and many of our customers actually use that in the DevOps infrastructure. So it's just the maturity curve of different organizations. The organizations where, um, the PKI modernization is across a lot of legacy infrastructure and it's very manual, but there are some of the customers who are ahead of even some of the Google and the Apple, uh, ballot initiatives and are, is showing very short term validity certificates.
Yeah, you picked up We're almost, we're, well, we're past time, to tell you the truth. We were always supposed to be 50 read. We went, we blew past that.
com. Yes. Yes, absolutely.
Alright, Ika, as always, it's a pleasure having you on. I appreciate you coming on here and educating us a little bit. Um, and you know, you haven't, I I know, I don't know if you're going to do a, a user conference back in Vegas or wherever next year, and I hope to see you in person, but until then, feel free to stop in and keep us posted here.
Absolutely. It's always a great pleasure talking to you, Alan. So thank you.
All righty for having me. Thank you Deepika on Chief Product Officer at Digis here on Text Arm tv. We're gonna take a break.
We'll be back in a minute with more Techstrong tv.