Renewal product for digital certificates
First Claim
1. A set of computer readable media containing computer instructions for operating a certificate management and renewal system for automatically renewing digital certificates in a managed network, the set of computer readable media comprising at least one medium upon which is stored the computer instructions executable by a computing system to achieve the functions of:
- receiving notifications from a certificate authority regarding a managed digital certificate;
identifying a managed server corresponding to a digital certificate referred to in a received notification from a certificate authority;
communicating with the managed server, the communicating causing the managed server to generate a certificate signing request and return the request to the managing device;
transmitting a generated and received certificate signing request to a certificate authority;
receiving a certificate signed by a certificate authority generated from a certificate signing request;
identifying a destination managed server corresponding to a received certificate signed by a certificate authority;
installing a received certificate signed by a certificate authority to an identified destination managed server; and
configuring an identified destination managed server to use a private key corresponding to an installed certificate.
11 Assignments
0 Petitions
Accused Products
Abstract
The disclosure relates to the management of PKI digital certificates, including certificate discovery, installation, verification and replacement for endpoints over an insecure network. A database of certificates may be maintained through discovery, replacement and other activities. Certificate discovery identifies certificates and associated information including network locations, methods of access, applications of use and non-use, and may produce logs and reports. Automated requests to certificate authorities for new certificates, renewals or certificate signing requests may precede the installation of issued certificates to servers using installation scripts directed to a particular application or product, which may provide notification or require approval or intervention. An administrator may be notified of expiring certificates, using a database or scanning or server agents. Interaction with certificate authorities may be by an abstractor providing a common interface for issuing signing requests to disparate certificate authorities. Digital certificate management may also be applied to network-connecting client devices.
69 Citations
25 Claims
-
1. A set of computer readable media containing computer instructions for operating a certificate management and renewal system for automatically renewing digital certificates in a managed network, the set of computer readable media comprising at least one medium upon which is stored the computer instructions executable by a computing system to achieve the functions of:
-
receiving notifications from a certificate authority regarding a managed digital certificate; identifying a managed server corresponding to a digital certificate referred to in a received notification from a certificate authority; communicating with the managed server, the communicating causing the managed server to generate a certificate signing request and return the request to the managing device; transmitting a generated and received certificate signing request to a certificate authority; receiving a certificate signed by a certificate authority generated from a certificate signing request; identifying a destination managed server corresponding to a received certificate signed by a certificate authority; installing a received certificate signed by a certificate authority to an identified destination managed server; and configuring an identified destination managed server to use a private key corresponding to an installed certificate. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
-
-
14. A set of computer readable media containing computer instructions for operating a certificate management and renewal system for automatically renewing digital certificates in a managed network, the set of computer readable media comprising at least one medium upon which is stored the computer instructions executable by a computing system to achieve the functions of:
-
receiving notifications from a certificate authority regarding a managed digital certificate; identifying a managed server corresponding to a digital certificate referred to in a received notification from a certificate authority; communicating with the managed server, the communicating causing the managed server to generate a certificate signing request and return the request to the managing device; transmitting a generated and received certificate signing request to a certificate authority; receiving a certificate signed by a certificate authority generated from a certificate signing request; identifying a destination managed server corresponding to a received certificate signed by a certificate authority; installing a received certificate signed by a certificate authority to an identified destination managed server; configuring an identified destination managed server to use a private key corresponding to an installed certificate; and performing a restart action selected from the group of commanding an identified destination managed server to perform a restart, commanding an identified destination managed server to restart and notifying an administrator to restart a destination server program or destination server computer. - View Dependent Claims (15, 16, 17, 18, 19, 20, 21, 22)
-
-
23. A set of computer readable media containing computer instructions for operating a certificate management and renewal system for automatically renewing digital certificates in a managed network, the set of computer readable media comprising at least one medium upon which is stored the computer instructions executable by a computing system to achieve the functions of:
-
receiving notifications from a certificate authority regarding a managed digital certificate; receiving, in response to a request for approval, an indication from an administrator that a certificate is to be renewed or installed; identifying a managed server corresponding to a digital certificate referred to in a received notification from a certificate authority; communicating with the managed server, the communicating causing the managed server to generate a new asymmetric key pair, the communicating further causing the managed server to generate a certificate signing request and return the request to the managing device; transmitting a generated and received certificate signing request to a certificate authority; receiving a certificate signed by a certificate authority generated from a certificate signing request; identifying a destination managed server corresponding to a received certificate signed by a certificate authority; installing a received certificate signed by a certificate authority to an identified destination managed server, the installing being performed by accessing the identified destination managed server using a corresponding object of said authentication objects, the installing utilizing a protocol selected from the group of a shell interface, an agent interface and a network interface provided by a web interface of a web server; configuring an identified destination managed server to use a private key corresponding to an installed certificate; and performing a restart action selected from the group of commanding an identified destination managed server to perform a restart, commanding an identified destination managed server to restart and notifying an administrator to restart a destination server program or destination server computer. - View Dependent Claims (24, 25)
-
Specification