IP Library Granted Patent US 7,650,496
Granted Patent B2
US 7,650,496 · App. 10/917,861 · Granted Jan 19, 2010

Renewal product for digital certificates

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,650,496
App. No.
10/917,861
Granted
Jan 19, 2010
Kind
B2
Abstract

The disclosure relates to the management of PKI digital certificates, including certificate discovery, installation, verification and replacement for endpoints over an insecure network. A database of certificates may be maintained through discovery, replacement and other activities. Certificate discovery identifies certificates and associated information including network locations, methods of access, applications of use and non-use, and may produce logs and reports. Automated requests to certificate authorities for new certificates, renewals or certificate signing requests may precede the installation of issued certificates to servers using installation scripts directed to a particular application or product, which may provide notification or require approval or intervention. An administrator may be notified of expiring certificates, using a database or scanning or server agents. Interaction with certificate authorities may be by an abstractor providing a common interface for issuing signing requests to disparate certificate authorities. Digital certificate management may also be applied to network-connecting client devices.

Claims (68)

1. A set of computer readable media containing computer instructions for operating a certificate management and renewal system for automatically renewing digital certificates in a managed network, the set of computer readable media comprising at least one medium upon which is stored the computer instructions executable by a computing system to achieve the functions of:

receiving notifications from a certificate authority regarding a managed digital certificate;

identifying a managed server corresponding to a digital certificate referred to in a received notification from a certificate authority;

communicating with the managed server, the communicating causing the managed server to generate a certificate signing request and return the request to the managing device;

transmitting a generated and received certificate signing request to a certificate authority;

receiving a certificate signed by a certificate authority generated from a certificate signing request;

identifying a destination managed server corresponding to a received certificate signed by a certificate authority;

installing a received certificate signed by a certificate authority to an identified destination managed server; and

configuring an identified destination managed server to use a private key corresponding to an installed certificate.

2. A set of computer readable media according to claim 1 , wherein said instructions are further executable to achieve the functions of:

generating a new asymmetric key pair, and installing a generated private key of a new asymmetric key pair to an identified destination managed server; and

wherein a generated certificate signing request includes a generated public key of a new asymmetric key pair.

3. A set of computer readable media according to claim 1 , wherein said instructions are further executable to install a received certificate signed by a certificate authority by a network interface provided by a web interface of a web server installed to an identified destination managed server.

4. A set of computer readable media according to claim 1 , wherein said instructions are further executable to install a received certificate signed by a certificate authority by a shell interface to an identified destination managed server.

5. A set of computer readable media according to claim 1 , wherein said instructions are further executable to install a received certificate signed by a certificate authority by an agent program installed to an identified destination managed server.

6. A set of computer readable media according to claim 1 , wherein said instructions are further executable to restart a destination server program.

7. A set of computer readable media according to claim 1 , wherein said instructions are further executable to restart a destination server computer.

8. A set of computer readable media according to claim 1 , wherein said instructions are further executable to notify an administrator to restart a destination server program or destination server computer.

9. A set of computer readable media according to claim 1 , wherein said instructions are further executable to confirm the installation of a received certificate to a destination server following the performance of a set of installation steps.

10. A set of computer readable media according to claim 9 , wherein said instructions are further executable to generate an alert to an administrator if the installation of a received certificate to a destination server is not confirmed.

11. A set of computer readable media according to claim 1 , wherein said instructions are further executable to achieve the functions of:

informing an administrator of a certificate for which a notification has been received from a certificate authority;

prior to said transmitting, requesting approval to renew a certificate for which a notification has been received from a certificate authority; and

receiving, in response to a request for approval, an indication from an administrator that a certificate is to be renewed.

12. A set of computer readable media according to claim 1 , wherein said instructions are further executable to achieve the functions of:

following said receiving a certificate signed by a certificate authority, informing an administrator of that renewed certificate;

prior to said installing, requesting approval to install a renewed certificate received from a certificate authority; and

receiving, in response to a request for approval, an indication from an administrator that a renewed certificate is to be installed.

13. A set of computer readable media according to claim 1 , wherein said instructions are further executable to store a received certificate signed by a certificate authority to a backup storage device.

14. A set of computer readable media containing computer instructions for operating a certificate management and renewal system for automatically renewing digital certificates in a managed network, the set of computer readable media comprising at least one medium upon which is stored the computer instructions executable by a computing system to achieve the functions of:

receiving notifications from a certificate authority regarding a managed digital certificate;

identifying a managed server corresponding to a digital certificate referred to in a received notification from a certificate authority;

communicating with the managed server, the communicating causing the managed server to generate a certificate signing request and return the request to the managing device;

transmitting a generated and received certificate signing request to a certificate authority;

receiving a certificate signed by a certificate authority generated from a certificate signing request;

identifying a destination managed server corresponding to a received certificate signed by a certificate authority;

installing a received certificate signed by a certificate authority to an identified destination managed server;

configuring an identified destination managed server to use a private key corresponding to an installed certificate; and

performing a restart action selected from the group of commanding an identified destination managed server to perform a restart, commanding an identified destination managed server to restart and notifying an administrator to restart a destination server program or destination server computer.

15. A set of computer readable media according to claim 14 , wherein said instructions are further executable to achieve the functions of:

generating a new asymmetric key pair; and

installing a generated private key of a new asymmetric key pair to an identified destination managed server.

16. A set of computer readable media according to claim 14 , wherein said instructions are further executable to install a received certificate signed by a certificate authority by a network interface provided by a web interface of a web server installed to an identified destination managed server.

17. A set of computer readable media according to claim 14 , wherein said instructions are further executable to install a received certificate signed by a certificate authority by a shell interface to an identified destination managed server.

18. A set of computer readable media according to claim 14 , wherein said instructions are further executable to install a received certificate signed by a certificate authority by an agent program installed to an identified destination managed server.

19. A set of computer readable media according to claim 14 , wherein said instructions are further executable to confirm the installation of a received certificate to a destination server following the performance of a set of installation steps.

20. A set of computer readable media according to claim 19 , wherein said instructions are further executable to generate an alert to an administrator if the installation of a received certificate to a destination server is not confirmed.

21. A set of computer readable media according to claim 14 , wherein said instructions are further executable to achieve the functions of:

informing an administrator of a certificate for which a notification has been received from a certificate authority;

prior to said transmitting, requesting approval to renew a certificate for which a notification has been received from a certificate authority; and

receiving, in response to a request for approval, an indication from an administrator that a certificate is to be renewed.

22. A set of computer readable media according to claim 14 , wherein said instructions are further executable to achieve the functions of:

following said receiving a certificate signed by a certificate authority, informing an administrator of that renewed certificate;

prior to said installing, requesting approval to install a renewed certificate received from a certificate authority; and

receiving, in response to a request for approval, an indication from an administrator that a renewed certificate is to be installed.

23. A set of computer readable media containing computer instructions for operating a certificate management and renewal system for automatically renewing digital certificates in a managed network, the set of computer readable media comprising at least one medium upon which is stored the computer instructions executable by a computing system to achieve the functions of:

receiving notifications from a certificate authority regarding a managed digital certificate;

receiving, in response to a request for approval, an indication from an administrator that a certificate is to be renewed or installed;

identifying a managed server corresponding to a digital certificate referred to in a received notification from a certificate authority;

communicating with the managed server, the communicating causing the managed server to generate a new asymmetric key pair, the communicating further causing the managed server to generate a certificate signing request and return the request to the managing device;

transmitting a generated and received certificate signing request to a certificate authority;

receiving a certificate signed by a certificate authority generated from a certificate signing request;

identifying a destination managed server corresponding to a received certificate signed by a certificate authority;

installing a received certificate signed by a certificate authority to an identified destination managed server, the installing being performed by accessing the identified destination managed server using a corresponding object of said authentication objects, the installing utilizing a protocol selected from the group of a shell interface, an agent interface and a network interface provided by a web interface of a web server;

configuring an identified destination managed server to use a private key corresponding to an installed certificate; and

performing a restart action selected from the group of commanding an identified destination managed server to perform a restart, commanding an identified destination managed server to restart and notifying an administrator to restart a destination server program or destination server computer.

24. A set of computer readable media according to claim 23 , wherein said instructions are further executable to confirm the installation of a received certificate to a destination server following the performance of a set of installation steps.

25. A set of computer readable media according to claim 24 , wherein said instructions are further executable to generate an alert to an administrator if the installation of a received certificate to a destination server is not confirmed.

Assignments (13)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2026
From: VENAFI, INC.; VENAFI BUYER, LLC; VENAFI INTERMEDIATE, LLC; VENAFI HOLDINGS, INC.
To: CYBERARK SOFTWARE, INC.
Reel/Frame 073400/0651 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL 054892, FRAME 0430 Recorded Oct 1, 2024
From: TRUIST BANK, AS ADMINISTRATIVE AGENT
To: VENAFI, INC.
Reel/Frame 069065/0950 →
PATENT SECURITY AGREEMENT Recorded Jan 4, 2021
From: VENAFI, INC.
To: TRUIST BANK
Reel/Frame 054892/0430 →
RELEASE OF SECURITY INTEREST Recorded Dec 10, 2018
From: ORIX GROWTH CAPITAL, LLC
To: VENAFI, INC.
Reel/Frame 047722/0100 →
SECURITY INTEREST Recorded Jul 21, 2017
From: VENAFI, INC.
To: ORIX GROWTH CAPITAL, LLC
Reel/Frame 043069/0191 →
RELEASE OF SECURITY INTEREST Recorded Jun 29, 2017
From: VENTURE LENDING & LEASING VI, INC.; VENTURE LENDING & LEASING VII, INC.
To: VENAFI, INC.
Reel/Frame 043038/0218 →
SECURITY INTEREST Recorded May 13, 2014
From: VENAFI, INC.
To: SILICON VALLEY BANK
Reel/Frame 032875/0450 →
SECURITY INTEREST Recorded May 8, 2014
From: VENAFI, INC.
To: VENTURE LENDING & LEASING VI, INC.; VENTURE LENDING & LEASING VII, INC.
Reel/Frame 032848/0048 →
CHANGE OF NAME Recorded Sep 6, 2013
From: IMCENTRIC, INC
To: VENAFI, INC.
Reel/Frame 031179/0777 →
SECURITY AGREEMENT Recorded Jul 15, 2011
From: VENAFI, INCORPORATED
To: SILICON VALLEY BANK
Reel/Frame 026597/0819 →
CHANGE OF NAME Recorded Oct 21, 2005
From: THORNTON, RUSSELL S.; HODSON, BENJAMIN; SEEGMILLER, JAYSON; HOLLOBON, TIMOTHY
To: VENAFI, INC.
Reel/Frame 017111/0526 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2005
From: THORNTON, RUSSELL S.; HODSON, BENJAMIN; SEEGMILLER, JAYSON; HOLLOBON, TIMOTHY
To: IMCENTRIC, INC.
Reel/Frame 016556/0055 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2004
From: THORNTON, RUSSELL S.; HODSON, BENJAMIN; SEEGMILLER, JAYSON; HOLLOBON, TIMOTHY
To: IMCENTRIC, INC.
Reel/Frame 016080/0560 →