IP Library Patent Application 10917961
Patent Application
App. No. 10/917,961

Method for discovering digital certificates in a network

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
10/917,961
Abstract

Disclosed herein are several digital certificate discovery and management systems. Detailed information on various example embodiments of the inventions are provided in the Detailed Description below, and the inventions are defined by the appended claims.

Claims (35)

1 . A method for discovering digital certificates to servers on a network, said method comprising the steps of:

receiving an address range corresponding to a network or network portion to be scanned,

contacting network devices within the received address range, said contacting further intended to initiate the transmission of a digital certificate from each of the contacted network devices to said certificate discovery system,

for each contacted network device transmitting a digital certificate, receiving the digital certificate,

for each received digital certificate, creating a certificate record containing a certificate identification, wherein the certificate identification contains sufficient information to identify the received digital certificate and the network device from where it was transmitted, and

storing created certificate records.

2 . A method according to claim 1 , wherein said contacting includes probing IP port 443 using a secure sockets layer protocol.

3 . A method according to claim 1 , wherein said contacting includes probing IP port 80 .

4 . A method according to claim 1 , wherein said contacting includes searching for certificates on network mountable filesystems.

5 . A method according to claim 1 , wherein said contacting includes executing a search command for certificates in a shell interface.

6 . A method according to claim 1 , further comprising the step of parsing found certificates for dates of validity.

7 . A method according to claim 1 , further comprising the step of parsing found certificates for issuing certificate authorities.

8 . A method according to claim 1 , wherein said storing stores certificate records to a database.

9 . A method according to claim 8 , further comprising the step of merging created certificate records with a database produced from earlier discovery activity.

10 . A method according to claim 1 , further comprising the step of identifying the type of servers located to the network devices.

11 . A method according to claim 10 , further comprising the step of storing server types to a database.

12 . A method for discovering digital certificates to servers on a network, said method comprising the steps of:

receiving an address range corresponding to a network or network portion to be scanned,

contacting network devices within the received address range, said contacting further intended to initiate the transmission of a digital certificate from each of the contacted network devices to said certificate discovery system, said contacting including probing of IP port 443 using a secure sockets layer protocol,

for network devices having servers installed thereto, attempting to identify the type of server for each,

for each contacted network device transmitting a digital certificate, receiving the digital certificate,

for each received digital certificate, parsing the certificates to retrieve beginning and ending dates of validity,

for each received digital certificate, creating a certificate record containing a certificate identification, wherein the certificate identification contains sufficient information to identify the received digital certificate and the network device from where it was transmitted, and

storing created certificate records to a database.

13 . A method according to claim 12 , further comprising the step of parsing found certificates for issuing certificate authorities.

14 . A method according to claim 12 , further comprising the step of merging created certificate records with a database produced from earlier discovery activity.

15 . A method according to claim 12 , further comprising the step of storing server types to a database.

16 . A method for discovering digital certificates to servers on a network, said method comprising the steps of:

receiving an address range corresponding to a network or network portion to be scanned,

contacting network devices within the received address range, said contacting further intended to initiate the transmission of a digital certificate from each of the contacted network devices to said certificate discovery system, said contacting including attempting to access the filesystems of the network devices to search for certificates installed thereto,

for network devices having servers installed thereto, attempting to identify the type of server for each,

for each contacted network device transmitting a digital certificate, receiving the digital certificate,

for each received digital certificate, parsing the certificates to retrieve beginning and ending dates of validity,

for each received digital certificate, creating a certificate record containing a certificate identification, wherein the certificate identification contains sufficient information to identify the received digital certificate and the network device from where it was transmitted, and

storing created certificate records to a database.

Assignments (5)
SECURITY INTEREST Recorded May 13, 2014
From: VENAFI, INC.
To: SILICON VALLEY BANK
Reel/Frame 032875/0450 →
SECURITY AGREEMENT Recorded Jul 15, 2011
From: VENAFI, INCORPORATED
To: SILICON VALLEY BANK
Reel/Frame 026597/0819 →
CHANGE OF NAME Recorded Oct 21, 2005
From: THORNTON, RUSSELL S.; HODSON, BENJAMIN; SEEGMILLER, JAYSON; HOLLOBON, TIMOTHY
To: VENAFI, INC.
Reel/Frame 017111/0526 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2005
From: THORNTON, RUSSELL S.; HODSON, BENJAMIN; SEEGMILLER, JAYSON; WEIGHT, RICHARD
To: IMCENTRIC, INC
Reel/Frame 016566/0870 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2004
From: THORNTON, RUSSELL S.; HODSON, BENJAMIN; SEEGMILLER, JAYSON; WEIGHT, RICHARD
To: IMCENTRIC, INC.
Reel/Frame 016080/0314 →