IP Library Granted Patent US 9,787,477
Granted Patent B1
US 9,787,477 · App. 14/478,543 · Granted Oct 10, 2017

Validating certificate chains for both internal and public facing server using unified interface

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,787,477
App. No.
14/478,543
Granted
Oct 10, 2017
Kind
B1
Abstract

Embodiments presented herein provide a validation service used to validate a certificate chain for both public facing servers as well as internal, non-public facing servers. To validate a certificate chain, the client generates a request with the network address and sends it to the validation service. In response, the validation service attempts to establish a connection with the server at the network address. If successful, the validation service receives a certificate chain from the server and can verify that the certificate chain is complete, valid, and chains to a trusted root. If the validation service cannot connect to the network address identified in the request, then the validation service sends a local validation component to the requesting client. The local validation component executes from the client and validates the certificate chain presented by the network server.

Claims (34)

1. A computer-implemented method to validate a certificate chain, the method comprising:

receiving, by a validation service, a request from a client to validate a certificate chain, wherein the request specifies a network server configured with one or more digital certificates presented to clients accessing the network server;

upon determining the network server is accessible by the validation service:

establishing a first network connection with the network server, and

validating the certificate chain associated with at least one digital certificate of the one or more of the digital certificates presented to the validation service by the network server; and

upon determining the network server is inaccessible by the validation service, sending an executable local validation component to the requesting client, wherein the local validation component, when executed by the requesting client, establishes a second network connection with the network server and validates the certificate chain associated with at least one digital certificate of the one or more of the digital certificates presented to the local validation component by the network server.

2. The method of claim 1 , further comprising, presenting a validation report to the requesting client indicating whether the certificate chain is valid or invalid.

3. The method of claim 1 , wherein a valid certificate chain includes a chain of certificates between an end-entity certificate, one or more intermediate certificates, and a trusted root certificate.

4. The method of claim 1 , wherein an invalid certificate chain includes at least one invalid or revoked certificate or does not include a trusted root certificate.

5. The method of claim 1 , wherein an invalid certificate chain is missing at least one certificate in a chain of certificates between an end-entity certificate and a trusted root certificate.

6. The method of claim 1 , wherein the request specifies a network address of the network server.

7. The method of claim 1 , wherein the one or more digital certificates include an end-entity certificate installed on the network server, wherein the end-entity certificate lists a public key used to assert an identify of the network server and to establish secure communication sessions with clients of the network server.

8. A non-transitory computer-readable storage medium storing instructions, which, when executed on a processor, perform an operation to validate a certificate chain, the operation comprising:

receiving, by a validation service, a request from a client to validate a certificate chain, wherein the request specifies a network server configured with one or more digital certificates presented to clients accessing the network server;

upon determining the network server is accessible by the validation service:

establishing a first network connection with the network server, and validating the certificate chain associated with at least one digital certificate of the one or more of the digital certificates presented to the validation service by the network server; and

upon determining the network server is inaccessible by the validation service, sending an executable local validation component to the requesting client, wherein the local validation component, when executed by the requesting client, establishes a second network connection with the network server and validates the certificate chain associated with at least one digital certificate of the one or more of the digital certificates presented to the local validation component by the network server.

9. The non-transitory computer-readable storage medium of claim 8 , wherein the operation further comprises, presenting a validation report to the requesting client indicating whether the certificate chain is valid or invalid.

10. The non-transitory computer-readable storage medium of claim 8 , wherein a valid certificate chain includes a chain of certificates between an end-entity certificate, one or more intermediate certificates, and a trusted root certificate.

11. The non-transitory computer-readable storage medium of claim 8 , wherein an invalid certificate chain includes at least one invalid or revoked certificate or does not include a trusted root certificate.

12. The non-transitory computer-readable storage medium of claim 8 , wherein an invalid certificate chain is missing at least one certificate in a chain of certificates between an end-entity certificate and a trusted root certificate.

13. The non-transitory computer-readable storage medium of claim 8 , wherein the request specifies a network address of the network server.

14. The non-transitory computer-readable storage medium of claim 8 , wherein the one or more digital certificates include an end-entity certificate installed on the network server, wherein the end-entity certificate lists a public key used to assert an identify of the network server and to establish secure communication sessions with clients of the network server.

15. A system, comprising:

a processor; and

a memory hosting an application, which, when executed on the processor, performs an operation to validate a certificate chain, the operation comprising:

receiving, by a validation service, a request from a client to validate a certificate chain, wherein the request specifies a network server configured with one or more digital certificates presented to clients accessing the network server,

upon determining the network server is accessible by the validation service:

establishing a first network connection with the network server; and validating the certificate chain associated with at least one digital certificate of the one or more of the digital certificates presented to the validation service by the network server, and

upon determining the network server is inaccessible by the validation service, sending an executable local validation component to the requesting client, wherein the local validation component, when executed by the requesting client, establishes a second network connection with the network server and validates the certificate chain associated with at least one digital certificate of the one or more of the digital certificates presented to the local validation component by the network server.

16. The system of claim 15 , wherein the operation further comprises, presenting a validation report to the requesting client indicating whether the certificate chain is valid or invalid.

17. The system of claim 15 , wherein a valid certificate chain includes a chain of certificates between an end-entity certificate, one or more intermediate certificates, and a trusted root certificate.

18. The system of claim 15 , wherein an invalid certificate chain (i) includes at least one invalid or revoked certificate or does not include a trusted root certificate or (ii) is missing at least one certificate in a chain of certificates between an end-entity certificate and a trusted root certificate.

19. The system of claim 15 , wherein the request specifies a network address of the network server.

Assignments (11)
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON OCTOBER 16, 2019 AT REEL 050741 FRAME 0918 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072947/0157 →
SECOND LIEN NOTICE OF SUCCESSION OF AGENCY Recorded Jul 30, 2025
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS PRIOR AGENT
To: UBS AG, STAMFORD BRANCH, AS SUCCESSOR AGENT
Reel/Frame 072300/0068 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 19, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS SUCCESSOR AGENT
Reel/Frame 055345/0042 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050746/0973 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050747/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 050741/0899 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 050741/0918 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044681/0556 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044710/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2017
From: SYMANTEC CORPORATION
To: DIGICERT, INC.
Reel/Frame 044344/0650 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2014
From: SINGAL, PADAM; RAMACHANDRAN, DEEPA PRIYA
To: SYMANTEC CORPORATION
Reel/Frame 033679/0444 →