IP Library Granted Patent US 11,764,978
Granted Patent B2
US 11,764,978 · App. 17/160,335 · Granted Sep 19, 2023

Method and system for certificate management

Inventors: Savithru Mallikarjuna Durga Lokanath (San Jose, CA); Vaishnavi Vithal Galgali (San Jose, CA); Arpeet Kale (San Jose, CA)
Assignee: Salesforce, Inc.
H04L9/3268H04L9/083H04L9/0891H04L9/0894H04L9/3265
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,764,978
App. No.
17/160,335
Granted
Sep 19, 2023
Kind
B2
Abstract

A method and system for certificate management for services in a container orchestrator. The method includes requesting a certificate for a service from a cloud certificate manager, in response to detecting a request from a control plane of the container orchestrator for the certificate for the service, receiving the certificate from the cloud certificate manager, storing the certificate in a secret storage, and returning the location of the secret storage to a requester of the certificate.

Claims (58)

1. A method for certificate management for services in a container orchestration system, the method comprising:

responsive to detecting a request for a certificate-related resource from one of the services implemented in a set of containers in the container orchestration system, the certificate-related resource associated with at least one of a certificate, keystore and truststore, a controller of the container orchestration system performing the following:

requesting the certificate-related resource from a cloud certificate manager for the one of the services;

receiving the certificate-related resource from the cloud certificate manager;

storing the certificate-related resource in a secret storage; and

returning a location of the secret storage for provision to the one of the services.

2. The method of claim 1 , further comprising:

monitoring a custom resource definition to detect the request for the certificate-related resource.

3. The method of claim 1 , further comprising:

requesting the secret storage be established by a cloud secrets manager, in response to determining that the secret storage is unavailable for the one of the services.

4. The method of claim 1 , further comprising:

receiving a private key from the cloud certificate manager; and

storing the private key in the secret storage.

5. The method of claim 1 , wherein the secret storage includes at least one of a key store and a trust store.

6. The method of claim 1 , wherein the location of the secret storage is a pointer to a location in a cloud computing environment.

7. The method of claim 1 , wherein the container orchestration system is Kubernetes, and wherein the one of the services is a pod.

8. The method of claim 1 , further comprising:

requesting to delete a certificate associated with a certificate-related resource for the one of the services from a cloud secrets manager, in response to detecting a request from a control plane of the container orchestration system to delete the certificate for the one of the services;

receiving confirmation of deletion of the certificate from the cloud secrets manager; and

returning the confirmation of the deletion to a requester of the deletion of the certificate.

9. A non-transitory machine-readable storage medium that provides instructions that, if executed by a processor, will cause said processor to perform operations of a method for certificate management for services in a container orchestration system, the operations comprising:

responsive to detecting a request for a certificate-related resource from one of the services implemented in a set of containers in the container orchestration system, the certificate-related resource associated with at least one of a certificate, keystore and truststore, a controller of the container orchestration system performing the following:

requesting the certificate-related resource from a cloud certificate manager for the one of the services;

receiving the certificate-related resource from the cloud certificate manager;

storing the certificate-related resource in a secret storage; and

returning a location of the secret storage for provision to the one of the services.

10. The non-transitory machine-readable storage medium of claim 9 , having further instructions for operations further comprising:

monitoring a custom resource definition to detect the request for the certificate-related resource.

11. The non-transitory machine-readable storage medium of claim 9 , having further instructions for operations further comprising:

requesting the secret storage be established by a cloud secrets manager, in response to determining that the secret storage is unavailable for the one of the services.

12. The non-transitory machine-readable storage medium of claim 9 , having further instructions for operations further comprising:

receiving a private key from the cloud certificate manager; and

storing the private key in the secret storage.

13. The non-transitory machine-readable storage medium of claim 9 , wherein the secret storage includes at least one of a key store and a trust store.

14. The non-transitory machine-readable storage medium of claim 9 , wherein the location of the secret storage is a pointer to a location in a cloud computing environment.

15. The non-transitory machine-readable storage medium of claim 9 , wherein the container orchestration system is Kubernetes, and wherein the one of the services is a pod.

16. The non-transitory machine-readable storage medium of claim 9 , having further instruction for operations further comprising:

requesting to delete a certificate associated with a certificate-related resource from a cloud secrets manager, in response to detecting a request from a control plane of the container orchestration system to delete the certificate for the one of the services;

receiving confirmation of deletion of the certificate from the cloud secrets manager; and

returning the confirmation of the deletion to a requester of the deletion of the certificate.

17. A computing system comprising:

a non-transitory machine-readable medium having stored therein a certificate orchestrator; and

a processor, coupled to the non-transitory machine-readable medium, to execute the certificate orchestrator to perform certificate management for services in a container orchestration system, the certificate orchestrator configurable to cause the processer to:

responsive to detecting a request for a certificate-related resource from one of the services implemented in a set of containers in the container orchestration system, the certificate-related resource associated with at least one of a certificate, keystore and truststore, a controller of the container orchestration system performing the following:

request the certificate-related resource from a cloud certificate manager for the one of the services,

receive the certificate-related resource from the cloud certificate manager,

store the certificate-related resource in a secret storage, and

return a location of the secret storage for provision to the one of the services.

18. The computing system of claim 17 , wherein the certificate orchestrator is further configurable to monitor a custom resource definition to detect the request for the certificate-related resource.

19. The computing system of claim 17 , wherein the certificate orchestrator is further configurable to request the secret storage be established by a cloud secrets manager, in response to determining that the secret storage is unavailable for the one of the services.

20. The computing system of claim 17 , wherein the certificate orchestrator is further configurable to receive a private key from the cloud certificate manager, and store the private key in the secret storage.

21. The computing system of claim 17 , wherein the secret storage includes at least one of a key store and a trust store.

22. The computing system of claim 17 , wherein the location of the secret storage is a pointer to a location in a cloud computing environment.

23. The computing system of claim 17 , wherein the container orchestration system is Kubernetes, and wherein the one of the services is a pod in Kubernetes.

24. The computing system of claim 17 , wherein the certificate orchestrator is further configurable to:

request to delete a certificate associated with a certificate-related resource from a cloud secrets manager, in response to detecting a request from a control plane of the container orchestration system to delete the certificate for the one of the services,

receive confirmation of deletion of the certificate from the cloud secrets manager, and

return the confirmation of the deletion to a requester of the deletion of the certificate.

Assignments (2)
CHANGE OF NAME Recorded Feb 17, 2023
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 062794/0656 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2021
From: MALLIKARJUNA DURGA LOKANATH, SAVITHRU; GALGALI, VAISHNAVI VITHAL; KALE, ARPEET
To: SALESFORCE.COM, INC.
Reel/Frame 055054/0650 →
Continuity (1)
Related Publication 20220239503A1 · Jul 28, 2022
Cited By (3)
US 12,267,253 US 12,489,641 US 12,615,220