IP Library Granted Patent US 7,512,974
Granted Patent B2
US 7,512,974 · App. 10/954,558 · Granted Mar 31, 2009

Computer system and program to update SSL certificates

Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,512,974
App. No.
10/954,558
Granted
Mar 31, 2009
Kind
B2
Abstract

System and computer program product for updating an SSL certificate for a server. First program instructions detect when a change has been made to a name, domain or IP address of the server and detect that the server is using an SSL certificate based on a name, domain or IP address applicable before the change. In response, the first program instructions notify an administrator that a change is required to the SSL certificate to reflect the change to the name, domain or IP address. Second program instructions respond to a request by the administrator, to automatically create a new SSL certificate signing request. The new SSL certificate signing request is a form which can be sent to an SSL certificate authority. Third program instructions respond to another request by the administrator, to send the new SSL certificate signing request to the SSL certificate authority. Fourth program instructions respond to receipt of a new SSL certificate from the SSL certificate authority and another request by the administrator, to substitute the new SSL certificate for the existing SSL certificate. Fourth program instructions query the administrator if the administrator wants to use a new self-signed SSL certificate reflecting the change to the name, domain or IP address of the server, until the new SSL certificate signed by the SSL certificate authority is received from the SSL certificate authority, and if so, generate the new SSL self-signed certificate. Other program instructions respond to a request by the administrator, to create a self-signed SSL certificate and substitute the self-signed SSL certificate for the existing SSL certificate.

Claims (21)

1. A method of updating an SSL certificate for a server computer system, said method comprising the steps of:

detecting, by a management server within said server computer system, changes to one or more current network configuration settings for said server computer system;

determining, by said management server upon detecting said changes to said one or more current network configuration settings, whether or not a web server within said server computer system is configured to use SSL certificates for establishing connection over a network with a client computer;

if said web server within said server computer system is determined by said management server to be configured to use said SSL certificates, ascertaining by said management server whether a current SSL certificate for said server computer system is a self-signed SSL certificate or a SSL certificate signed by a certificate authority;

if said current SSL certificate is ascertained to be said SSL certificate signed by said certificate authority, querying in a request to an administrator of said server computer system whether or not to generate a new certificate signing request (CSR) using said changes to said one or more network configuration settings to obtain from said certificate authority a new SSL certificate signed by said certificate authority; and

on receiving an affirmative response to said request from said administrator, automatically generating said new certificate signing request (CSR) for sending to said certificate authority for obtaining said new SSL certificate

if said current SSL certificate is ascertained to be said self-signed SSL certificate, querying in a request to an administrator of said server computer system whether or not to generate a new self-signed SSL certificate; and

on receiving an affirmative response to said request from said administrator, automatically generating said new self-signed SSL certificate using said changes to said one or more current network configuration settings.

2. A method according to claim 1 , further comprising the steps of:

receiving said new SSL certificate signed by said certificate authority;

storing said new SSL certificate signed by said certificate authority in a certificate database; and

restarting said web server to use said new SSL certificate signed by said certificate authority.

3. A method according to claim 1 , wherein said determining step further comprises the step of:

if said web server within said server computer system is not configured to use said SSL certificates, restarting said web server to apply said changes to said one or more current network configuration settings.

4. A method according to claim 1 , wherein said automatically generating step further comprises the steps of:

writing said new certificate signing request (CSR) generated to a removable media;

querying whether or not said administrator wants to temporarily use a self-signed version of said new certificate signing request (CSR) created until said new SSL certificate signed by said certificate authority is received; and

if said administrator wants to temporarily use said self-signed version of said new certificate signing request (CSR) created, automatically generating said self-signed version of said new certificate signing request (CSR) created.

5. A method according to claim 1 , further comprising the steps of:

querying whether or not said administrator wants to begin immediate use of said new self-signed SSL certificate generated; and

if said administrator wants to begin use of said new self-signed SSL certificate, restarting said web server using said new self-signed SSL certificate generated.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2004
From: CALLAGHAN, PATRICK JOSEPH; HENNESSY, JAMES PATRICK; NICHOLS, STEPHEN RICHARD; SCHROEDER, KURT NORMAN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 015492/0085 →
Continuity (1)
Related Publication 20060075219A1 · Apr 6, 2006