IP Library Granted Patent US 12,401,634
Granted Patent B2
US 12,401,634 · App. 18/467,350 · Granted Aug 26, 2025

Distributing certificate bundles according to fault domains

Inventors: Burak Uzun (London, GB); Mauruthi Geetha Mohan (Seattle, WA); Saranya Mani (Coventry, GB); Geetha Ravi (England, GB)
Assignee: Oracle International Corporation
H04L63/0823H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,634
App. No.
18/467,350
Granted
Aug 26, 2025
Kind
B2
Abstract

Operations of a certificate bundle distribution service may include: detecting a trigger condition to distribute a certificate bundle that includes a set of certificate authority certificates; determining, for each of a plurality of network entities associated with a computer network, a fault domain representing at least one single point of failure; partitioning the plurality of network entities into a plurality of certificate distribution groups, based on a set of partitioning criteria that includes a fault domain of each particular network entity, in which each particular certificate distribution group includes a particular subset of network entities, and the particular subset of network entities are associated with a particular fault domain; selecting a particular certificate distribution group, of the plurality of certificate distribution groups, for distribution of the certificate bundle; and transmitting the certificate bundle to the particular subset of network entities in the particular certificate distribution group.

Claims (111)

1. One or more non-transitory computer readable media comprising instructions which, when executed by one or more hardware processors, causes performance of operations comprising:

detecting a trigger condition to distribute a first certificate bundle comprising a first set of one or more certificate authority certificates;

determining, for each particular network entity of a plurality of network entities associated with a computer network, a fault domain associated with the particular network entity, from among a plurality of fault domains associated with the computer network,

wherein each particular fault domain, of the plurality of fault domains, represents at least one single point of failure;

partitioning the plurality of network entities into a plurality of certificate distribution groups based on a set of one or more partitioning criteria,

wherein the set of one or more partitioning criteria comprises the fault domain associated with the particular network entity, and

wherein each particular certificate distribution group, of the plurality of certificate distribution groups, comprises a particular subset of network entities, of the plurality of network entities,

wherein the particular subset of network entities is associated with a particular single point of failure corresponding to a particular fault domain of the plurality of fault domains;

selecting a first certificate distribution group, of the plurality of certificate distribution groups, for distribution of the first certificate bundle, wherein the first certificate distribution group comprises a first subset of network entities that is associated with a first fault domain of the plurality of fault domains;

transmitting the first certificate bundle to the first subset of network entities.

2. The media of claim 1 , wherein the first subset of network entities is not associated with a second fault domain of the plurality of fault domains.

3. The media of claim 2 , wherein at least a first network entity, of the first subset of network entities, performs a first service with respect to the first fault domain, and wherein at least a second network entity, of a second subset of network entities, performs the first service with respect to the second fault domain.

4. The media of claim 1 , wherein the fault domain of each particular network entity is determined based on metadata associated with each particular network entity, wherein the metadata comprises a fault domain attribute identifying the fault domain corresponding to the particular network entity,

wherein for a first network entity of the first subset of network entities, a first metadata element comprises a first fault domain attribute, wherein the first fault domain attribute identifies the first network entity as corresponding to the first fault domain.

5. The media of claim 1 , wherein the operations further comprise:

determining, for each particular network entity of the plurality of network entities, a resource group associated with the particular network entity, from among a plurality of resource groups associated with the computer network,

wherein each particular resource group, of the plurality of resource groups, represents at least one of: an attribute, a functionality, or a purpose,

wherein the set of one or more partitioning criteria comprises the resource group associated with the particular network entity,

wherein the first subset of network entities of the first certificate distribution group is associated with a first resource group of the plurality of resource groups.

6. The media of claim 5 , wherein the resource group of each particular network entity is determined based on metadata associated with each particular network entity, wherein the metadata comprises a resource group attribute identifying the resource group corresponding to the particular network entity,

wherein for a first network entity of the first subset of network entities, a first metadata element comprises a first resource group attribute, wherein the first resource group attribute identifies the first network entity as corresponding to the first resource group.

7. The media of claim 5 , wherein the operations further comprise:

selecting a second certificate distribution group, of the plurality of certificate distribution groups, for distribution of the first certificate bundle, wherein the second certificate distribution group comprises a second subset of network entities corresponding to a second fault domain of the plurality of fault domains;

subsequent to transmitting the first certificate bundle to the first subset of network entities, transmitting the first certificate bundle to the second subset of network entities.

8. The media of claim 7 , wherein the second subset of network entities of the second certificate distribution group corresponds to the first resource group of the plurality of resource groups.

9. The media of claim 7 , wherein the operations further comprise:

subsequent to transmitting the first certificate bundle to the first subset of network entities, determining a distribution metric with respect to distribution of the first certificate bundle to the first subset of network entities;

determining that the distribution metric meets a distribution criterion; and

responsive to the distribution metric meeting the distribution criterion, transmitting the first certificate bundle to the second subset of network entities.

10. The media of claim 9 ,

wherein the distribution metric comprises an error count associated with transmitting the first certificate bundle to the first subset of network entities, the error count indicative of a number or a proportion of network entities from among the first subset of network entities with respect to which an error event associated with the first certificate bundle occurs during a verification period; and

wherein the distribution criterion comprises the error count remaining below a threshold during the verification period.

11. The media of claim 9 ,

wherein the distribution metric comprises a distribution count associated with transmitting the first certificate bundle to the first subset of network entities, the distribution count indicative of a number or a proportion of network entities from among the first subset of network entities with respect to which a distribution indicator indicates a successful distribution of the first certificate bundle; and

wherein the distribution criterion comprises the distribution count meeting a threshold.

12. The media of claim 5 , wherein the operations further comprise:

selecting a second certificate distribution group, of the plurality of certificate distribution groups, for distribution of the first certificate bundle, wherein the second certificate distribution group comprises a second subset of network entities corresponding to a second resource group of the plurality of resource groups;

subsequent to transmitting the first certificate bundle to the first subset of network entities, transmitting the first certificate bundle to the second subset of network entities.

13. The media of claim 12 , wherein the second subset of network entities of the second certificate distribution group corresponds to the first fault domain of the plurality of fault domains.

14. The media of claim 13 , wherein the operations further comprise:

selecting a third certificate distribution group, of the plurality of certificate distribution groups, for distribution of the first certificate bundle, wherein the third certificate distribution group comprises a third subset of network entities corresponding to a second fault domain of the plurality of fault domains;

subsequent to transmitting the first certificate bundle to the second subset of network entities, transmitting the first certificate bundle to the third subset of network entities.

15. The media of claim 14 , wherein the third subset of network entities of the third certificate distribution group corresponds to the first resource group of the plurality of resource groups.

16. The media of claim 5 , wherein the operations further comprise:

subsequent to transmitting the first certificate bundle to the first subset of network entities, transmitting the first certificate bundle to one or more additional certificate distribution groups of the plurality of certificate distribution groups;

determining a second subset of one or more network entities, associated with the computer network, that are excluded from the plurality of certificate distribution groups,

determining, for each particular network entity of the second subset of one or more network entities, a particular aft-distribution group from among a plurality of aft-distribution groups based on the particular fault domain of the particular network entity,

selecting a first aft-distribution group, of the plurality of aft-distribution groups, for distribution of the first certificate bundle, wherein the first aft-distribution group comprises a first subgroup of network entities corresponding to the first fault domain of the plurality of fault domains;

transmitting the first certificate bundle to the first subgroup of network entities.

17. The media of claim 1 , wherein the operations further comprise:

determining, based on one or more pre-distribution criteria, a subgroup of one or more network entities, of the plurality of network entities, corresponding to a pre-distribution group; and

prior to transmitting the first certificate bundle to the first subset of network entities:

transmitting the first certificate bundle to the subgroup of one or more network entities of the pre-distribution group; and

determining a successful distribution of the first certificate bundle with respect to the pre-distribution group.

18. The media of claim 1 , wherein the operations further comprise:

selecting a second certificate distribution group, of the plurality of certificate distribution groups, for distribution of the first certificate bundle, wherein the second certificate distribution group comprises a second subset of one or more network entities corresponding to a second fault domain of the plurality of fault domains;

subsequent to transmitting the first certificate bundle to the first subset of network entities:

detecting a second trigger condition to transmit the first certificate bundle to the second subset of one or more network entities, wherein the second trigger condition comprises at least one of:

a time interval having elapsed subsequent to transmitting the first certificate bundle to the first subset of network entities, or

a release phase for releasing the first certificate bundle to the second subset of one or more network entities having commenced; and

responsive to detecting the second trigger condition, transmitting the first certificate bundle to the second subset of one or more network entities.

19. The media of claim 1 , wherein the operations further comprise:

determining, for each particular network entity associated with at least one of the plurality of certificate distribution groups, a particular certificate distribution subgroup, from among a plurality of certificate distribution subgroups, corresponding to the particular network entity,

wherein the particular certificate distribution subgroup is determined based on a network address of the particular network entity, at least by applying a randomization function to the network address of the particular network entity,

wherein each particular certificate distribution subgroup comprises a particular subgroup of network entities;

selecting a first certificate distribution subgroup, of the plurality of certificate distribution subgroups, for distribution of the first certificate bundle, wherein the first certificate distribution subgroup comprises a first subgroup of network entities;

selecting a second certificate distribution subgroup, of the plurality of certificate distribution subgroups, for distribution of the first certificate bundle, wherein the second certificate distribution subgroup comprises a second subgroup of network entities;

wherein transmitting the first certificate bundle to the first subset of network entities comprises:

transmitting the first certificate bundle to the first subgroup of network entities; and

subsequent to transmitting the first certificate bundle to the first subgroup of network entities, transmitting the first certificate bundle to the second subgroup of network entities.

20. The media of claim 1 , wherein the computer network comprise a plurality of availability domains respectively representing a physically separate portion of the computer network with respect to a set of one or more failure modes,

wherein each of the plurality of network entities is associated with a particular set of one or more failure modes corresponding to a particular availability domain of the plurality of availability domains:

wherein the operations further comprise:

determining, for each particular network entity of the plurality of network entities, the particular availability domain associated with the particular network entity, and a particular certificate distribution class, from among a plurality of certificate distribution classes, corresponding to the particular availability domain of the particular network entity;

selecting a first certificate distribution class, of the plurality of certificate distribution classes, for distribution of the first certificate bundle, wherein the first certificate distribution class comprises a first set of network entities corresponding to a first availability domain of the plurality of availability domains, wherein the first set of network entities comprise the first subset of network entities;

selecting a second certificate distribution class, of the plurality of certificate distribution classes, for distribution of the first certificate bundle, wherein the second certificate distribution class comprises a second set of network entities corresponding to a second availability domain of the plurality of availability domains,

transmitting the first certificate bundle to the first set of network entities;

subsequent to transmitting the first certificate bundle to the first set of network entities, transmitting the first certificate bundle to the second set of network entities.

21. The media of claim 1 ,

wherein partitioning the plurality of network entities into of the plurality of certificate distribution groups comprises:

receiving, from a first network entity associated with the computer network, a first request for certificate bundle distribution;

determining, based at least in part on a distribution schedule for distributing the first certificate bundle a first release phase for releasing the first certificate bundle for distribution to the first certificate distribution group,

wherein the first release phase has commenced prior to having received the first request;

wherein selecting the first certificate distribution group comprises:

selecting the first certificate bundle for distribution to the first network entity based at least in part on the first release phase having commenced prior to receiving the first request; and

wherein transmitting the first certificate bundle to the first subset of network entities comprises:

transmitting the first certificate bundle to the first network entity.

22. The media of claim 1 , wherein the computer network comprises a virtual cloud network.

23. A method, comprising:

detecting a trigger condition to distribute a first certificate bundle comprising a first set of one or more certificate authority certificates;

determining, for each particular network entity of a plurality of network entities associated with a computer network, a fault domain associated with the particular network entity, from among a plurality of fault domains associated with the computer network,

wherein each particular fault domain, of the plurality of fault domains, represents at least one single point of failure;

partitioning the plurality of network entities into a plurality of certificate distribution groups based on a set of one or more partitioning criteria,

wherein the set of one or more partitioning criteria comprises the fault domain associated with the particular network entity, and

wherein each particular certificate distribution group, of the plurality of certificate distribution groups, comprises a particular subset of network entities, of the plurality of network entities,

wherein the particular subset of network entities is associated with a particular single point of failure corresponding to a particular fault domain of the plurality of fault domains;

selecting a first certificate distribution group, of the plurality of certificate distribution groups, for distribution of the first certificate bundle, wherein the first certificate distribution group comprises a first subset of network entities that is associated with a first fault domain of the plurality of fault domains;

transmitting the first certificate bundle to the first subset of network entities;

wherein the method is performed by at least one device including a hardware processor.

24. A system, comprising:

at least one hardware processor;

the system being configured to execute operations, using the at least one hardware processor, the operations comprising:

detecting a trigger condition to distribute a first certificate bundle comprising a first set of one or more certificate authority certificates;

determining, for each particular network entity of a plurality of network entities associated with a computer network, a fault domain associated with the particular network entity, from among a plurality of fault domains associated with the computer network,

wherein each particular fault domain, of the plurality of fault domains, represents at least one single point of failure;

partitioning the plurality of network entities into a plurality of certificate distribution groups based on a set of one or more partitioning criteria,

wherein the set of one or more partitioning criteria comprises the fault domain associated with the particular network entity, and

wherein each particular certificate distribution group, of the plurality of certificate distribution groups, comprises a particular subset of network entities, of the plurality of network entities,

wherein the particular subset of network entities is associated with a particular single point of failure corresponding to a particular fault domain of the plurality of fault domains;

selecting a first certificate distribution group, of the plurality of certificate distribution groups, for distribution of the first certificate bundle, wherein the first certificate distribution group comprises a first subset of network entities that is associated with a first fault domain of the plurality of fault domains;

transmitting the first certificate bundle to the first subset of network entities.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2023
From: UZUN, BURAK; GEETHA MOHAN, MAURUTHI; MANI, SARANYA; RAVI, GEETHA
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 064907/0936 →
Continuity (1)
Related Publication 20250097211A1 · Mar 20, 2025
References Cited (142)
US 5699431A · Van Oorschot et al. · 1997 [cited by applicant]
US 7272714B2 · Nagaratnam et al. · 2007 [cited by applicant]
US 7644270B1 · Cherukumudi et al. · 2010 [cited by applicant]
US 8452958B2 · Sun et al. · 2013 [cited by applicant]
US 9172543B2 · Wnuk · 2015 [cited by applicant]
US 9197630B2 · Sharif et al. · 2015 [cited by applicant]
US 9231933B1 · Shenoy et al. · 2016 [cited by applicant]
US 9485101B2 · Bowen · 2016 [cited by applicant]
US 9660978B1 · Truskovsky et al. · 2017 [cited by applicant]
US 9680813B2 · Sade et al. · 2017 [cited by applicant]
US 9794249B1 · Truskovsky et al. · 2017 [cited by applicant]
US 9882727B1 · Veladanda et al. · 2018 [cited by applicant]
US 10021084B2 · Matthews et al. · 2018 [cited by applicant]
US 10212147B2 · Buendgen et al. · 2019 [cited by applicant]
US 10652030B1 · Levy et al. · 2020 [cited by applicant]
US 10764263B2 · Rossi · 2020 [cited by applicant]
US 10771261B1 · Lazar et al. · 2020 [cited by applicant]
US 10812276B2 · Bojjireddy et al. · 2020 [cited by applicant]
US 10848323B2 · Barr, III et al. · 2020 [cited by applicant]
US 11153103B2 · Fynaardt et al. · 2021 [cited by applicant]
US 11196570B2 · Borne-Pons et al. · 2021 [cited by applicant]
US 11310059B2 · Leibmann et al. · 2022 [cited by applicant]
US 11362843B1 · Jiang et al. · 2022 [cited by applicant]
US 11368314B2 · Ray et al. · 2022 [cited by applicant]
US 11388594B2 · Uy et al. · 2022 [cited by applicant]
US 11438325B2 · Begun et al. · 2022 [cited by applicant]
US 11627123B2 · Stayskal et al. · 2023 [cited by applicant]
US 11706038B1 · Thakore et al. · 2023 [cited by applicant]
US 11888997B1 · Bowen et al. · 2024 [cited by applicant]
US 12088738B2 · Rosenthol et al. · 2024 [cited by applicant]
US 20020007346A1 · Qiu et al. · 2002 [cited by applicant]
US 20020174066A1 · Kleckner et al. · 2002 [cited by applicant]
US 20030037234A1 · Fu et al. · 2003 [cited by applicant]
US 20060047965A1 · Thayer · 2006 [cited by applicant]
US 20060101510A1 · Kadyk et al. · 2006 [cited by applicant]
US 20070005956A1 · Zilinskas et al. · 2007 [cited by applicant]
US 20070147619A1 · Bellows et al. · 2007 [cited by applicant]
US 20100030897A1 · Stradling · 2010 [cited by applicant]
US 20100325429A1 · Saha et al. · 2010 [cited by applicant]
US 20110113239A1 · Fu et al. · 2011 [cited by applicant]
US 20120036220A1 · Dare et al. · 2012 [cited by applicant]
US 20120246466A1 · Salvarani et al. · 2012 [cited by applicant]
US 20140298419A1 · Boubez et al. · 2014 [cited by applicant]
US 20150135299A1 · Liang et al. · 2015 [cited by applicant]
US 20170039373A1 · Sasin et al. · 2017 [cited by applicant]
US 20170126667A1 · Bishop et al. · 2017 [cited by applicant]
US 20170171191A1 · Cignetti et al. · 2017 [cited by applicant]
US 20170317837A1 · Alrawais et al. · 2017 [cited by applicant]
US 20170338967A1 · Lewison et al. · 2017 [cited by applicant]
US 20180083966A1 · Zhou et al. · 2018 [cited by applicant]
US 20180102904A1 · Lin et al. · 2018 [cited by applicant]
US 20180287804A1 · Geisbush · 2018 [cited by applicant]
US 20190149342A1 · Fynaardt et al. · 2019 [cited by applicant]
US 20190165950A1 · Ibrahim · 2019 [cited by examiner]
US 20190347406A1 · Lev-Ran · 2019 [cited by applicant]
US 20190349402A1 · Shukla et al. · 2019 [cited by applicant]
US 20190363895A1 · Barr et al. · 2019 [cited by applicant]
US 20200021575A1 · Rezvani et al. · 2020 [cited by applicant]
US 20200092095A1 · Yang et al. · 2020 [cited by applicant]
US 20200150972A1 · Ketkar et al. · 2020 [cited by applicant]
US 20200274718A1 · Hwang et al. · 2020 [cited by applicant]
US 20200274862A1 · Varvarezis et al. · 2020 [cited by applicant]
US 20210034767A1 · Free et al. · 2021 [cited by applicant]
US 20210126801A1 · Nix · 2021 [cited by examiner]
US 20210152547A1 · Barhudarian et al. · 2021 [cited by applicant]
US 20210211307A1 · Statia et al. · 2021 [cited by applicant]
US 20210218723A1 · Lekov et al. · 2021 [cited by applicant]
US 20210392002A1 · Gray et al. · 2021 [cited by applicant]
US 20210409403A1 · Lewin et al. · 2021 [cited by applicant]
US 20210409409A1 · Palanisamy · 2021 [cited by applicant]
US 20220038894A1 · Yoon et al. · 2022 [cited by applicant]
US 20220123951A1 · Lutz et al. · 2022 [cited by applicant]
US 20220150238A1 · Bhalerao · 2022 [cited by applicant]
US 20220239503A1 · Mallikarjuna et al. · 2022 [cited by applicant]
US 20220393886A1 · Williams et al. · 2022 [cited by applicant]
US 20230032867A1 · Peddada et al. · 2023 [cited by applicant]
US 20230109231A1 · Adogla et al. · 2023 [cited by applicant]
US 20230208655A1 · Statia et al. · 2023 [cited by applicant]
US 20230237155A1 · Jacquin et al. · 2023 [cited by applicant]
US 20230291577A1 · Thai et al. · 2023 [cited by applicant]
US 20230401307A1 · Pop · 2023 [cited by examiner]
US 20230412397A1 · Gollent et al. · 2023 [cited by applicant]
US 20240015508A1 · Yoon et al. · 2024 [cited by applicant]
US 20240020373A1 · Ivanov et al. · 2024 [cited by applicant]
US 20240031146A1 · Marosi-Bauer et al. · 2024 [cited by applicant]
US 20240106886A1 · Roy et al. · 2024 [cited by applicant]
US 20240121603A1 · Yoon et al. · 2024 [cited by applicant]
US 20240146543A1 · Sahoo et al. · 2024 [cited by applicant]
US 20240333640A1 · Shevade et al. · 2024 [cited by applicant]
US 20240356763A1 · Goldberg et al. · 2024 [cited by applicant]
US 20240388510A1 · Madtha et al. · 2024 [cited by applicant]
US 20250030561A1 · Long et al. · 2025 [cited by applicant]
US 20250088373A1 · Uzun et al. · 2025 [cited by applicant]
US 20250133401A1 · Lee et al. · 2025 [cited by applicant]
CN 112019477A · 2020 [cited by applicant]
CN 114884963A · 2022 [cited by applicant]
EP 1251670A2 · 2002 [cited by applicant]
EP 2267970A2 · 2010 [cited by applicant]
EP 2854349A1 · 2015 [cited by applicant]
EP 3772208B1 · 2024 [cited by applicant]
KR 1020110045459A · 2011 [cited by applicant]
WO 2006122024A2 · 2006 [cited by applicant]
WO 2022121461A1 · 2022 [cited by applicant]
WO 2022133026A1 · 2022 [cited by applicant]
WO 2023240360A1 · 2023 [cited by applicant]
WO 2025059187A1 · 2025 [cited by applicant]
“About Azure Key Vault certificates”, Retrieved from https://learn.microsoft.com/en-us/azure/key-vault/certificates/about-certificates, Feb. 8, 2023, pp. 1-8. [cited by applicant]
“About the Expressway”, Aug. 17, 2022. pp. 1-12. [cited by applicant]
“Automated certificate management for TLS certificates”, Retrieved from https://docs.servicenow.com/en-US/bundle/utah-it-operations-management/page/product/discovery/concept/automated-cert-requests.html, Retrieved on Ma… [cited by applicant]
“AWS Certificate Manager FAQs”, Retrieved from https://aws.amazon.com/certificate-manager/faqs/, Retrieved on Mar. 24, 2023, pp. 1-17. [cited by applicant]
“Azure Instance Metadata Service”, Retrieved from https://learn.microsoft.com/en-us/azure/virtual-machines/instance-metadata-service?tabs=windows, Mar. 15, 2023, pp. 1-42. [cited by applicant]
“Cisco Expressway Certificate Creation and Use Deployment Guide”, Feb. 23, 2021, pp. 10. [cited by applicant]
“Deploying the CA bundle iApp”, Retrieved from https://www.f5.com/pdf/deployment-guides/f5-ca-bundle-dg.pdf, Dec. 14, 2017, pp. 1-9. [cited by applicant]
“DigiCert Public Key Infrastructure (PKI) Platform”, 2019, pp. 15. [cited by applicant]
“Get started with Key Vault certificates”, Retrieved from https://learn.microsoft.com/en-us/azure/key-vault/certificates/certificate-scenarios, Retrieved on Feb. 1, 2023, pp. 1-6. [cited by applicant]
“High Availability using Patching and Rolling AP Upgrade on Cisco Catalyst 9800 Wireless Controllers”, Copyright 2020, pp. 1-41. [cited by applicant]
“Manage Certificate Revocation Lists (CRLs)”, Jul. 23, 2021, pp. 1-4. [cited by applicant]
“PKI secrets engine”, Retrieved from https://developer.hashicorp.com/vault/docs/secrets/pki, Retrieved on May 4, 2023, pp. 1-3. [cited by applicant]
“Planning a certificate revocation list (CRL)”, Retrieved from https://docs.aws.amazon.com/privateca/latest/userguide/crl-planning.html, Retrieved on Jul. 28, 2023, pp. 11. [cited by applicant]
“Release app updates with staged rollouts”, Retrieved from https://support.google.com/googleplay/android-developer/answer/6346149?hl=en#zippy=%2Crelease-a-staged-rollout-to-specific-countries, Retrieved on Apr. 27, 2023… [cited by applicant]
“Release Your App Update in a Staged Rollout”, Retrieved from https://developer.amazon.com/docs/app-submission/release-updates-in-staged-rollouts.html, Retrieved on Apr. 27, 2023, pp. 1-18. [cited by applicant]
“Rotate Security Certificates”, Retrieved from https://www.cockroachlabs.com/docs/stable/rotate-certificates, Retrieved on May 4, 2023, pp. 1-6. [cited by applicant]
“Rotating the Root CA and Leaf Certificates”, Retrieved from https://docs.pivotal.io/ops-manager/2-4/security/pcf-infrastructure/rotate-cas-and-leaf-certs.html, Nov. 5, 2020, pp. 1-9. [cited by applicant]
“Staged upgrade”, Retrieved from https://www.ibm.com/docs/en/order-management-sw/9.4.0?topic=migrating-staged-upgrade, Mar. 2, 2021, pp. 1-3. [cited by applicant]
“Troubleshoot SSL certificates”, Retrieved from https://cloud.google.com/load-balancing/docs/ssl-certificates/troubleshooting, Retrieved on Mar. 24, 2023, pp. 1-8. [cited by applicant]
“Tutorial: Configure certificate auto-rotation in Key Vault”, Retrieved from https://learn.microsoft.com/en-us/azure/key-vault/certificates/tutorial-rotate-certificates, Feb. 27, 2023, pp. 1-6. [cited by applicant]
“Updating the CA bundle”, Retrieved from https://docs.openshift.com/container-platform/4.9/security/certificates/updating-ca-bundle.html#ca-bundle-understanding_updating-ca-bundle, Retrieved on Mar. 24, 2023, pp. 1-2. [cited by applicant]
“Updating your private CA”, Retrieved from https://docs.aws.amazon.com/privateca/latest/userguide/PCAUpdateCA.html, Retrieved on Mar. 24, 2023, pp. 1-4. [cited by applicant]
“Use self-managed SSL certificates”, Retrieved from https://cloud.google.com/load-balancing/docs/ssl-certificates/self-managed-certs, Aug. 15, 2023, pp. 13. [cited by applicant]
“VSphere Security”, vmware, Update 3, Mar. 21, 2023, pp. 1-426. [cited by applicant]
“Working with Hosts”, Retrieved from https://docs.cloudstack.apache.org/projects/archived-cloudstack-administration/en/latest/hosts.html, Retrieved on Mar. 24, 2023, pp. 1-7. [cited by applicant]
Atutxa et al., “Improving efficiency and security of IIoT communications using in-network validation of server certificate”, Computers in Industry, vol. 144, Jan. 2023, 103802, pp. 30. [cited by applicant]
Bigelow S.J., “Rolling deployment”, Retrieved from https://www.techtarget.com/searchitoperations/definition/rolling-deployment, Jan. 2023, pp. 4. [cited by applicant]
Este-Gracias S., “Rotate your CA seamlessly using a Vault PKI”, Retrieved from https://sestegra.medium.com/rotate-your-ca-seamlessly-using-a-vault-pki-9262228b4afb Sep. 29, 2022, pp. 1-49. [cited by applicant]
Ghanmi et al., “A Secure Data Storage in Multi-cloud Architecture Using Blowfish Encryption Algorithm”, Advanced Information Networking and Applications, Mar. 2022, pp. 398-408. [cited by applicant]
Jamal F., “Zero Trust for SSH—Secure One-click Server Access for Software Engineering Teams”, Retrieved from https://www.banyansecurity.io/blog/zero-trust-for-ssh/, Oct. 28, 2020, pp. 1-7. [cited by applicant]
Manjusha R. et al., “Secure Authentication and Access System for Cloud Computing Auditing Services Using Associated Digital Certificate”, Indian Journal of Science and Technology, vol. 8 (S7), Apr. 2015, pp. 220-227. [cited by applicant]
Nexthop Team, “Updated: Creating a Certificate Revocation List Distribution Point for Your Internal Certification Authority”, Retrieved from https://techcommunity.microsoft.com/t5/skype-for-business-blog/updated-creatin… [cited by applicant]
Rowley J., “Google's Moving Forward Together Proposals for Root CA Policy: Rotating ICAS More Frequently”, Retrieved from https://www.digicert.com/blog/googles-moving-forward-together-proposals-for-root-ca-policy, Mar. … [cited by applicant]
Subhayu, “Different Phases of a Certificate Lifecycle Management Process for a secure WPA2-Enterprise network”, Certificate Lifecycle Management Oct. 6, 2022, pp. 16. [cited by applicant]
Ylonen et al., “Security of Automated Access Management Using Secure Shell (SSH)”, NISTIR 7966 (Draft), Aug. 2014, pp. 43. [cited by applicant]
“What is Certificate Lifecycle Management”, Retrieved from https://www.encryptionconsulting.com/different-phases-of-a-certificate-lifecycle-management-process/, Aug. 1, 2024, pp. 1-12. [cited by applicant]