IP Library Granted Patent US 12,425,239
Granted Patent B2
US 12,425,239 · App. 18/447,993 · Granted Sep 23, 2025

Authenticating certificate bundles with asymmetric keys

Inventors: Tony Long (Edmonds, WA); Mauruthi Geetha Mohan (Seattle, WA); Karthik Venkatesh (Bothell, WA)
Assignee: Oracle International Corporation
H04L9/3268H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,239
App. No.
18/447,993
Granted
Sep 23, 2025
Kind
B2
Abstract

Operations of a digital signature manager may include detecting, in a certificate repository on a first virtual cloud network, set of one or more new certificate authority (CA) certificates; transmitting, to a key management service hosted on a second virtual cloud network, a CA dataset that includes the set of one or more new CA certificates; receiving, from the key management service, a digital signature of the CA dataset generated based at least on a global private key stored on the second virtual cloud network in a private key repository associated with the key management service; and storing the digital signature in the certificate repository in a data structure that associates the digital signature with the CA dataset.

Claims (96)

1. One or more non-transitory computer readable media comprising instructions which, when executed by one or more hardware processors, causes performance of operations comprising:

detecting, in a certificate repository on a first virtual cloud network, at least one new certificate authority (CA) certificate;

transmitting, to a key management service hosted on a second virtual cloud network, a CA dataset comprising the at least one new CA certificate;

receiving, from the key management service, a digital signature of the CA dataset, wherein the digital signature of the CA dataset is generated based at least on a global private key, wherein the global private key is stored on the second virtual cloud network in a private key repository associated with the key management service;

storing the digital signature in the certificate repository, wherein the certificate repository comprises a data structure that associates the digital signature with the CA dataset;

wherein the first virtual cloud network comprises a first system infrastructure, and the second virtual cloud network comprises a second system infrastructure, wherein the first system infrastructure differs from the second system infrastructure.

2. The media of claim 1 ,

wherein the first virtual cloud network is located within a first region of a first realm, the first region comprising a first set of one or more interconnected data centers upon which the first virtual cloud network is deployed, and the first realm comprising a first infrastructure-as-a-service (IaaS) system infrastructure; and

wherein the second virtual cloud network is located within a second region of a second realm, the second region comprising a second set of one or more interconnected data centers upon which the second virtual cloud network is deployed, and the second realm comprising a second IaaS system infrastructure.

3. The media of claim 2 , wherein the operations further comprise:

generating the at least one new CA certificate in connection with deploying the first region and/or the first virtual cloud network.

4. The media of claim 3 , wherein the at least one new CA certificate comprises a root CA certificate for issuing intermediate CA certificates and/or entity certificates to network entities associated with the first virtual cloud network.

5. The media of claim 1 , wherein the operations further comprise:

transmitting to at least one network entity, the CA dataset and the digital signature of the CA dataset.

6. The media of claim 1 , wherein detecting the at least one new CA certificate comprises:

identifying the at least one CA certificate; and

determining that the at least one CA certificate is unassociated with a current digital signature from the key management service.

7. The media of claim 1 , wherein the CA dataset comprises a certificate bundle, and wherein the certificate bundle comprises a set of CA certificates, the set of CA certificates including the at least one new CA certificate.

8. The media of claim 1 , wherein transmitting the CA dataset to the key management service comprises:

transmitting, to the key management service, a request for the key management service to digitally sign the CA dataset.

9. The media of claim 8 , wherein transmitting the CA dataset to the key management service comprises:

transmitting a credential to the key management service to authenticate the request for the key management service to digitally sign the CA dataset.

10. One or more non-transitory computer readable media comprising instructions which, when executed by one or more hardware processors, causes performance of operations comprising:

receiving at a distribution service associated with a first virtual cloud network, a request from a network entity for at least one new certificate authority (CA) certificate; and

responsive to receiving the request, transmitting to the network entity, (a) a CA dataset comprising the at least one new CA certificate, and (b) a digital signature of the CA dataset,

wherein the digital signature of the CA dataset has been generated, by a key management service hosted on a second virtual cloud network, using a global private key;

wherein the global private key is stored on the second virtual cloud network in a private key repository associated with the key management service, and

wherein the CA dataset is validatable with a first global public key corresponding to the global private key, wherein the first global public key is stored in a public key repository associated with the network entity;

wherein the first virtual cloud network comprises a first system infrastructure, and the second virtual cloud network comprises a second system infrastructure, wherein the first system infrastructure differs from the second system infrastructure.

11. The media of claim 10 , wherein the operations further comprise:

prior to transmitting the CA dataset and the digital signature of the CA dataset to the network entity, validating the CA dataset using a second global public key corresponding to the global private key, wherein the second global public key is stored in a second public key repository associated with the distribution service.

12. The media of claim 11 , wherein validating the CA dataset comprises:

generating a first hash value by applying a hash function to the CA dataset;

generating a second hash value by decrypting the digital signature of the CA dataset using the second global public key;

comparing the first hash value to the second hash value; and

determining that the first hash value matches the second hash value.

13. The media of claim 10 , wherein the operations further comprise:

responsive to receiving the request, locating the CA dataset and the digital signature in a certificate repository.

14. The media of claim 10 ,

wherein the request for the at least one new CA certificate is associated with an initial provisioning of a cloud resource instance on the first virtual cloud network; or

wherein the request for the at least one new CA certificate is one of a series of periodic requests for an updated certificate bundle.

15. The media of claim 10 , wherein the CA dataset comprises a certificate bundle, and wherein the certificate bundle comprises a set of CA certificates, the set of CA certificates including the at least one new CA certificate.

16. The media of claim 10 , wherein the operations further comprise:

responsive to receiving the request:

determining a first timestamp corresponding to the digital signature of the CA dataset;

determining a second timestamp corresponding to a previous transmission to the network entity, the previous transmission comprising a previous CA dataset including one or more previous CA certificates;

determining that the second timestamp is earlier than the first timestamp; and

responsive to determining that the second timestamp is earlier than the first timestamp, transmitting the CA dataset and the digital signature of the CA dataset to the network entity.

17. The media of claim 10 ,

wherein the first virtual cloud network is located within a first region of a first realm, the first region comprising a first set of one or more interconnected data centers upon which the first virtual cloud network is deployed, and the first realm comprising a first infrastructure-as-a-service (IaaS) system infrastructure; and

wherein the second virtual cloud network is located within a second region of a second realm, the second region comprising a second set of one or more interconnected data centers upon which the second virtual cloud network is deployed, and the second realm comprising a second IaaS system infrastructure.

18. The media of claim 10 , wherein the operations further comprise:

prior to receiving the request from the network entity:

detecting, in a certificate repository on the first virtual cloud network, at least one new CA certificate;

transmitting the CA dataset to the key management service;

receiving, from the key management service, the digital signature of the CA dataset;

storing the digital signature in the certificate repository, wherein the certificate repository comprises a data structure that associates the digital signature with the CA dataset.

19. One or more non-transitory computer readable media comprising instructions which, when executed by one or more hardware processors, causes performance of operations comprising:

transmitting, to a distribution service associated with a first virtual cloud network, a request for at least one certificate authority (CA) certificate for use by a network entity;

receiving from the distribution service, (a) a CA dataset comprising the at least one CA certificate, and (b) a digital signature of the CA dataset,

wherein the digital signature of the CA dataset has been generated, by a key management service hosted on a second virtual cloud network, using a global private key, and

wherein the global private key is stored on the second virtual cloud network in a private key repository associated with the key management service, and

validating the CA dataset using a global public key corresponding to the global private key, wherein the global public key is stored in a public key repository on the first virtual cloud network;

installing the at least one CA certificate in a storage medium associated with the network entity;

wherein the first virtual cloud network comprises a first system infrastructure, and the second virtual cloud network comprises a second system infrastructure, wherein the first system infrastructure differs from the second system infrastructure.

20. The media of claim 19 ,

wherein installing the at least one CA certificate in the storage medium represents an operation of a provisioning process for the network entity.

21. The media of claim 20 , wherein the operations further comprise:

detecting a certificate bundle-retrieval trigger during the provisioning process; and

transmitting the request for the at least one CA certificate responsive to detecting the certificate bundle-retrieval trigger.

22. The media of claim 21 , wherein the operations further comprise:

performing an additional operation of the provisioning process after installing the at least one CA certificate.

23. The media of claim 19 , wherein the global public key is built into an operating system image of the network entity.

24. The media of claim 19 , wherein the key management service is a third-party service.

25. The media of claim 19 ,

wherein the first virtual cloud network is located within a first region of a first realm, the first region comprising a first set of one or more interconnected data centers upon which the first virtual cloud network is deployed, and the first realm comprising a first infrastructure-as-a-service (IaaS) system infrastructure; and

wherein the second virtual cloud network is located within a second region of a second realm, the second region comprising a second set of one or more interconnected data centers upon which the second virtual cloud network is deployed, and the second realm comprising a second IaaS system infrastructure.

26. One or more non-transitory computer readable media comprising instructions which, when executed by one or more hardware processors, causes performance of operations comprising:

transmitting, from a network entity to a distribution service, a request for at least one certificate authority (CA) certificate, wherein the network entity and the distribution service are associated with a first virtual cloud network;

wherein the distribution service receives the request;

wherein responsive to receiving the request, the distribution service transmits to the network entity, (a) a CA dataset comprising the at least one CA certificate, and (b) a digital signature of the CA dataset,

wherein the digital signature of the CA dataset has been generated, by a key management service hosted on a second virtual cloud network, using a global private key,

and wherein the distribution service validates the CA dataset using a first global public key corresponding to the global private key;

receiving, at the network entity, the CA dataset comprising the at least one CA certificate and the digital signature of the CA dataset;

validating the CA dataset using a second global public key corresponding to the global private key;

installing the at least one CA certificate in a storage medium associated with the network entity;

wherein the global private key is stored on the second virtual cloud network in a private key repository associated with the key management service, and

wherein the first global public key is stored on the first virtual cloud network in a public key repository associated with the network entity.

27. The media of claim 26 , wherein:

the second global public key is stored on the first virtual cloud network in a second public key repository associated with the distribution service;

the distribution service determines, based on validating the CA dataset, that the CA dataset is valid; and

wherein the distribution service transmits the CA dataset and the digital signature of the CA dataset to the network entity subsequent to determining that the CA dataset is valid.

28. The media of claim 26 , wherein the operations further comprise:

detecting a certificate bundle-retrieval trigger during a provisioning process for the network entity; and

transmitting the request for the at least one CA certificate responsive to detecting the certificate bundle-retrieval trigger.

29. The media of claim 26 , wherein the first global public key and the second global public key are identical.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2023
From: LONG, TONY; GEETHA MOHAN, MAURUTHI; VENKATESH, KARTHIK
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 064710/0878 →
Continuity (1)
Related Publication 20250055710A1 · Feb 13, 2025
References Cited (164)
US 5671279A · Elgamal · 1997 [cited by applicant]
US 5699431A · Van Oorschot et al. · 1997 [cited by applicant]
US 7272714B2 · Nagaratnam et al. · 2007 [cited by applicant]
US 7644270B1 · Cherukumudi et al. · 2010 [cited by applicant]
US 8176328B2 · Chen · 2012 [cited by examiner]
US 8452958B2 · Sun et al. · 2013 [cited by applicant]
US 9172543B2 · Wnuk · 2015 [cited by applicant]
US 9197630B2 · Sharif et al. · 2015 [cited by applicant]
US 9231933B1 · Shenoy et al. · 2016 [cited by applicant]
US 9485101B2 · Bowen · 2016 [cited by applicant]
US 9660978B1 · Truskovsky et al. · 2017 [cited by applicant]
US 9680813B2 · Sade et al. · 2017 [cited by applicant]
US 9794249B1 · Truskovsky et al. · 2017 [cited by applicant]
US 9882727B1 · Veladanda et al. · 2018 [cited by applicant]
US 10021084B2 · Matthews et al. · 2018 [cited by applicant]
US 10212147B2 · Buendgen et al. · 2019 [cited by applicant]
US 10621577B2 · Castinado · 2020 [cited by examiner]
US 10652030B1 · Levy et al. · 2020 [cited by applicant]
US 10764263B2 · Rossi · 2020 [cited by applicant]
US 10771261B1 · Lazar et al. · 2020 [cited by applicant]
US 10812276B2 · Bojjireddy et al. · 2020 [cited by applicant]
US 10848323B2 · Barr et al. · 2020 [cited by applicant]
US 11153103B2 · Fynaardt et al. · 2021 [cited by applicant]
US 11196570B2 · Borne-Pons et al. · 2021 [cited by applicant]
US 11310059B2 · Leibmann et al. · 2022 [cited by applicant]
US 11362843B1 · Jiang et al. · 2022 [cited by applicant]
US 11368314B2 · Ray et al. · 2022 [cited by applicant]
US 11388594B2 · Uy et al. · 2022 [cited by applicant]
US 11438325B2 · Begun et al. · 2022 [cited by applicant]
US 11627123B2 · Stayskal et al. · 2023 [cited by applicant]
US 11706038B1 · Thakore et al. · 2023 [cited by applicant]
US 11888997B1 · Bowen et al. · 2024 [cited by applicant]
US 12088738B2 · Rosenthol et al. · 2024 [cited by applicant]
US 20020007346A1 · Qiu et al. · 2002 [cited by applicant]
US 20020174066A1 · Kleckner et al. · 2002 [cited by applicant]
US 20030037234A1 · Fu et al. · 2003 [cited by applicant]
US 20060047965A1 · Thayer · 2006 [cited by applicant]
US 20060101510A1 · Kadyk et al. · 2006 [cited by applicant]
US 20070005956A1 · Zilinskas et al. · 2007 [cited by applicant]
US 20070016782A1 · Crall et al. · 2007 [cited by applicant]
US 20070147619A1 · Bellows et al. · 2007 [cited by applicant]
US 20100030897A1 · Stradling · 2010 [cited by applicant]
US 20100325429A1 · Saha et al. · 2010 [cited by applicant]
US 20110113239A1 · Fu et al. · 2011 [cited by applicant]
US 20120036220A1 · Dare et al. · 2012 [cited by applicant]
US 20120240192A1 · Orazi · 2012 [cited by examiner]
US 20120246466A1 · Salvarani et al. · 2012 [cited by applicant]
US 20120278614A1 · Choi · 2012 [cited by examiner]
US 20130086642A1 · Resch · 2013 [cited by examiner]
US 20140298419A1 · Boubez et al. · 2014 [cited by applicant]
US 20150135299A1 · Liang et al. · 2015 [cited by applicant]
US 20150215308A1 · Manolov et al. · 2015 [cited by applicant]
US 20150279132A1 · Perotti · 2015 [cited by applicant]
US 20160277923A1 · Steffey et al. · 2016 [cited by applicant]
US 20170039373A1 · Sasin et al. · 2017 [cited by applicant]
US 20170126667A1 · Bishop et al. · 2017 [cited by applicant]
US 20170171191A1 · Cignetti et al. · 2017 [cited by applicant]
US 20170279807A1 · Bermúdez · 2017 [cited by examiner]
US 20170317837A1 · Alrawais et al. · 2017 [cited by applicant]
US 20170338967A1 · Lewison et al. · 2017 [cited by applicant]
US 20180083966A1 · Zhou et al. · 2018 [cited by applicant]
US 20180102904A1 · Lin et al. · 2018 [cited by applicant]
US 20180287804A1 · Geisbush · 2018 [cited by applicant]
US 20190026804A1 · Yin · 2019 [cited by applicant]
US 20190149342A1 · Fynaardt et al. · 2019 [cited by applicant]
US 20190165950A1 · Ibrahim · 2019 [cited by applicant]
US 20190166635A1 · McColgan et al. · 2019 [cited by applicant]
US 20190347406A1 · Lev-Ran · 2019 [cited by applicant]
US 20190349402A1 · Shukla et al. · 2019 [cited by applicant]
US 20190356817A1 · Bush · 2019 [cited by examiner]
US 20190363895A1 · Barr et al. · 2019 [cited by applicant]
US 20190372783A1 · Martinez et al. · 2019 [cited by applicant]
US 20200021575A1 · Rezvani et al. · 2020 [cited by applicant]
US 20200092095A1 · Yang et al. · 2020 [cited by applicant]
US 20200150972A1 · Ketkar et al. · 2020 [cited by applicant]
US 20200274718A1 · Hwang et al. · 2020 [cited by applicant]
US 20200274862A1 · Varvarezis et al. · 2020 [cited by applicant]
US 20200396089A1 · Guo et al. · 2020 [cited by applicant]
US 20210034767A1 · Free et al. · 2021 [cited by applicant]
US 20210126801A1 · Nix · 2021 [cited by applicant]
US 20210152547A1 · Barhudarian et al. · 2021 [cited by applicant]
US 20210211307A1 · Statia et al. · 2021 [cited by applicant]
US 20210218723A1 · Lekov et al. · 2021 [cited by applicant]
US 20210392002A1 · Gray et al. · 2021 [cited by applicant]
US 20210409403A1 · Lewin et al. · 2021 [cited by applicant]
US 20210409409A1 · Palanisamy · 2021 [cited by applicant]
US 20220014522A1 · Thomas · 2022 [cited by examiner]
US 20220038894A1 · Yoon et al. · 2022 [cited by applicant]
US 20220123951A1 · Lutz et al. · 2022 [cited by applicant]
US 20220150238A1 · Bhalerao · 2022 [cited by applicant]
US 20220239503A1 · Mallikarjuna et al. · 2022 [cited by applicant]
US 20220393886A1 · Williams et al. · 2022 [cited by applicant]
US 20230007474A1 · Ni · 2023 [cited by examiner]
US 20230032867A1 · Peddada et al. · 2023 [cited by applicant]
US 20230062888A1 · Colombano · 2023 [cited by examiner]
US 20230109231A1 · Adogla et al. · 2023 [cited by applicant]
US 20230121514A1 · Smith · 2023 [cited by applicant]
US 20230208655A1 · Statia et al. · 2023 [cited by applicant]
US 20230237155A1 · Jacquin et al. · 2023 [cited by applicant]
US 20230291574A1 · Held · 2023 [cited by examiner]
US 20230291577A1 · Thai et al. · 2023 [cited by applicant]
US 20230401307A1 · Pop et al. · 2023 [cited by applicant]
US 20230412397A1 · Gollent et al. · 2023 [cited by applicant]
US 20240015508A1 · Yoon et al. · 2024 [cited by applicant]
US 20240020373A1 · Ivanov et al. · 2024 [cited by applicant]
US 20240031146A1 · Marosi-Bauer et al. · 2024 [cited by applicant]
US 20240106886A1 · Roy et al. · 2024 [cited by applicant]
US 20240121603A1 · Yoon et al. · 2024 [cited by applicant]
US 20240146543A1 · Sahoo et al. · 2024 [cited by applicant]
US 20240333640A1 · Shevade et al. · 2024 [cited by applicant]
US 20240356763A1 · Goldberg et al. · 2024 [cited by applicant]
US 20240388510A1 · Madtha et al. · 2024 [cited by applicant]
US 20250030561A1 · Long et al. · 2025 [cited by applicant]
US 20250088373A1 · Uzun et al. · 2025 [cited by applicant]
US 20250097211A1 · Uzun et al. · 2025 [cited by applicant]
US 20250133401A1 · Lee et al. · 2025 [cited by applicant]
CN 112019477A · 2020 [cited by applicant]
CN 114884963A · 2022 [cited by applicant]
EP 1251670A2 · 2002 [cited by applicant]
EP 2267970A2 · 2010 [cited by applicant]
EP 2854349A1 · 2015 [cited by applicant]
EP 3772208B1 · 2024 [cited by applicant]
KR 1020110045459A · 2011 [cited by applicant]
WO 2006122024A2 · 2006 [cited by applicant]
WO 2022121461A1 · 2022 [cited by applicant]
WO 2022133026A1 · 2022 [cited by applicant]
WO 2023240360A1 · 2023 [cited by applicant]
WO 2025059187A1 · 2025 [cited by applicant]
“About Azure Key Vault certificates”, Retrieved from https://learn.microsoft.com/en-us/azure/key-vault/certificates/about-certificates, Feb. 8, 2023, pp. 1-8. [cited by applicant]
“About the Expressway”, Aug. 17, 2022. pp. 1-12. [cited by applicant]
“Automated certificate management for TLS certificates”, Retrieved from https://docs.servicenow.com/en-us/bundle/utah-it-operations-management/page/product/discovery/concept/ automated-cert-requests.html, Retrieved on M… [cited by applicant]
“AWS Certificate Manager FAQs”, Retrieved from https://aws.amazon.com/certificate-manager/faqs/, Retrieved on Mar. 24, 2023, pp. 1-17. [cited by applicant]
“Azure Instance Metadata Service”, Retrieved from https://learn.microsoft.com/en-us/azure/virtual-machines/instance-metadata-service?tabs=windows, Mar. 15, 2023, pp. 1-42. [cited by applicant]
“Cisco Expressway Certificate Creation and Use Deployment Guide”, Feb. 23, 2021, pp. 10. [cited by applicant]
“Deploying the CA bundle iApp”, Retrieved from https://www.f5.com/pdf/deployment-guides/f5-ca-bundle-dg.pdf, Dec. 14, 2017, pp. 1-9. [cited by applicant]
“DigiCert Public Key Infrastructure (PKI) Platform”, 2019, pp. 15. [cited by applicant]
“Get started with Key Vault certificates”, Retrieved from https://learn.microsoft.com/en-us/azure/key-vault/certificates/certificate-scenarios, Retrieved on Feb. 1, 2023, pp. 1-6. [cited by applicant]
“High Availability using Patching and Rolling AP Upgrade on Cisco Catalyst 9800 Wireless Controllers”, Copyright 2020, pp. 1-41. [cited by applicant]
“Manage Certificate Revocation Lists (CRLs)”, Jul. 23, 2021, pp. 1-4. [cited by applicant]
“PKI secrets engine”, Retrieved from https://developer.hashicorp.com/vault/docs/secrets/pki, Retrieved on May 4, 2023, pp. 1-3. [cited by applicant]
“Planning a certificate revocation list (CRL)”, Retrieved from https://docs.aws.amazon.com/privateca/latest/userguide/crl-planning.html, Retrieved on Jul. 28, 2023, p. 11. [cited by applicant]
“Release app updates with staged rollouts”, Retrieved from https://support.google.com/googleplay/android-developer/answer/6346149?hl=en#zippy=%2Crelease-a-staged-rollout-to-specific-countries, Retrieved on Apr. 27, 2023… [cited by applicant]
“Release Your App Update in a Staged Rollout”, Retrieved from https://developer.amazon.com/docs/app-submission/release-updates-in-staged-rollouts.html, Retrieved on Apr. 27, 2023, pp. 1-18. [cited by applicant]
“Rotate Security Certificates”, Retrieved from https://www.cockroachlabs.com/docs/stable/rotate-certificates, Retrieved on May 4, 2023, pp. 1-6. [cited by applicant]
“Rotating the Root CA and Leaf Certificates”, Retrieved from https://docs.pivotal.io/ops-manager/2-4/security/pcf-infrastructure/rotate-cas-and-leaf-certs.html, Nov. 5, 2020, pp. 1-9. [cited by applicant]
“Staged upgrade”, Retrieved from https://www.ibm.com/docs/en/order-management-sw/9.4.0?topic=migrating-staged-upgrade, Mar. 2, 2021, pp. 1-3. [cited by applicant]
“Troubleshoot SSL certificates”, Retrieved from https://cloud.google.com/load-balancing/docs/ssl-certificates/troubleshooting, Retrieved on Mar. 24, 2023, pp. 1-8. [cited by applicant]
“Tutorial: Configure certificate auto-rotation in Key Vault”, Retrieved from https://learn.microsoft.com/en-us/azure/key-vault/certificates/tutorial-rotate-certificates, Feb. 27, 2023, pp. 1-6. [cited by applicant]
“Updating the CA bundle”, Retrieved from https://docs.openshift.com/container-platform/4.9/security/certificates/updating-ca-bundle.html#ca-bundle-understanding_updating-ca-bundle, Retrieved on Mar. 24, 2023, pp. 1-2. [cited by applicant]
“Updating your private CA”, Retrieved from https://docs.aws.amazon.com/privateca/latest/userguide/PCAUpdateCA.html, Retrieved on Mar. 24, 2023, pp. 1-4. [cited by applicant]
“Use self-managed SSL certificates”, Retrieved from https://cloud.google.com/load-balancing/docs/ssl-certificates/self-managed-certs, Aug. 15, 2023, pp. 13. [cited by applicant]
“vSphere Security”, vmware, Update 3, Mar. 21, 2023, pp. 1-426. [cited by applicant]
“Working with Hosts”, Retrieved from https://docs.cloudstack.apache.org/projects/archived-cloudstack-administration/en/latest/hosts.html, Retrieved on Mar. 24, 2023, pp. 1-7. [cited by applicant]
Atutxa et al., “Improving efficiency and security of lloT communications using in-network validation of server certificate”, Computers in Industry, vol. 144, Jan. 2023, 103802, pp. 30. [cited by applicant]
Bigelow S.J., “Rolling deployment”, Retrieved from https://www.techtarget.com/searchitoperations/definition/rolling-deployment, Jan. 2023, pp. 4. [cited by applicant]
Este-Gracias S., “Rotate your CA seamlessly using a Vault PKI”, Retrieved from https://sestegra.medium.com/rotate-your-ca-seamlessly-using-a-vault-pki-9262228b4afb Sep. 29, 2022, pp. 1-49. [cited by applicant]
Ghanmi et al., “A Secure Data Storage in Multi-cloud Architecture Using Blowfish Encryption Algorithm”, Advanced Information Networking and Applications, Mar. 2022, pp. 398-408. [cited by applicant]
Jamal F., “Zero Trust for SSH—Secure One-click Server Access for Software Engineering Teams”, Retrieved from https://www.banyansecurity.io/blog/zero-trust-for-ssh/, Oct. 28, 2020, pp. 1-7. [cited by applicant]
Manjusha R. et al., “Secure Authentication and Access System for Cloud Computing Auditing Services Using Associated Digital Certificate”, Indian Journal of Science and Technology, vol. 8 (S7), Apr. 2015, pp. 220-227. [cited by applicant]
Nexthop Team, “Updated: Creating a Certificate Revocation List Distribution Point for Your Internal Certification Authority”, Retrieved from https://techcommunity.microsoft.com/t5/skype-for-business-blog/updated-creatin… [cited by applicant]
Rowley J., “Google's Moving Forward Together Proposals for Root CA Policy: Rotating Icas More Frequently”, Retrieved from https://www.digicert.com/blog/googles-moving-forward-together-proposals-for-root-ca-policy, Mar. … [cited by applicant]
Subhayu, “Different Phases of a Certificate Lifecycle Management Process for a secure WPA2-Enterprise network”, Certificate Lifecycle Management Oct. 6, 2022, Pp. 16. [cited by applicant]
Ylonen et al., “Security of Automated Access Management Using Secure Shell (SSH)”, NISTIR 7966 (Draft), Aug. 2014, pp. 43. [cited by applicant]
“What is Certificate Lifecycle Management”, Retrieved from https://www.encryptionconsulting.com/different-phases-of-a-certificate-lifecycle-management-process/, Aug. 1, 2024, pp. 1-12. [cited by applicant]