发明名称 Generating a CRL using a sub-system having resources separate from a main certificate authority sub-system
摘要 A server computing system initiates a first sub-system to generate a certificate revocation list (CRL) using resources that are separate from resources of a second sub-system that performs certificate authority (CA) management functions other than generating a CRL. The first sub-system receives a command from the second sub-system to update revocation data in a cache that is coupled to the first sub-system and generates a CRL using the updated revocation data in the cache. The first sub-system provides the CRL to the second sub-system.
申请公布号 US9419805(B2) 申请公布日期 2016.08.16
申请号 US201113190297 申请日期 2011.07.25
申请人 Red Hat, Inc. 发明人 Wnuk Andrew
分类号 H04L9/32;H04L29/06 主分类号 H04L9/32
代理机构 Lowenstein Sandler LLP 代理人 Lowenstein Sandler LLP
主权项 1. A method comprising: receiving, by a first server computer, a command from a second server computer to update revocation data; generating, using computing resources of the first server computer separate from computing resources of the second server computer, updated revocation data in view of the command; generating, using the computing resources of the first server computer separate from computing resources of the second server computer, a certificate revocation list (CRL) in view of the updated revocation data; receiving a status request regarding the first server computer; transmitting a response for the status request, the response comprising data indicating whether the first server computer is not busy, a scheduled time for generating the CRL, an amount of time to generate the CRL and a time the CRL is last generated; receiving, by the first server computer, a command to override the scheduled time for generating the CRL in view of the response; providing, by the first server computer, the CRL to the second server computer to update certificate records stored in a data store that is coupled to the second server computer, wherein the update is to cause at least one of: a digital certificate to be generated in view of the CRL, the digital certificate to be issued, or the CRL to be published; receiving, by the first server computer, a command to update configuration data for the CRL stored in a cache memory that is separate from the second server computer, wherein the configuration data comprising a schedule to generate the CRL; and providing a status update comprising a time the cache memory is last updated.
地址 Raleigh NC US
您可能感兴趣的专利