SSL certificate management method, device, equipment and system
By updating certificates at system startup and periodically, the inefficiency problem caused by the management of existing SSL certificates relying on manual operations is solved, and automatic updates and efficient operation and maintenance are achieved.
Patent Information
- Application Number
- CN202510225257.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2025-05-13
AI Technical Summary
The existing SSL certificate management process relies on manual operations, which is inefficient, error-prone and cannot be managed in batches, resulting in low operation and maintenance efficiency.
When the system starts, the network application server sends a certificate request to the certificate management server, obtains the target SSL certificate, and periodically updates the certificate after the system starts to ensure that the latest certificate is used.
Automatic update and management of SSL certificates is realized, manual operations are reduced, operation and maintenance efficiency is improved, and problems such as inefficiency, error-prone and inability to manage in batches are avoided.
Smart Images

Figure CN119996021A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to an SSL certificate management method, device, equipment and system. Background Art
[0002] SSL (Secure Socket Layer) certificate can also be called SSL server certificate. It is a digital certificate that complies with the SSL protocol and is issued by a globally trusted certificate authority after verifying the server's identity. The content of an SSL certificate may include: version, serial number, algorithm identifier, issuer, validity period, user, public key algorithm, public key, certificate signature algorithm, certificate signature, domain name, etc.
[0003] In order to ensure the security of data transmission, multiple network application servers use SSL certificates, that is, they provide HTTPS (Hypertext Transfer Protocol Secure) protocol network services based on SSL certificates. The functions of SSL certificates include: SSL certificates are used for identity authentication, and the identity of the network application server is verified by a third-party authority to ensure that the network application server is trustworthy. SSL certificates are used for data encryption: that is, the data being transmitted is encrypted through SSL certificates.
[0004] The management of SSL certificates has become an indispensable part of operation and maintenance work. However, the management process of SSL certificates often relies on manual operations, which is not only inefficient and error-prone, but also cannot be managed in batches. Summary of the invention
[0005] The present application provides a secure socket layer (SSL) certificate management method, the method comprising:
[0006] When the system is started, the network application server sends a first certificate request to the certificate management server, wherein the first certificate request includes the device identification of the network application server, so that the certificate management server obtains a first SSL certificate corresponding to the device identification; the network application server receives a first certificate response, and stores the first SSL certificate in the first certificate response as a target SSL certificate;
[0007] After the system is started, the network application server periodically sends a second certificate request to the certificate management server, wherein the second certificate request includes the device identifier, so that the certificate management server obtains a second SSL certificate corresponding to the device identifier; the network application server receives a second certificate response, and if the version of the second SSL certificate is newer than that of the first SSL certificate, updates the second SSL certificate in the second certificate response to the target SSL certificate;
[0008] The web application server communicates with the client based on the target SSL certificate.
[0009] The present application provides an SSL certificate management method, which is applied to a network application server, including:
[0010] When the system starts, a first certificate request is sent to a certificate management server, wherein the first certificate request includes the device identification of the network application server; a first certificate response returned by the certificate management server is received, wherein the first certificate response includes a first SSL certificate corresponding to the device identification obtained by the certificate management server; and the first SSL certificate in the first certificate response is stored as a target SSL certificate;
[0011] After the system is started, periodically sending a second certificate request to the certificate management server, wherein the second certificate request includes the device identification; receiving a second certificate response returned by the certificate management server, wherein the second certificate response includes a second SSL certificate corresponding to the device identification obtained by the certificate management server; if the version of the second SSL certificate is newer than that of the first SSL certificate, updating the second SSL certificate in the second certificate response to the target SSL certificate;
[0012] Communicate with the client based on the target SSL certificate.
[0013] The present application provides an SSL certificate management method, which is applied to a certificate management server, including:
[0014] Receiving a first certificate request sent by a network application server, the first certificate request including a device identifier of the network application server, the first certificate request being sent when the system is started;
[0015] Obtaining a first SSL certificate corresponding to the device identifier; sending a first certificate response to the network application server, wherein the first certificate response includes the first SSL certificate, so that the network application server stores the first SSL certificate in the first certificate response as a target SSL certificate;
[0016] receiving a second certificate request sent by the network application server, wherein the second certificate request includes the device identification, and the second certificate request is sent periodically after the system is started;
[0017] Obtain a second SSL certificate corresponding to the device identifier; send a second certificate response to the network application server, wherein the second certificate response includes the second SSL certificate, so that the network application server updates the second SSL certificate in the second certificate response to a target SSL certificate when the version of the second SSL certificate is newer than that of the first SSL certificate.
[0018] The present application provides an SSL certificate management device, which is applied to a network application server, including:
[0019] A sending module, configured to send a first certificate request to a certificate management server when the network application server system is started, wherein the first certificate request includes a device identifier of the network application server;
[0020] A receiving module, configured to receive a first certificate response returned by the certificate management server, wherein the first certificate response includes a first SSL certificate corresponding to the device identifier obtained by the certificate management server;
[0021] A processing module, configured to store the first SSL certificate in the first certificate response as a target SSL certificate;
[0022] A sending module, configured to periodically send a second certificate request to the certificate management server after the network application server system is started, wherein the second certificate request includes the device identification;
[0023] A receiving module, configured to receive a second certificate response returned by the certificate management server, wherein the second certificate response includes a second SSL certificate corresponding to the device identifier obtained by the certificate management server;
[0024] a processing module, configured to update the second SSL certificate in the second certificate response to a target SSL certificate if the version of the second SSL certificate is newer than the version of the first SSL certificate;
[0025] A communication module is used to communicate with the client based on the target SSL certificate.
[0026] The present application provides an SSL certificate management device, which is applied to a certificate management server, including:
[0027] A receiving module, configured to receive a first certificate request sent by a network application server, wherein the first certificate request includes a device identifier of the network application server, and the first certificate request is sent when the system is started;
[0028] An acquisition module, used to acquire a first SSL certificate corresponding to the device identifier;
[0029] A sending module, configured to send a first certificate response to the network application server, wherein the first certificate response includes the first SSL certificate, so that the network application server stores the first SSL certificate in the first certificate response as a target SSL certificate;
[0030] A receiving module, configured to receive a second certificate request sent by the network application server, wherein the second certificate request includes the device identification, and the second certificate request is sent periodically after the system is started;
[0031] An acquisition module, used to acquire a second SSL certificate corresponding to the device identifier;
[0032] The sending module is used to send a second certificate response to the network application server, the second certificate response including a second SSL certificate, so that the network application server updates the second SSL certificate in the second certificate response to a target SSL certificate when the version of the second SSL certificate is newer than that of the first SSL certificate.
[0033] The present application provides an electronic device, comprising: a processor and a machine-readable storage medium, wherein the machine-readable storage medium stores machine-executable instructions that can be executed by the processor; the processor is used to execute the machine-executable instructions to implement the above-mentioned SSL certificate management method.
[0034] The present application provides a secure socket layer (SSL) certificate management system, the SSL certificate management system comprising a network application server and a certificate management server, wherein:
[0035] The network application server is used to send a first certificate request to the certificate management server when the system is started, wherein the first certificate request includes a device identifier of the network application server;
[0036] The certificate management server is configured to obtain a first SSL certificate corresponding to the device identifier, and send a first certificate response to the network application server, wherein the first certificate response includes the first SSL certificate;
[0037] The network application server is configured to receive the first certificate response, and store the first SSL certificate in the first certificate response as a target SSL certificate;
[0038] The network application server is used to periodically send a second certificate request to the certificate management server after the system is started, wherein the second certificate request includes the device identification;
[0039] The certificate management server is used to obtain a second SSL certificate corresponding to the device identifier, and send a second certificate response to the network application server, where the second certificate response includes the second SSL certificate;
[0040] The network application server is configured to receive the second certificate response, and if the version of the second SSL certificate in the second certificate response is newer than the version of the first SSL certificate, update the second SSL certificate in the second certificate response to a target SSL certificate;
[0041] The network application server is used to communicate with the client based on the target SSL certificate.
[0042] The present application provides a computer program product, which may include a computer program, and the computer program implements the above-mentioned SSL certificate management method when executed by a processor.
[0043] The present application provides a machine-readable storage medium, which stores machine-executable instructions that can be executed by a processor; wherein the processor is used to execute the machine-executable instructions, and implement the above-mentioned SSL certificate management method when the machine-executable instructions are executed.
[0044] It can be seen from the above technical scheme that in the embodiment of the present application, when the system starts, the network application server obtains the SSL certificate from the certificate management server, and the network application server periodically sends a certificate request to the certificate management server. When the SSL certificate changes, the network application server actively obtains the changed SSL certificate from the certificate management server, quickly obtains the SSL certificate, and realizes automatic update of the SSL certificate. It does not rely on manual operation, and there are fewer operations involving operation and maintenance personnel. It can improve operation and maintenance efficiency, take into account both operation and maintenance efficiency and low cost, ensure system security, and avoid problems such as inefficiency, easy errors, and inability to manage in batches. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Figure 1A It is a flowchart of an SSL certificate management method in one implementation of the present application;
[0046] Figure 1B It is a flowchart of an SSL certificate management method in one implementation of the present application;
[0047] Figure 1C It is a flowchart of an SSL certificate management method in one implementation of the present application;
[0048] Figure 2 It is a structural diagram of an SSL certificate management system in one embodiment of the present application;
[0049] Figure 3 It is a flowchart of an SSL certificate management method in one implementation of the present application;
[0050] Figure 4 It is a flowchart of an SSL certificate management method in one implementation of the present application;
[0051] Figure 5 It is a flowchart of an SSL certificate management method in one implementation of the present application;
[0052] Figure 6 It is a flowchart of an SSL certificate management method in one implementation of the present application;
[0053] Fig. 7A and Figure 7B It is a structural diagram of an SSL certificate management device in one embodiment of the present application;
[0054] Figure 8 It is a hardware structure diagram of an electronic device in one embodiment of the present application. DETAILED DESCRIPTION
[0055] In the present application, a method for managing SSL certificates is proposed. Figure 1A FIG. 1 is a flow chart of the SSL certificate management method, which may include:
[0056] Step 101. When the system starts, the network application server sends a first certificate request to the certificate management server. The first certificate request includes the device identifier of the network application server, so that the certificate management server obtains the first SSL certificate corresponding to the device identifier; the network application server receives the first certificate response and stores the first SSL certificate in the first certificate response as the target SSL certificate.
[0057] Step 102: After the system is started, the network application server periodically sends a second certificate request to the certificate management server, where the second certificate request includes the device identifier of the network application server, so that the certificate management server obtains the second SSL certificate corresponding to the device identifier; the network application server receives the second certificate response, and if the version of the second SSL certificate is newer than that of the first SSL certificate, the second SSL certificate in the second certificate response is updated to the target SSL certificate, i.e., the existing target SSL certificate is replaced.
[0058] Step 103: The network application server communicates with the client based on the target SSL certificate.
[0059] Exemplarily, after receiving the second certificate request, if the second certificate request also includes the certificate identifier of the first SSL certificate, the certificate management server compares whether the certificate identifier of the second SSL certificate is the same as the certificate identifier of the first SSL certificate; if not, it determines that the version of the second SSL certificate is newer than the version of the first SSL certificate, and sends a second certificate response to the network application server. After receiving the second certificate response, the network application server determines that the version of the second SSL certificate is newer than the version of the first SSL certificate. Or,
[0060] After receiving the second certificate request, the certificate management server sends a second certificate response to the network application server, and the second certificate response includes the certificate identifier of the second SSL certificate. After receiving the second certificate response, the network application server compares whether the certificate identifier of the second SSL certificate is the same as the certificate identifier of the first SSL certificate. If not, it is determined that the version of the second SSL certificate is newer than the version of the first SSL certificate.
[0061] Exemplarily, the certificate management server can periodically scan the configured domain name list, which includes the mapping relationship between the domain names supported by the network application server, the certificate type and the status; if the domain name list includes the target domain name, the target domain name does not correspond to the SSL certificate or the interval between the expiration time of the SSL certificate corresponding to the target domain name and the current time is less than the preset threshold, and the status of the target domain name is online, and the online status indicates that the SSL certificate needs to be maintained, then the certificate management server generates a new SSL certificate for the target domain name, and verifies the new SSL certificate based on the certificate type corresponding to the target domain name; if the verification is successful, the certificate management server saves the correspondence between the certificate name corresponding to the target domain name and the new SSL certificate. Among them, the certificate management server saves the correspondence between the device identification of the network application server and the certificate name corresponding to the target domain name. Combined with the above two correspondences, the correspondence between the device identification of the network application server and the new SSL certificate can be obtained, and then the SSL certificate corresponding to the device identification can be obtained.
[0062] Exemplarily, the certificate management server verifies the new SSL certificate based on the certificate type corresponding to the target domain name, which may include but is not limited to: if the certificate type is a subdomain type, and the target domain name is a subdomain, the certificate management server may send a query message carrying the primary domain name to which the subdomain belongs to a DNS (Domain Name System) server, so that the DNS server returns the owner information of the primary domain name to which the subdomain belongs; if the owner information matches the account information of the operation and maintenance personnel used to configure the domain name list, it is determined that the new SSL certificate verification is successful; if the owner information does not match the account information, it is determined that the new SSL certificate verification has failed. Alternatively, if the certificate type is a wildcard primary domain name type, and the target domain name is a primary domain name, the certificate management server may send a query message carrying the primary domain name to the DNS server, so that the DNS server returns the owner information of the primary domain name; if the owner information matches the account information of the operation and maintenance personnel, it is determined that the new SSL certificate verification is successful; if the owner information does not match the account information, it is determined that the new SSL certificate verification has failed. Alternatively, if the certificate type is a wildcard multi-primary domain name type, and the target domain name includes multiple primary domain names, for each primary domain name, the certificate management server can send a query message carrying the primary domain name to the DNS server, so that the DNS server returns the owner information of the primary domain name; if the owner information of each primary domain name matches the account information of the operation and maintenance personnel, it is determined that the new SSL certificate verification is successful; if the owner information of any primary domain name does not match the account information, it is determined that the new SSL certificate verification has failed.
[0063] Exemplarily, when the network application server supports the first primary domain name, the certificate management server adds the first primary domain name to the domain name list, and the certificate type of the first primary domain name is a wildcard primary domain name type; the certificate management server generates a new SSL certificate for the first primary domain name. When the primary domain name supported by the network application server switches from the first primary domain name to the second primary domain name, the certificate management server adds a domain name set to the domain name list, the domain name set includes the first primary domain name and the second primary domain name, and the certificate type of the domain name set is a wildcard multi-primary domain name type; the certificate management server generates a new SSL certificate for the domain name set. When the configured domain name switching conditions are met, the certificate management server adds the second primary domain name to the domain name list, and the certificate type of the second primary domain name is a wildcard primary domain name type; the certificate management server generates a new SSL certificate for the second primary domain name.
[0064] It can be seen from the above technical scheme that in the embodiment of the present application, when the system starts, the network application server obtains the SSL certificate from the certificate management server, and the network application server periodically sends a certificate request to the certificate management server. When the SSL certificate changes, the network application server actively obtains the changed SSL certificate from the certificate management server, quickly obtains the SSL certificate, and realizes automatic update of the SSL certificate. It does not rely on manual operation, and there are fewer operations involving operation and maintenance personnel. It can improve operation and maintenance efficiency, take into account both operation and maintenance efficiency and low cost, ensure system security, and avoid problems such as inefficiency, easy errors, and inability to manage in batches.
[0065] In the embodiment of the present application, a SSL certificate management method is proposed. The method can be applied to a network application server. Figure 1B FIG. 4 is a flow chart of the method, which may include:
[0066] Step 111. When the system starts, send a first certificate request to the certificate management server, where the first certificate request includes the device identifier of the network application server; receive a first certificate response returned by the certificate management server, where the first certificate response includes a first SSL certificate corresponding to the device identifier obtained by the certificate management server; store the first SSL certificate in the first certificate response as the target SSL certificate.
[0067] Step 112: After the system is started, periodically send a second certificate request to the certificate management server, where the second certificate request includes the device identifier of the network application server; receive a second certificate response returned by the certificate management server, where the second certificate response includes a second SSL certificate corresponding to the device identifier obtained by the certificate management server; if the version of the second SSL certificate is newer than the version of the first SSL certificate, update the second SSL certificate in the second certificate response to the target SSL certificate.
[0068] Step 113: Communicate with the client based on the target SSL certificate.
[0069] It can be seen from the above technical scheme that in the embodiment of the present application, when the system starts, the network application server obtains the SSL certificate from the certificate management server, and the network application server periodically sends a certificate request to the certificate management server. When the SSL certificate changes, the network application server actively obtains the changed SSL certificate from the certificate management server, quickly obtains the SSL certificate, and realizes automatic update of the SSL certificate. It does not rely on manual operation, and there are fewer operations involving operation and maintenance personnel. It can improve operation and maintenance efficiency, take into account both operation and maintenance efficiency and low cost, ensure system security, and avoid problems such as inefficiency, easy errors, and inability to manage in batches.
[0070] In the embodiment of the present application, a SSL certificate management method is proposed. The method can be applied to a certificate management server. Figure 1C FIG. 4 is a flow chart of the method, which may include:
[0071] Step 121: Receive a first certificate request sent by a network application server, where the first certificate request includes a device identifier of the network application server, and the first certificate request is sent when the network application server is started.
[0072] Step 122, obtain the first SSL certificate corresponding to the device identifier; send a first certificate response to the network application server, the first certificate response may include a first SSL certificate, so that the network application server stores the first SSL certificate in the first certificate response as a target SSL certificate.
[0073] Step 123: Receive a second certificate request sent by the network application server, where the second certificate request includes a device identifier of the network application server, and the second certificate request is sent periodically after the system is started.
[0074] Step 124, obtain the second SSL certificate corresponding to the device identifier; send a second certificate response to the network application server, where the second certificate response may include a second SSL certificate, so that when the version of the second SSL certificate is newer than the version of the first SSL certificate, the network application server updates the second SSL certificate in the second certificate response to a target SSL certificate, and then communicates with the client based on the target SSL certificate.
[0075] Exemplarily, after receiving the second certificate request, if the second certificate request also includes the certificate identifier of the first SSL certificate, the certificate identifier of the second SSL certificate is compared with the certificate identifier of the first SSL certificate to see if they are the same; if not, it is determined that the version of the second SSL certificate is newer than the version of the first SSL certificate, and a second certificate response is sent to the network application server, so that after receiving the second certificate response, the network application server determines that the version of the second SSL certificate is newer than the version of the first SSL certificate. Or,
[0076] After receiving the second certificate request, a second certificate response is sent to the network application server, and the second certificate response includes the certificate identifier of the second SSL certificate, so that after receiving the second certificate response, the network application server compares the certificate identifier of the second SSL certificate with the certificate identifier of the first SSL certificate to see whether they are the same. If not, it is determined that the version of the second SSL certificate is newer than the version of the first SSL certificate.
[0077] Exemplarily, a configured domain name list may be scanned periodically, and the domain name list may include a mapping relationship between domain names supported by the network application server, certificate types, and statuses. If the domain name list includes a target domain name, the target domain name does not correspond to an SSL certificate or the interval between the expiration time of the SSL certificate corresponding to the target domain name and the current time is less than a preset threshold, and the status of the target domain name is online, which may indicate that the SSL certificate needs to be maintained, then a new SSL certificate is generated for the target domain name, and the new SSL certificate is verified based on the certificate type corresponding to the target domain name; if the verification is successful, the correspondence between the certificate name corresponding to the target domain name and the new SSL certificate may be saved. Among them, the certificate management server saves the correspondence between the device identification of the network application server and the certificate name corresponding to the target domain name.
[0078] Exemplarily, verifying the new SSL certificate based on the certificate type corresponding to the target domain name includes: if the certificate type is a subdomain type and the target domain name is a subdomain, sending a query message carrying the primary domain name to which the subdomain belongs to a DNS server so that the DNS server returns the owner information of the primary domain name to which the subdomain belongs; if the owner information matches the account information of the operation and maintenance personnel used to configure the domain name list, it is determined that the new SSL certificate verification is successful; if the owner information does not match the account information, it is determined that the new SSL certificate verification has failed. Or, if the certificate type is a wildcard primary domain type and the target domain name is a primary domain name, sending a query message carrying the primary domain name to the DNS server so that the DNS server returns the owner information of the primary domain name; if the owner information matches the account information of the operation and maintenance personnel, it is determined that the new SSL certificate verification is successful; if the owner information does not match the account information, it is determined that the new SSL certificate verification has failed. Or, if the certificate type is a wildcard multi-primary domain name type, the target domain name includes multiple primary domain names. For each primary domain name, a query message carrying the primary domain name is sent to the DNS server, so that the DNS server returns the owner information of the primary domain name; if the owner information of each primary domain name matches the account information of the operation and maintenance personnel, it is determined that the new SSL certificate verification is successful; if the owner information of any primary domain name does not match the account information, it is determined that the new SSL certificate verification has failed.
[0079] Exemplarily, when the network application server supports the first primary domain name, the first primary domain name is added to the domain name list, and the certificate type of the first primary domain name is a wildcard primary domain name type, thereby generating a new SSL certificate for the first primary domain name. When the primary domain name supported by the network application server is switched from the first primary domain name to the second primary domain name, a domain name set is added to the domain name list, the domain name set includes the first primary domain name and the second primary domain name, and the certificate type of the domain name set is a wildcard multi-primary domain name type, thereby generating a new SSL certificate for the domain name set. When the configured domain name switching condition is met, the second primary domain name is added to the domain name list, and the certificate type of the second primary domain name is a wildcard primary domain name type, thereby generating a new SSL certificate for the second primary domain name.
[0080] It can be seen from the above technical scheme that in the embodiment of the present application, when the system starts, the network application server obtains the SSL certificate from the certificate management server, and the network application server periodically sends a certificate request to the certificate management server. When the SSL certificate changes, the network application server actively obtains the changed SSL certificate from the certificate management server, quickly obtains the SSL certificate, and realizes automatic update of the SSL certificate. It does not rely on manual operation, and there are fewer operations involving operation and maintenance personnel. It can improve operation and maintenance efficiency, take into account both operation and maintenance efficiency and low cost, ensure system security, and avoid problems such as inefficiency, easy errors, and inability to manage in batches.
[0081] The above technical solutions of the embodiments of the present application are described below in combination with specific application scenarios.
[0082] In the embodiment of the present application, an SSL certificate management system is proposed. The SSL certificate management system may include but is not limited to a network application server (also referred to as a network application system, and the number of network application servers may be at least one), a certificate management server (also referred to as a certificate management system), a DNS server, and a client. Figure 2 The figure shows a schematic diagram of the structure of an SSL certificate management system.
[0083] For the DNS server, the DNS server is used to implement the domain name resolution function, which is a public service. When the certificate management server generates an SSL certificate, the certificate management server can interact with the DNS server to verify the SSL certificate and save the successfully verified SSL certificate.
[0084] For network application servers, network application systems can be deployed on servers, and the servers where network application systems are located are called network application servers, such as network application system A (service A), network application system B, network application system C, and network application system D. For each network application system, multiple servers can be deployed, and these servers form a cluster to provide unified services to the outside world.
[0085] For example, network application system A includes server A1 and server A2, and servers A1 and server A2 provide services to the outside in a unified manner. Network application system B includes server B1 and server B2, and servers B1 and server B2 provide services to the outside in a unified manner. Network application system C includes server C1 and server C2, and servers C1 and server C2 provide services to the outside in a unified manner. Network application system D includes server D1 and server D2, and servers D1 and server D2 provide services to the outside in a unified manner.
[0086] In this embodiment, the network application system is referred to as a network application server, and the processing process of the network application server is taken as an example, that is, the processing of the network application server is the processing of the network application system.
[0087] For each network application server, you can also expand or shrink the cluster of the network application server. For cluster expansion scenarios, when a new server joins the cluster (i.e., network application server), the new server can complete the loading of the SSL certificate when the system starts. For cluster shrinking scenarios, you can kick the server out of the cluster, and the SSL certificate will no longer be used after the server is shut down.
[0088] The network application server only needs to obtain the latest SSL certificate from the certificate management server. There is no need to synchronize changes in servers within the cluster to the certificate management server. The network application server and the certificate management server are loosely coupled, and changes in the network application server do not affect the implementation of the certificate management server.
[0089] For the client, the client is used to implement specific business functions. The client has a built-in domain name of the network application server. Different modules of the client implement different functions and use different domain names. These domain names may be different subdomains of the same main domain name, or subdomains of different main domain names. For example, client A can access network application server A through the domain name serviceA.domain1.com. Client B can access network application server B through the domain name serviceB.domain2.com. Client C can access network application server C through the domain name serviceC.domain2.com. Client D can access network application server D through the domain name serviceD.domain3.com or serviceD.domain4.com.
[0090] For the certificate management server, the operation and maintenance personnel (also known as the system operation and maintenance personnel) can add a domain name to the certificate management server, and the certificate management server can generate an SSL certificate for the domain name. The certificate management server can interact with the DNS server to verify the domain name. If the verification is successful, the SSL certificate of the domain name is saved. If the verification fails, the SSL certificate of the domain name is not saved.
[0091] Exemplarily, the network application server and the certificate management server meet the following design constraints: 1. The network interface definition complies with the TCP (Transmission Control Protocol) protocol. 2. The constraints of the software environment and the hardware environment (such as the operating environment and the development environment) are met, such as the processor meets the 4-core constraint, the DDR memory meets the 16G constraint, the storage medium meets the 40G hard disk constraint, the file system (disk) meets the NTFS constraint, the operating system meets the specified system constraint, and the network meets the 100M bandwidth constraint. 3. The constraints of the interface / protocol are met. 4. The constraints of the user interface are met. 5. The quality constraints are met.
[0092] Quality constraints can include scalability constraints. For example, considering the continuous growth in the number of connections, the network application server can be dynamically expanded. According to the number of single-machine connections and user scale in the actual stress test, the number of network application servers that need to be deployed is calculated, and then multiple network application servers are expanded. The certificate management server can be dynamically expanded. According to the number of single-machine connections and the number of network application servers in the actual stress test, the number of certificate management servers that need to be deployed is calculated, and then multiple certificate management servers are expanded.
[0093] The quality constraint may include a security constraint, wherein HTTPS is used for encrypted communication between the network application server and the certificate management server, and HTTPS is used for encrypted communication between the client and the network application server.
[0094] Quality constraints can include performance constraints. You can use an exclusive test environment to perform stress tests three times and obtain the average value as the number of connections supported by a single certificate management server. You can use an exclusive test environment to perform stress tests three times and obtain the average value as the number of connections supported by a single certificate network application server.
[0095] For example, a network application system is a network application that provides HTTPS protocol interface functions. A network application server is a server that has a specified operating system (such as a Linux operating system) installed and has a network application system deployed. A certificate management server can maintain domain name lists, certificate lists, and network application system lists, and provide functions such as automatic generation of SSL certificates and automatic renewal of SSL certificates. The client is installed on a smartphone or computer, connected to a network application server, and implements an application for business functions.
[0096] An SSL certificate can also be called an SSL server certificate. An SSL certificate is a digital certificate that complies with the SSL protocol and is issued by a globally trusted certificate authority after verifying the server's identity. The contents of an SSL certificate may include but are not limited to at least one of the following: domain name, version, serial number, algorithm identifier, issuer, validity period, user, public key algorithm, public key, certificate signature algorithm, and certificate signature.
[0097] In the above application scenario, an SSL certificate management method is proposed in the embodiment of the present application. The certificate management server can automatically generate an SSL certificate. Figure 3 As shown, the method may include:
[0098] Step 301: When a new domain name is online, the certificate management server adds the new domain name to the domain name list, adds the certificate name and certificate type corresponding to the new domain name, and sets the status of the new domain name to the online status.
[0099] Exemplarily, the certificate management server can maintain a domain name list, which can include mapping relationships between domain names, certificate names, certificate types, and statuses supported by the network application server. See Table 1 for an example of the domain name list, and the content of the domain name list is not limited.
[0100] Table 1
[0101]
[0102] In Table 1, the subdomain type can also be called a subdomain single domain certificate. The subdomain type is used to indicate that a domain name can be a subdomain, that is, serviceA.domain1.com can represent a subdomain. The wildcard primary domain type can also be called a primary domain wildcard certificate. The wildcard primary domain type is used to indicate that a domain name can be a primary domain name, that is, *.domain2.com can represent a primary domain name. The wildcard multi-primary domain type can also be called a multi-primary domain wildcard certificate. The wildcard multi-primary domain type is used to indicate that a domain name can be multiple primary domain names, that is, *.domain3.com represents one primary domain name, and *.domain4.com represents another primary domain name.
[0103] Exemplarily, the initial state of the domain name list is empty. When a new domain name comes online, that is, when a new network application system needs to go online, the certificate management server can add the domain name supported by the network application system (that is, the domain name supported by the network application server) to the domain name list, that is, add a table entry to add the domain name.
[0104] The system operation and maintenance personnel can also configure the certificate name corresponding to the new domain name, and the certificate management server adds the certificate name to the domain name list, that is, adds the certificate name to the table item corresponding to the new domain name.
[0105] The system operation and maintenance personnel can also determine the certificate type corresponding to the new domain name, and the certificate management server adds the certificate type to the domain name list, that is, adds the certificate type to the table item corresponding to the new domain name. For example, if the new domain name is a subdomain name, the certificate type corresponding to the new domain name is the subdomain name type. If the new domain name includes a primary domain name, the certificate type corresponding to the new domain name is the wildcard primary domain name type. If the new domain name includes multiple primary domain names, the certificate type corresponding to the new domain name is the wildcard multi-primary domain name type.
[0106] The certificate management server may also add the status of the new domain name in the domain name list, and set the status of the new domain name to an online status, and the online status may indicate that the SSL certificate needs to be maintained.
[0107] Step 302: The certificate management server periodically scans the domain name list. If the domain name list includes the target domain name, the certificate management server generates a new SSL certificate for the target domain name. If the domain name list does not include the target domain name, the certificate management server does not need to generate a new SSL certificate in the current period.
[0108] Exemplarily, the certificate management server can maintain a certificate list, which can include a mapping relationship between a certificate identifier (certificate ID), a certificate name, an expiration date, and an SSL certificate. See Table 2, which is an example of the certificate list, and the content of the certificate list is not limited.
[0109] Table 2
[0110] Certificate Identification Certificate Name Expiration time SSL Certificate 1 cert-serviceA.domain1 2024.9.4 JSON data 2 cert-domain2 2025.1.7 JSON data 3 cert-domain3-domain4 2025.1.19 JSON data
[0111] In Table 2, the certificate identifier can represent the unique identifier of the SSL certificate. Each time a new SSL certificate is added to the certificate list, the certificate identifier can be increased by 1 to ensure the uniqueness of the certificate identifier of the SSL certificate. The certificate name is configured by the system operation and maintenance personnel for the domain name. The certificate name corresponding to the same domain name can be the same. The same certificate name can correspond to multiple SSL certificates, that is, SSL certificates corresponding to multiple certificate identifiers. For example, for "cert-domain2", after generating SSL certificate 2 with certificate identifier 2 for "cert-domain2", when the expiration time of SSL certificate 2 is approaching, SSL certificate 4 with certificate identifier 4 can also be generated for "cert-domain2", that is, "cert-domain2" corresponds to SSL certificate 2 and SSL certificate 4.
[0112] An SSL certificate can have a validity period, such as 3 months or 1 year. If the SSL certificate expires, the client will fail to verify the SSL certificate (i.e., the verification result is failure when verifying the SSL certificate), indicating that the SSL certificate is not secure and will cause data transmission failure. Based on this, the SSL certificate can correspond to an expiration time. For example, when the validity period of the SSL certificate is 1 year, if the effective date of the SSL certificate is 2023.9.4, then the expiration time of the SSL certificate can be 2024.9.4.
[0113] The SSL certificate can be the actual certificate data (i.e. the content of the SSL certificate), i.e. the JSON data is the actual certificate data of the SSL certificate, and the SSL certificate is stored in JSON format. For example, the JSON data may include but is not limited to the domain name, version, serial number, algorithm identifier, issuer, validity period, user, public key algorithm, public key, certificate signature algorithm, and certificate signature of the SSL certificate.
[0114] For example, the certificate management server may scan the domain name list periodically, such as scanning the domain name list every hour. Each time the domain name list is scanned, the certificate management server sequentially traverses each domain name in the domain name list, and calls the currently traversed domain name the current domain name.
[0115] The certificate management server queries the certificate name corresponding to the current domain name through the domain name list, and queries whether there is an SSL certificate corresponding to the certificate name through the certificate list. If not, it means that the current domain name has not yet corresponded to the SSL certificate, that is, the current domain name is newly added to the domain name list, and the SSL certificate has not yet been generated for the current domain name. Therefore, the current domain name can be used as the target domain name, that is, the target domain name does not correspond to the SSL certificate.
[0116] If the certificate list contains an SSL certificate corresponding to the certificate name, it means that the current domain name has a corresponding SSL certificate. The certificate management server can also query the certificate list to determine the expiration time of the SSL certificate corresponding to the current domain name. If the interval between the expiration time and the current time is less than the preset threshold (which can be configured based on experience, such as 7 days, 5 days, etc.), it means that the SSL certificate corresponding to the current domain name is about to expire. Based on this, the certificate management server can also determine the status corresponding to the current domain name by querying the domain name list. If the status is online, it means that the SSL certificate corresponding to the current domain name needs to continue to be maintained. Therefore, the current domain name can be used as the target domain name, that is, the interval between the expiration time of the SSL certificate corresponding to the target domain name and the current time is less than the preset threshold, and the status of the target domain name is online. Alternatively, if the status is offline, it means that the SSL certificate corresponding to the current domain name does not need to be maintained. Therefore, the current domain name is not used as the target domain name, and the SSL certificate corresponding to the current domain name is no longer maintained, and the use ends after the SSL certificate expires.
[0117] If the certificate list contains an SSL certificate corresponding to the certificate name, the certificate management server can also query the certificate list to determine the expiration time of the SSL certificate corresponding to the current domain name. If the interval between the expiration time and the current time is not less than the preset threshold, it means that the SSL certificate corresponding to the current domain name has not expired, and the SSL certificate corresponding to the current domain name can continue to be used. Based on this, the current domain name is not used as the target domain name.
[0118] For each domain name, as shown in Table 1, the status of the domain name can be maintained in the domain name list. For example, if the SSL certificate corresponding to the domain name needs to be maintained, the system operation and maintenance personnel can update the status of the domain name to the online status. If the SSL certificate corresponding to the domain name does not need to be maintained, the system operation and maintenance personnel can update the status of the domain name to the offline status. In this way, when the SSL certificate corresponding to the domain name expires, the SSL certificate corresponding to the domain name can be deleted and no longer maintained.
[0119] Obviously, for each domain name in the domain name list, the certificate management server can use the above method to determine whether the domain name is the target domain name or not. If the target domain name is not included in the domain name list, the certificate management server does not need to generate a new SSL certificate in the current cycle, and the certificate generation process ends.
[0120] If the domain name list includes the target domain name (such as at least one target domain name), then for each target domain name, the certificate management server can generate a new SSL certificate for the target domain name. There is no restriction on the generation process of the new SSL certificate. The content of the new SSL certificate includes the domain name, version, serial number, algorithm identifier, issuer, validity period, user, public key algorithm, public key, certificate signature algorithm, certificate signature, etc.
[0121] To summarize, the certificate management server can start a scheduled task to periodically scan the domain name list. If a domain name does not correspond to an SSL certificate, or the SSL certificate corresponding to a domain name is about to expire, the domain name will be used as the target domain name, and an SSL certificate will be generated for the target domain name, thereby automatically renewing the SSL certificate.
[0122] Step 303: After the certificate management server generates a new SSL certificate for the target domain name, the certificate management server verifies the new SSL certificate based on the certificate type corresponding to the target domain name.
[0123] Exemplarily, the certificate management server may query the domain name list in Table 1 to obtain the certificate type corresponding to the target domain name, where the certificate type is a subdomain type, a wildcard primary domain type, or a wildcard multi-primary domain type.
[0124] For example, if the certificate type is a subdomain type, that is, the target domain name is a subdomain, such as when the target domain name is serviceA.domain1.com, the certificate type is a subdomain type, and serviceA.domain1.com is a subdomain. Based on this, the certificate management server can send a query message carrying the primary domain name to which the subdomain belongs (such as domain1.com) to the DNS server. After receiving the query message, the DNS server can return the owner information of the primary domain name to which the subdomain belongs to the certificate management server. For example, when an entity applies for a domain name on a DNS server, the DNS server can maintain the domain name and the owner information of the domain name. Based on this, the DNS server can query the owner information of the primary domain name to which the subdomain belongs.
[0125] For example, the system operation and maintenance personnel can log in to the certificate management server and query the owner information (value) from the certificate management server. The owner information can be a random string or other information, and there is no restriction on this. The system operation and maintenance personnel can provide the owner information (value) to the DNS server, and the DNS server maintains the domain name and the owner information (value) of the domain name.
[0126] System operation and maintenance personnel can log in to the user interface of the certificate management server and configure information such as the domain name list in the user interface. The system operation and maintenance personnel use a certain account information to log in to the user interface of the certificate management server. Therefore, the certificate management server can obtain the account information of the system operation and maintenance personnel (such as user name and password), that is, the account information of the operation and maintenance personnel used to configure the domain name list.
[0127] When the certificate management server generates a random string (value) for the system operation and maintenance personnel, it can bind the account information of the system operation and maintenance personnel and the random string, and provide the random string to the system operation and maintenance personnel, who then provide the random string as owner information to the DNS server.
[0128] Based on this, if the owner information of the main domain name to which the subdomain belongs matches the account information of the system operation and maintenance personnel (such as the random string bound to the owner information and the account information is the same), the certificate management server determines that the new SSL certificate verification is successful. If the owner information of the main domain name to which the subdomain belongs does not match the account information of the system operation and maintenance personnel, the certificate management server determines that the new SSL certificate verification has failed.
[0129] For example, if the certificate type is a wildcard primary domain name type, that is, the target domain name is the primary domain name, such as when the target domain name is *.domain2.com, the certificate type is a wildcard primary domain name type, and *.domain2.com is the primary domain name. Based on this, the certificate management server can send a query message carrying the primary domain name (such as *.domain2.com) to the DNS server. After receiving the query message, the DNS server can return the owner information of the primary domain name to the certificate management server. Based on this, if the owner information of the primary domain name matches the account information of the system operation and maintenance personnel (the operation and maintenance personnel used to configure the domain name list), the certificate management server determines that the new SSL certificate verification is successful. If the owner information of the primary domain name does not match the account information of the system operation and maintenance personnel, the certificate management server determines that the new SSL certificate verification has failed.
[0130] For example, if the certificate type is a wildcard multi-primary domain name type, that is, the target domain name includes multiple primary domain names, such as when the target domain names are *.domain3.com and *.domain4.com, the certificate type is a wildcard multi-primary domain name type, *.domain3.com is one primary domain name, and *.domain4.com is another primary domain name. Based on this, for each primary domain name, the certificate management server sends a query message carrying the primary domain name to the DNS server. After receiving the query message, the DNS server returns the owner information of the primary domain name to the certificate management server. If the owner information of each primary domain name matches the account information of the system operation and maintenance personnel, the certificate management server determines that the new SSL certificate verification is successful. If the owner information of any primary domain name does not match the account information of the system operation and maintenance personnel, the certificate management server determines that the new SSL certificate verification has failed.
[0131] The certificate management server can send a query message carrying the primary domain name "*.domain3.com" to the DNS server, and the DNS server returns the owner information of the primary domain name "*.domain3.com" to the certificate management server. The certificate management server can send a query message carrying the primary domain name "*.domain4.com" to the DNS server, and the DNS server returns the owner information of the primary domain name "*.domain4.com" to the certificate management server. If the owner information of "*.domain3.com" matches the account information of the system operation and maintenance personnel, and the owner information of "*.domain4.com" matches the account information of the system operation and maintenance personnel, the certificate management server determines that the new SSL certificate verification is successful. If the owner information of "*.domain3.com" does not match the account information of the system operation and maintenance personnel, and / or the owner information of "*.domain4.com" does not match the account information of the system operation and maintenance personnel, the certificate management server determines that the new SSL certificate verification has failed.
[0132] Step 304: After the certificate management server verifies the new SSL certificate, if the new SSL certificate verification fails, the certificate management server outputs an alarm message, which indicates that the domain name is abnormal and the system operation and maintenance personnel are required to adjust the domain names in the domain name list. This process will not be described in detail.
[0133] Alternatively, if the new SSL certificate verification succeeds, the certificate management server saves the correspondence between the certificate name corresponding to the target domain name and the new SSL certificate corresponding to the target domain name. The certificate management server saves the correspondence between the device identification of the network application server and the certificate name corresponding to the target domain name.
[0134] Exemplarily, when a new SSL certificate is generated for the target domain name and the new SSL certificate is successfully verified, the certificate management server can determine the certificate name corresponding to the target domain name, such as by querying Table 1 to obtain the certificate name corresponding to the target domain name. The certificate management server adds the certificate name corresponding to the target domain name and the new SSL certificate corresponding to the target domain name to the certificate list, thereby storing the new SSL certificate corresponding to the target domain name. For example, if the interval between the expiration time of the SSL certificate corresponding to the target domain name "serviceA.domain1.com" and the current time is less than a preset threshold, a new SSL certificate is generated for the target domain name "serviceA.domain1.com", the certificate name and SSL certificate are added to the certificate list, and the certificate identifier is automatically increased by 1, as shown in Table 3.
[0135] Table 3
[0136] Certificate Identification Certificate Name Expiration time SSL Certificate 1 cert-serviceA.domain1 2024.9.4 JSON data 2 cert-domain2 2025.1.7 JSON data 3 cert-domain3-domain4 2025.1.19 JSON data 4 cert-serviceA.domain1 2025.9.4 JSON data (new SSL certificate)
[0137] Exemplarily, the certificate management server may maintain a network application system list, which may include a mapping relationship between a device identifier of the network application server and a certificate name of the SSL certificate. See Table 4, which is an example of the network application system list, and is not limited thereto.
[0138] Table 4
[0139]
[0140]
[0141] In Table 4, serviceA can represent the device identifier of network application server A (i.e., the unique identifier of the device), and can also be called the system name of network application server A (such as the name of the network application system). serviceB can represent the device identifier of network application server B. serviceC can represent the device identifier of network application server C. serviceD can represent the device identifier of network application server D. cert-serviceA.domain1 can represent the certificate name of the SSL certificate used by network application server A. cert-domain2 represents the certificate name of the SSL certificate used by network application server B and network application server C, that is, it supports multiple network application servers to be associated with the same SSL certificate, that is, it supports the reuse of SSL certificates. cert-domain3-domain4 represents the certificate name of the SSL certificate used by network application server D.
[0142] Exemplarily, for the target domain name supported by the network application server, when the new SSL certificate corresponding to the target domain name is successfully verified, the certificate management server can also save the correspondence between the device identifier of the network application server and the certificate name of the new SSL certificate. For example, the certificate management server can obtain the device identifier of the network application server, such as the system operation and maintenance personnel can log in to the user interface of the certificate management server and configure the device identifier of the network application server in the user interface. Then, the certificate management server determines whether there is a correspondence between the device identifier of the network application server and the certificate name corresponding to the target domain name (obtained by querying Table 1) in the network application system list. If not, the certificate management server records the correspondence between the device identifier of the network application server and the certificate name corresponding to the target domain name in the network application system list. If so, there is no need to update the network application system list.
[0143] In summary, the mapping relationship between the new SSL certificate corresponding to the target domain name and the certificate name corresponding to the target domain name can be recorded in the certificate list, as shown in Table 3. The mapping relationship between the device identifier of the network application server and the certificate name corresponding to the target domain name can be recorded in the network application system list, as shown in Table 4. Combined with the above mapping relationship, the mapping relationship between the new SSL certificate corresponding to the target domain name and the device identifier of the network application server can be known, that is, the certificate management server saves the corresponding relationship between the device identifier of the network application server and the new SSL certificate corresponding to the target domain name.
[0144] At this point, for the target domain name in the domain name list, you can save the new SSL certificate for the target domain name.
[0145] Exemplarily, when the certificate management server periodically scans the domain name list, if a domain name has a corresponding SSL certificate, and the interval between the expiration time of the SSL certificate and the current time is less than a preset threshold (that is, the SSL certificate is about to expire), then if the status corresponding to the domain name is offline (that is, the system operation and maintenance personnel take the domain name offline in the domain name list, indicating that the SSL certificate corresponding to the domain name will no longer be maintained), the certificate management server will no longer maintain the SSL certificate corresponding to the domain name, and will stop using it after the SSL certificate expires, thereby filtering out the domain name in the offline state, and no longer renewing the SSL certificate for the domain name, and automatically stopping the renewal process.
[0146] For example, when a network application system goes offline and no longer provides services, the system operation and maintenance personnel will take the domain name offline in the certificate management server (i.e., modify the status in the domain name list), and the certificate management server will stop detecting and renewing the domain name. See Table 5 for an example of modifying the offline status.
[0147] Table 5
[0148]
[0149] In the embodiment of the present application, a SSL certificate management method is proposed, and the network application server can obtain the SSL certificate from the certificate management server. Figure 4 As shown, the method may include:
[0150] Step 401: When the system starts, the network application server sends a first certificate request to the certificate management server. The first certificate request may include a device identification of the network application server.
[0151] When the network application system is started, the network application server provides services to the outside through the network application system. Since there is no SSL certificate when the network application system is started, the network application server needs to load the SSL certificate once. Based on this, the network application server sends a first certificate request to the certificate management server. The network application server can have a device identifier of the network application server (such as the system name of the network application system) built in, so the first certificate request can include the device identifier of the network application server.
[0152] Step 402: The certificate management server parses the device identification of the network application server from the first certificate request, and obtains the SSL certificate corresponding to the device identification (hereinafter referred to as the first SSL certificate).
[0153] The certificate management server can query the network application system list shown in Table 4 through the device identification of the network application server to obtain the certificate name corresponding to the device identification. The certificate management server can query the certificate list shown in Table 3 through the certificate name to obtain the first SSL certificate corresponding to the certificate name.
[0154] When searching the certificate list shown in Table 3 by the certificate name, if an SSL certificate corresponding to the certificate name is obtained, the SSL certificate is used as the first SSL certificate corresponding to the certificate name. If multiple SSL certificates corresponding to the certificate name are obtained, the expiration time of each SSL certificate is determined, and the SSL certificate with the latest expiration time is used as the first SSL certificate corresponding to the certificate name, that is, the certificates can be arranged in reverse order according to the expiration time, and the first SSL certificate after the arrangement is used as the first SSL certificate corresponding to the certificate name.
[0155] When the certificate management server queries the certificate list shown in Table 3 through the certificate name, it can also obtain the certificate identifier corresponding to the first SSL certificate, and the certificate identifier can be 1, 2, 3, 4, etc.
[0156] Step 403: The certificate management server sends a first certificate response to the network application server. The first certificate response may include a first SSL certificate and a certificate identifier corresponding to the first SSL certificate.
[0157] Step 404: The network application server parses the first SSL certificate and the certificate identifier corresponding to the first SSL certificate from the first certificate response, stores the first SSL certificate as the target SSL certificate, and stores the certificate identifier corresponding to the first SSL certificate, which is used to compare the versions of different SSL certificates.
[0158] Step 405: The network application server communicates with the client based on the target SSL certificate.
[0159] For example, when a client accesses a network application server through a domain name, the client obtains the target SSL certificate through the HTTPS handshake protocol. Then, the client verifies the domain name in the target SSL certificate and verifies whether the target SSL certificate is within the validity period. If the verification fails, the communication process ends, and the client does not exchange application data with the network application server. If the verification succeeds, the client negotiates a symmetric key with the network application server based on the content of the target SSL certificate (such as public key algorithm, public key, certificate signature algorithm, certificate signature, etc.). On this basis, when the client sends application data to the network application server, it can use a symmetric key to encrypt the application data and send the encrypted data. When the network application server sends application data to the client, it can use a symmetric key to encrypt the application data and send the encrypted data.
[0160] Step 406: After the system is started, the network application server periodically sends a second certificate request to the certificate management server. The second certificate request may include a device identifier of the network application server.
[0161] After the network application system is started, the network application server starts a scheduled task. Every fixed period of time (such as 1 hour), the network application server sends a second certificate request to the certificate management server. In this way, when the SSL certificate corresponding to the network application server changes, it only takes 1 hour for the network application server to obtain the latest SSL certificate, thereby automatically updating the SSL certificate within 1 hour.
[0162] Step 407: The certificate management server parses the device identification of the network application server from the second certificate request, and obtains the SSL certificate corresponding to the device identification (hereinafter referred to as the second SSL certificate).
[0163] Step 408: The certificate management server sends a second certificate response to the network application server. The second certificate response may include a second SSL certificate and a certificate identifier corresponding to the second SSL certificate.
[0164] Step 409, the network application server parses the second SSL certificate and the certificate identifier corresponding to the second SSL certificate from the second certificate response, and compares whether the certificate identifier of the second SSL certificate is the same as the certificate identifier of the first SSL certificate. If so, it means that the second SSL certificate and the first SSL certificate are SSL certificates of the same version, and there is no need to update the SSL certificate. The network application server discards the certificate identifier corresponding to the second SSL certificate and the second SSL certificate. If not, it means that the second SSL certificate and the first SSL certificate are SSL certificates of different versions, that is, the version of the second SSL certificate is newer than the version of the first SSL certificate, and step 410 is executed.
[0165] Step 410: If the version of the second SSL certificate is newer than that of the first SSL certificate, the network application server updates the second SSL certificate to the target SSL certificate, that is, replaces the existing target SSL certificate, and stores the certificate identifier corresponding to the second SSL certificate. In the subsequent process, the second SSL certificate serves as the first SSL certificate, and the certificate identifier corresponding to the second SSL certificate serves as the certificate identifier corresponding to the first SSL certificate.
[0166] Step 411: The network application server communicates with the client based on the target SSL certificate.
[0167] For example, as shown in Table 2, the network application server obtains the first SSL certificate with a certificate identifier of 1, uses the first SSL certificate as the target SSL certificate, and communicates with the client based on the target SSL certificate. When the first SSL certificate is about to expire, a new SSL certificate can be automatically generated. As shown in Table 3, the network application server can obtain the second SSL certificate with a certificate identifier of 4, uses the second SSL certificate as the target SSL certificate, and communicates with the client based on the target SSL certificate.
[0168] In the embodiment of the present application, a SSL certificate management method is proposed, and the network application server can obtain the SSL certificate from the certificate management server. Figure 5 As shown, the method may include:
[0169] Step 501: When the system starts, the network application server sends a first certificate request to the certificate management server. The first certificate request may include a device identification of the network application server.
[0170] Step 502: The certificate management server parses the device identification of the network application server from the first certificate request, and obtains a first SSL certificate corresponding to the device identification.
[0171] Step 503: The certificate management server sends a first certificate response to the network application server. The first certificate response may include a first SSL certificate and a certificate identifier corresponding to the first SSL certificate.
[0172] Step 504: The network application server parses the first SSL certificate and the certificate identifier corresponding to the first SSL certificate from the first certificate response, stores the first SSL certificate as the target SSL certificate, and stores the certificate identifier corresponding to the first SSL certificate, which is used to compare the versions of different SSL certificates.
[0173] Step 505: The network application server communicates with the client based on the target SSL certificate.
[0174] Step 506: After the system is started, the network application server periodically sends a second certificate request to the certificate management server. The second certificate request may include the device identifier of the network application server and the certificate identifier corresponding to the first SSL certificate. Compared with step 406, the certificate identifier needs to be additionally transmitted.
[0175] Step 507: The certificate management server parses the device identifier of the network application server and the certificate identifier corresponding to the first SSL certificate from the second certificate request, and obtains the second SSL certificate corresponding to the device identifier.
[0176] Step 508: The certificate management server compares the certificate identifier of the second SSL certificate with the certificate identifier of the first SSL certificate to see if they are the same. If so, it means that the second SSL certificate and the first SSL certificate are SSL certificates of the same version, and there is no need to update the SSL certificate. Therefore, the certificate management server does not send a second certificate response to the network application server, which can avoid transmitting the second SSL certificate, save bandwidth overhead, and reduce data transmission volume. If not, it means that the second SSL certificate and the first SSL certificate are SSL certificates of different versions, that is, the version of the second SSL certificate is newer than the version of the first SSL certificate, and step 509 is executed.
[0177] Step 509: The certificate management server sends a second certificate response to the network application server. The second certificate response may include a second SSL certificate and a certificate identifier corresponding to the second SSL certificate.
[0178] Step 510: After receiving the second certificate response, the network application server parses the second SSL certificate and the certificate identifier corresponding to the second SSL certificate from the second certificate response, determines that the version of the second SSL certificate is newer than the version of the first SSL certificate, updates the second SSL certificate to the target SSL certificate, and stores the certificate identifier corresponding to the second SSL certificate. In the subsequent process, the second SSL certificate is used as the first SSL certificate, and the certificate identifier corresponding to the second SSL certificate is used as the certificate identifier corresponding to the first SSL certificate.
[0179] Step 511: The network application server communicates with the client based on the target SSL certificate.
[0180] In a possible implementation, when the client is released, the client has a built-in primary domain name (recorded as the first primary domain name), and the network application server supports the first primary domain name. In the subsequent business development process, if the primary domain name needs to be switched (such as a change in the brand name, etc.), the client's primary domain name needs to be modified (recorded as the second primary domain name), and the primary domain name supported by the network application server is switched from the first primary domain name to the second primary domain name. In order to switch the client's primary domain name from the first primary domain name to the second primary domain name, for the newly released client, the client has a built-in second primary domain name. For the released client, the client has a built-in first primary domain name, and the client needs to be upgraded before the first primary domain name can be switched to the second primary domain name.
[0181] However, considering that users will not upgrade the client immediately after the version is updated, and users themselves decide when to upgrade the client, even if a client supporting the second primary domain name has been released, the first primary domain name cannot be taken offline, but both the first primary domain name and the second primary domain name need to be supported at the same time.
[0182] In view of the above findings, an SSL certificate management method is proposed in the embodiment of the present application, which can support the domain name switching scenario. In the domain name switching scenario, before most clients complete the upgrade, it is necessary to support the first primary domain name and the second primary domain name at the same time. Figure 6 As shown, the method may include:
[0183] Step 601: When the network application server supports the first primary domain name, the certificate management server adds the first primary domain name to the domain name list, and the certificate type of the first primary domain name is a wildcard primary domain name type.
[0184] For example, the system operation and maintenance personnel can configure the first primary domain name (such as *.domain3.com), the certificate name and certificate type corresponding to the first primary domain name, etc. in the user interface of the certificate management server. In this way, the certificate management server can add the first primary domain name (such as *.domain3.com) to the domain name list, and add the certificate name and certificate type corresponding to the first primary domain name, and set the status of the first primary domain name to the online status. The certificate type can be a wildcard primary domain name type. The process can refer to step 301.
[0185] Step 602: The certificate management server adds a mapping relationship between the device identifier of the network application server and the certificate name corresponding to the first primary domain name in the network application system list.
[0186] For example, the system operation and maintenance personnel can configure the device identifier of the network application server (such as serviceD) and the certificate name corresponding to the first primary domain name (such as cert-domain3) in the user interface of the certificate management server. In this way, the certificate management server can add the mapping relationship between the device identifier of the network application server and the certificate name corresponding to the first primary domain name in the network application system list.
[0187] Step 603: The certificate management server generates a new SSL certificate for the first primary domain name, and saves the correspondence between the certificate name corresponding to the first primary domain name and the new SSL certificate corresponding to the first primary domain name.
[0188] For example, when the certificate management server scans the domain name list, if the first primary domain name does not correspond to the SSL certificate, the first primary domain name can be used as the target domain name, a new SSL certificate can be generated for the first primary domain name, and the new SSL certificate can be verified based on the certificate type (wildcard primary domain name type) corresponding to the first primary domain name. If the new SSL certificate is successfully verified, the corresponding relationship between the certificate name corresponding to the first primary domain name and the new SSL certificate is saved. The process can be referred to steps 302-304, and will not be repeated here.
[0189] Step 604: The network application server obtains the SSL certificate corresponding to the first primary domain name from the certificate management server, stores the SSL certificate as a target SSL certificate, and communicates with the client based on the target SSL certificate.
[0190] For example, step 604 can refer to Figure 4 The process shown or Figure 5 The process shown will not be repeated here.
[0191] Step 605: When the primary domain name supported by the network application server switches from the first primary domain name to the second primary domain name, the certificate management server adds a domain name set to the domain name list, where the domain name set includes both the first primary domain name and the second primary domain name, and the certificate type of the domain name set is a wildcard multi-primary domain name type.
[0192] For example, in a domain name switching scenario, when switching from the first primary domain name to the second primary domain name, it is necessary to support both the first primary domain name and the second primary domain name. In order to support the first primary domain name and the second primary domain name, the system operation and maintenance personnel can configure the first primary domain name (such as *.domain3.com) and the second primary domain name (such as *.domain4.com) in the user interface of the certificate management server. The set of the first primary domain name and the second primary domain name can be called a domain name set, and the certificate name and certificate type and other contents can be configured in the user interface.
[0193] On this basis, the certificate management server can add a domain name set to the domain name list. The domain name set needs to include both the first primary domain name and the second primary domain name, and add the certificate name and certificate type, set the status to the online status, and the certificate type can be a wildcard multi-primary domain name type.
[0194] Step 606: The certificate management server adds a mapping relationship between the device identifier of the network application server and the certificate name corresponding to the domain name set in the network application system list.
[0195] For example, the system operation and maintenance personnel can configure the device identifier of the network application server (such as serviceD) and the certificate name corresponding to the domain name set (such as cert-domain3-domain4) in the user interface of the certificate management server. In this way, the certificate management server can add the mapping relationship between the device identifier of the network application server and the certificate name corresponding to the domain name set in the network application system list.
[0196] Step 607: The certificate management server generates a new SSL certificate for the domain name set, and saves the correspondence between the certificate name corresponding to the domain name set and the new SSL certificate corresponding to the domain name set.
[0197] For example, when the certificate management server scans the domain name list, if the domain name set does not correspond to the SSL certificate, the domain name set can be used as the target domain name, a new SSL certificate can be generated for the domain name set, and the new SSL certificate can be verified based on the certificate type corresponding to the domain name set (i.e., wildcard multi-primary domain name type), that is, the first primary domain name (such as *.domain3.com) and the second primary domain name (such as *.domain4.com) are verified respectively. If the new SSL certificate is successfully verified, the corresponding relationship between the certificate name corresponding to the domain name set and the new SSL certificate is saved. The process can be referred to steps 302-304, and will not be repeated here.
[0198] Step 608: The network application server obtains the SSL certificate corresponding to the domain name set from the certificate management server, stores the SSL certificate as a target SSL certificate, and communicates with the client based on the target SSL certificate.
[0199] For the new version of the client, the network application server can be accessed through the second primary domain name (such as *.domain4.com). Since the target SSL certificate is the SSL certificate for the first primary domain name (such as *.domain3.com) and the second primary domain name, the new version of the client can successfully access it through the second primary domain name.
[0200] In addition, for old version clients, the network application server can be accessed through the first primary domain name (such as *.domain3.com). Since the target SSL certificate is the SSL certificate for the first primary domain name and the second primary domain name, the old version client can successfully access it through the first primary domain name.
[0201] Step 609: When the configured domain name switching conditions are met, the network application server only supports the second primary domain name, and the network application server no longer supports the first primary domain name. The certificate management server adds the second primary domain name to the domain name list, and the certificate type of the second primary domain name is a wildcard primary domain name type.
[0202] For example, considering that users will not upgrade the client immediately after the version is updated, and users themselves decide when to upgrade the client, the first primary domain name and the second primary domain name need to be supported simultaneously for a period of time, waiting for users to upgrade their clients. On this basis, the domain name switching condition can be a duration, such as a few months, a year, or several years. In this way, the timing starts from the time a new SSL certificate is generated for the domain name set, and when the duration meets the preset duration, it is determined that the domain name switching condition is met. Alternatively, the domain name switching condition can be the proportion of upgraded clients, such as 95%, 90%, etc. In this way, if the proportion of clients that have completed the upgrade reaches a preset proportion, it is determined that the domain name switching condition is met. Of course, the above are just two examples.
[0203] For example, when the domain name switching conditions are met, the system operation and maintenance personnel can configure the second primary domain name (such as *.domain4.com), the certificate name and certificate type corresponding to the second primary domain name, etc. in the user interface of the certificate management server. In this way, the certificate management server can add the second primary domain name to the domain name list, add the certificate name and certificate type corresponding to the second primary domain name, and set the status of the second primary domain name to the online status. The certificate type can be a wildcard primary domain name type.
[0204] Step 610: The certificate management server adds a mapping relationship between the device identifier of the network application server and the certificate name corresponding to the second primary domain name in the network application system list.
[0205] For example, the system operation and maintenance personnel can configure the device identifier of the network application server (such as serviceD) and the certificate name corresponding to the second primary domain name (such as cert-domain4) in the user interface of the certificate management server. In this way, the certificate management server can add the mapping relationship between the device identifier of the network application server and the certificate name corresponding to the second primary domain name in the network application system list.
[0206] For example, for step 602, see Table 6, which is an example of a network application system list. Before the primary domain name is switched, the device identifier (serviceD) can be associated with the SSL certificate cert-domain3. For step 606, see Table 7, which is an example of a network application system list. During the transition period of the primary domain name switch, the device identifier (serviceD) can be associated with the SSL certificate cert-domain3-domain4. For step 610, see Table 8, which is an example of a network application system list. After the primary domain name switch is completed, the device identifier (serviceD) can be associated with the SSL certificate cert-domain4.
[0207] Table 6
[0208] Device ID of the network application server The certificate name of the SSL certificate serviceA cert-serviceA.domain1 serviceB cert-domain2 serviceC cert-domain2 serviceD cert-domain3
[0209] Table 7
[0210] Device ID of the network application server The certificate name of the SSL certificate serviceA cert-serviceA.domain1 serviceB cert-domain2 serviceC cert-domain2 serviceD cert-domain3-domain4
[0211] Table 8
[0212]
[0213]
[0214] Step 611: The certificate management server generates a new SSL certificate for the second primary domain name, and saves the correspondence between the certificate name corresponding to the second primary domain name and the new SSL certificate corresponding to the second primary domain name.
[0215] Step 612: The network application server obtains the SSL certificate corresponding to the second primary domain name from the certificate management server, stores the SSL certificate as a target SSL certificate, and communicates with the client based on the target SSL certificate.
[0216] Exemplarily, after the certificate management server generates a new SSL certificate for the second primary domain name, the certificate management server can take offline the SSL certificate corresponding to *.domain3.com, and the certificate management server takes offline the SSL certificates corresponding to *.domain3.com and *.domain4.com, and stops the renewal of these two SSL certificates.
[0217] For example, the certificate management server does not need to know the internal situation of the network application server cluster, for example, it does not need to know the IP addresses of the servers in the cluster, nor does it need to know the increase or decrease of servers, nor does it need to know whether a server has loaded an SSL certificate or whether the SSL certificate has been updated. The certificate management server only maintains the domain name list, certificate list and network application system list to complete the SSL certificate association, and the coupling between the certificate management server and the network application server is relatively low.
[0218] In a possible implementation, when the network application server sends a certificate request (such as the first certificate request or the second certificate request) to the certificate management server, the certificate request carries the unique identifier of the network application server (such as the system name). When the certificate management server sends a certificate response (such as the first certificate response or the second certificate response) to the network application server, the certificate response carries the SSL certificate and the certificate identifier of the SSL certificate. Based on this, the certificate management server provides an "obtain the latest certificate information interface", the request parameters of which include the system name, and the response parameters of which include the SSL certificate and the certificate identifier.
[0219] For example, the protocol of the "Get the latest certificate information interface" is HTTP or HTTPS, the request method of the "Get the latest certificate information interface" is POST, and the request Body is JSON.
[0220] For example, the request parameters of the interface can be seen in Table 9.
[0221] Table 9
[0222] parameter type Required illustrate serviceName String yes System Name
[0223] For example, the response parameters of the interface can be seen in Table 10.
[0224] Table 10
[0225]
[0226]
[0227] As can be seen from the above technical solutions, the present application relates to a SSL certificate management and update method, which can realize automatic update of SSL certificates. When the SSL certificate changes, the network application server quickly obtains the SSL certificate, realizes automatic update of the SSL certificate, does not rely on manual operation, and the operation and maintenance personnel intervene in relatively few operations, which can improve the operation and maintenance efficiency, take into account the operation and maintenance efficiency and low cost, ensure system security, and avoid problems such as inefficiency, easy errors, and inability to manage in batches. It can support SSL certificate reuse and support SSL certificate switching. The network application server is decoupled from the certificate management server, with fewer abnormal scenarios and a more stable system. During the validity period of each SSL certificate, renewal and SSL certificate replacement are automatically completed to reduce maintenance costs. Each network application server is composed of a cluster of multiple servers. When a new server is added to the cluster, the SSL certificate is automatically loaded. During the normal operation of the system, the SSL certificate is automatically renewed and replaced. When a server is offline, the SSL certificate is automatically stopped from being updated. For multiple subdomains using the same primary domain name, multiple network application servers can reuse the same SSL certificate to save costs. By supporting multiple primary domain name wildcard certificates and combining the dynamic configuration of the network application system list, it is convenient to replace the primary domain name for the network application server.
[0228] Based on the same application concept as the above method, the present application embodiment proposes an SSL certificate management device applied to a network application server, see Fig. 7A As shown, it is a schematic diagram of the structure of the device, comprising:
[0229] The sending module 711 is used to send a first certificate request to the certificate management server when the network application server system is started, wherein the first certificate request includes the device identification of the network application server; the receiving module 712 is used to receive a first certificate response returned by the certificate management server, wherein the first certificate response includes a first SSL certificate corresponding to the device identification obtained by the certificate management server; the processing module 713 is used to store the first SSL certificate in the first certificate response as a target SSL certificate;
[0230] The sending module 711 is used to periodically send a second certificate request to the certificate management server after the network application server system is started, wherein the second certificate request includes the device identification; the receiving module 712 is used to receive a second certificate response returned by the certificate management server, wherein the second certificate response includes a second SSL certificate corresponding to the device identification obtained by the certificate management server; the processing module 713 is used to update the second SSL certificate in the second certificate response to a target SSL certificate if the version of the second SSL certificate is newer than that of the first SSL certificate;
[0231] The communication module 714 is used to communicate with the client based on the target SSL certificate.
[0232] Based on the same application concept as the above method, the present application embodiment proposes an SSL certificate management device applied to a certificate management server, see Figure 7B As shown, it is a schematic diagram of the structure of the device, comprising:
[0233] A receiving module 721 is configured to receive a first certificate request sent by a network application server, wherein the first certificate request includes a device identifier of the network application server, and the first certificate request is sent when the system is started;
[0234] An acquisition module 722 is used to acquire a first SSL certificate corresponding to the device identifier;
[0235] A sending module 723 is used to send a first certificate response to the network application server, where the first certificate response includes the first SSL certificate, so that the network application server stores the first SSL certificate in the first certificate response as a target SSL certificate;
[0236] A receiving module 721 is configured to receive a second certificate request sent by the network application server, wherein the second certificate request includes the device identification, and the second certificate request is sent periodically after the system is started;
[0237] An acquisition module 722 is used to acquire a second SSL certificate corresponding to the device identifier;
[0238] The sending module 723 is used to send a second certificate response to the network application server, where the second certificate response includes a second SSL certificate, so that the network application server updates the second SSL certificate in the second certificate response to a target SSL certificate when the version of the second SSL certificate is newer than that of the first SSL certificate.
[0239] Exemplarily, the sending module 723 is further used to, after receiving the second certificate request, if the second certificate request also includes the certificate identifier of the first SSL certificate, compare whether the certificate identifier of the second SSL certificate is the same as the certificate identifier of the first SSL certificate; if not, determine that the version of the second SSL certificate is newer than the version of the first SSL certificate, and send a second certificate response to the network application server, so that the network application server determines that the version of the second SSL certificate is newer than the version of the first SSL certificate after receiving the second certificate response. Or,
[0240] After receiving the second certificate request, a second certificate response is sent to the network application server, wherein the second certificate response includes the certificate identifier of the second SSL certificate, so that after receiving the second certificate response, the network application server compares the certificate identifier of the second SSL certificate with the certificate identifier of the first SSL certificate to see whether they are the same; if not, it is determined that the version of the second SSL certificate is newer than that of the first SSL certificate.
[0241] Exemplarily, the acquisition module 722 is also used to periodically scan the configured domain name list, which may include the mapping relationship between the domain names supported by the network application server, the certificate type and the status. If the domain name list includes the target domain name, the target domain name does not correspond to the SSL certificate or the interval between the expiration time of the SSL certificate corresponding to the target domain name and the current time is less than a preset threshold, and the status of the target domain name is online, which may indicate that the SSL certificate needs to be maintained, then a new SSL certificate is generated for the target domain name, and the new SSL certificate is verified based on the certificate type corresponding to the target domain name; if the verification is successful, the correspondence between the certificate name corresponding to the target domain name and the new SSL certificate can be saved. Among them, the certificate management server saves the correspondence between the device identification of the network application server and the certificate name corresponding to the target domain name.
[0242] Exemplarily, when verifying the new SSL certificate based on the certificate type corresponding to the target domain name, the acquisition module 722 is specifically used to: if the certificate type is a subdomain type and the target domain name is a subdomain, a query message carrying the primary domain name to which the subdomain belongs is sent to the DNS server, so that the DNS server returns the owner information of the primary domain name to which the subdomain belongs; if the owner information matches the account information of the operation and maintenance personnel used to configure the domain name list, it is determined that the new SSL certificate verification is successful; if the owner information does not match the account information, it is determined that the new SSL certificate verification has failed; or, if the certificate type is a wildcard primary domain type and the target domain name is a primary domain name, a query message carrying the primary domain name is sent to the DNS server. message, so that the DNS server returns the owner information of the primary domain name; if the owner information matches the account information of the operation and maintenance personnel, it is determined that the new SSL certificate verification is successful; if the owner information does not match the account information, it is determined that the new SSL certificate verification has failed; or, if the certificate type is a wildcard multi-primary domain name type, the target domain name includes multiple primary domain names, and for each primary domain name, a query message carrying the primary domain name is sent to the DNS server, so that the DNS server returns the owner information of the primary domain name; if the owner information of each primary domain name matches the account information of the operation and maintenance personnel, it is determined that the new SSL certificate verification is successful; if the owner information of any primary domain name does not match the account information, it is determined that the new SSL certificate verification has failed.
[0243] Exemplarily, when the network application server supports the first primary domain name, the first primary domain name is added to the domain name list, and the certificate type of the first primary domain name is a wildcard primary domain name type, thereby generating a new SSL certificate for the first primary domain name. When the primary domain name supported by the network application server is switched from the first primary domain name to the second primary domain name, a domain name set is added to the domain name list, the domain name set includes the first primary domain name and the second primary domain name, and the certificate type of the domain name set is a wildcard multi-primary domain name type, thereby generating a new SSL certificate for the domain name set. When the configured domain name switching condition is met, the second primary domain name is added to the domain name list, and the certificate type of the second primary domain name is a wildcard primary domain name type, thereby generating a new SSL certificate for the second primary domain name.
[0244] Based on the same application concept as the above method, an SSL certificate management system is proposed in an embodiment of the present application, wherein the SSL certificate management system includes a network application server and a certificate management server, wherein:
[0245] The network application server is used to send a first certificate request to the certificate management server when the system is started, wherein the first certificate request includes a device identifier of the network application server;
[0246] The certificate management server is configured to obtain a first SSL certificate corresponding to the device identifier, and send a first certificate response to the network application server, wherein the first certificate response includes the first SSL certificate;
[0247] The network application server is configured to receive the first certificate response, and store the first SSL certificate in the first certificate response as a target SSL certificate;
[0248] The network application server is used to periodically send a second certificate request to the certificate management server after the system is started, wherein the second certificate request includes the device identification;
[0249] The certificate management server is used to obtain a second SSL certificate corresponding to the device identifier, and send a second certificate response to the network application server, where the second certificate response includes the second SSL certificate;
[0250] The network application server is configured to receive the second certificate response, and if the version of the second SSL certificate in the second certificate response is newer than the version of the first SSL certificate, update the second SSL certificate in the second certificate response to a target SSL certificate;
[0251] The network application server is used to communicate with the client based on the target SSL certificate.
[0252] Based on the same application concept as the above method, an electronic device (such as the network application server or certificate management server in the above embodiment) is proposed in the embodiment of the present application, see Figure 8 As shown, the electronic device may include: a processor 81 and a machine-readable storage medium 82, wherein the machine-readable storage medium 82 stores machine-executable instructions that can be executed by the processor 81; the processor 81 is used to execute the machine-executable instructions to implement the SSL certificate management method disclosed in the above example of this application.
[0253] Based on the same application concept as the above method, an embodiment of the present application also provides a machine-readable storage medium, on which a number of computer instructions are stored. When the computer instructions are executed by a processor, the SSL certificate management method disclosed in the above example of the present application can be implemented.
[0254] The above-mentioned machine-readable storage medium may be any electronic, magnetic, optical or other physical storage device, which may contain or store information, such as executable instructions, data, etc. For example, the machine-readable storage medium may be: RAM (Radom Access Memory), volatile memory, non-volatile memory, flash memory, storage drive (such as hard disk drive), solid state drive, any type of storage disk (such as CD, DVD, etc.), or similar storage medium, or a combination thereof.
[0255] Based on the same application concept as the above method, an embodiment of the present application also provides a computer program product, which may include a computer program. When the computer program is executed by a processor, it implements the SSL certificate management method disclosed in the above example of the present application.
[0256] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the embodiments of the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0257] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.
Claims
1. A secure socket layer (SSL) certificate management method, characterized in that: The method comprises: When the system is started, the network application server sends a first certificate request to the certificate management server, wherein the first certificate request includes the device identification of the network application server, so that the certificate management server obtains a first SSL certificate corresponding to the device identification; the network application server receives a first certificate response, and stores the first SSL certificate in the first certificate response as a target SSL certificate; After the system is started, the network application server periodically sends a second certificate request to the certificate management server, wherein the second certificate request includes the device identifier, so that the certificate management server obtains a second SSL certificate corresponding to the device identifier; the network application server receives a second certificate response, and if the version of the second SSL certificate is newer than that of the first SSL certificate, updates the second SSL certificate in the second certificate response to the target SSL certificate; The web application server communicates with the client based on the target SSL certificate.
2. The method according to claim 1, characterized in that The method further comprises: After receiving the second certificate request, the certificate management server compares whether the certificate identifier of the second SSL certificate is the same as the certificate identifier of the first SSL certificate if the second certificate request also includes the certificate identifier of the first SSL certificate; if not, determines that the version of the second SSL certificate is newer than the version of the first SSL certificate, and sends a second certificate response to the network application server; After receiving the second certificate response, the network application server determines that the version of the second SSL certificate is newer than the version of the first SSL certificate; or, After receiving the second certificate request, the certificate management server sends a second certificate response to the network application server, where the second certificate response includes a certificate identifier of the second SSL certificate; After receiving the second certificate response, the network application server compares whether the certificate identifier of the second SSL certificate is the same as the certificate identifier of the first SSL certificate. If not, it determines that the version of the second SSL certificate is newer than that of the first SSL certificate.
3. The method according to claim 1 or 2, characterized in that: The method further comprises: The certificate management server periodically scans a configured domain name list, wherein the domain name list includes a mapping relationship between domain names, certificate types, and statuses supported by the network application server; If the domain name list includes a target domain name, the target domain name does not correspond to an SSL certificate or the interval between the expiration time of the SSL certificate corresponding to the target domain name and the current time is less than a preset threshold, and the status of the target domain name is an online status, and the online status indicates that the SSL certificate needs to be maintained, then the certificate management server generates a new SSL certificate for the target domain name, and verifies the new SSL certificate based on the certificate type corresponding to the target domain name; if the verification is successful, the certificate management server saves the correspondence between the certificate name corresponding to the target domain name and the new SSL certificate; The certificate management server stores the correspondence between the device identification of the network application server and the certificate name corresponding to the target domain name.
4. The method according to claim 3, characterized in that: The certificate management server verifies the new SSL certificate based on the certificate type corresponding to the target domain name, including: If the certificate type is a subdomain type and the target domain name is a subdomain, the certificate management server sends a query message carrying the primary domain name to which the subdomain belongs to the DNS server, so that the DNS server returns the owner information of the primary domain name to which the subdomain belongs; if the owner information matches the account information of the operation and maintenance personnel used to configure the domain name list, it is determined that the new SSL certificate verification is successful; if the owner information does not match the account information, it is determined that the new SSL certificate verification fails; or, If the certificate type is a wildcard primary domain name type and the target domain name is a primary domain name, the certificate management server sends a query message carrying the primary domain name to the DNS server, so that the DNS server returns the owner information of the primary domain name; if the owner information matches the account information of the operation and maintenance personnel, it is determined that the new SSL certificate verification is successful; if the owner information does not match the account information, it is determined that the new SSL certificate verification fails; or, If the certificate type is a wildcard multi-primary domain name type, the target domain name includes multiple primary domain names. For each primary domain name, the certificate management server sends a query message carrying the primary domain name to the DNS server, so that the DNS server returns the owner information of the primary domain name; if the owner information of each primary domain name matches the account information of the operation and maintenance personnel, it is determined that the new SSL certificate verification is successful; if the owner information of any primary domain name does not match the account information, it is determined that the new SSL certificate verification has failed.
5. The method according to claim 3, characterized in that: When the network application server supports the first primary domain name, the certificate management server adds the first primary domain name to the domain name list, and the certificate type of the first primary domain name is a wildcard primary domain name type; wherein the certificate management server generates a new SSL certificate for the first primary domain name; When the primary domain name supported by the network application server switches from the first primary domain name to the second primary domain name, the certificate management server adds a domain name set to the domain name list, the domain name set includes the first primary domain name and the second primary domain name, and the certificate type of the domain name set is a wildcard multi-primary domain name type; wherein the certificate management server generates a new SSL certificate for the domain name set; When the configured domain name switching conditions are met, the certificate management server adds the second primary domain name to the domain name list, and the certificate type of the second primary domain name is a wildcard primary domain name type; wherein the certificate management server generates a new SSL certificate for the second primary domain name.
6. A method for managing SSL certificates, characterized in that: Applicable to network application servers, including: When the system starts, a first certificate request is sent to a certificate management server, wherein the first certificate request includes the device identification of the network application server; a first certificate response returned by the certificate management server is received, wherein the first certificate response includes a first SSL certificate corresponding to the device identification obtained by the certificate management server; and the first SSL certificate in the first certificate response is stored as a target SSL certificate; After the system is started, periodically sending a second certificate request to the certificate management server, wherein the second certificate request includes the device identification; receiving a second certificate response returned by the certificate management server, wherein the second certificate response includes a second SSL certificate corresponding to the device identification obtained by the certificate management server; if the version of the second SSL certificate is newer than that of the first SSL certificate, updating the second SSL certificate in the second certificate response to the target SSL certificate; Communicate with the client based on the target SSL certificate.
7. A method for managing SSL certificates, characterized in that: Applicable to certificate management servers, including: Receiving a first certificate request sent by a network application server, the first certificate request including a device identifier of the network application server, the first certificate request being sent when the system is started; Obtaining a first SSL certificate corresponding to the device identifier; sending a first certificate response to the network application server, wherein the first certificate response includes the first SSL certificate, so that the network application server stores the first SSL certificate in the first certificate response as a target SSL certificate; receiving a second certificate request sent by the network application server, wherein the second certificate request includes the device identification, and the second certificate request is sent periodically after the system is started; Obtain a second SSL certificate corresponding to the device identifier; send a second certificate response to the network application server, wherein the second certificate response includes the second SSL certificate, so that the network application server updates the second SSL certificate in the second certificate response to a target SSL certificate when the version of the second SSL certificate is newer than that of the first SSL certificate.
8. An SSL certificate management device, characterized in that: Applicable to network application servers, including: A sending module, configured to send a first certificate request to a certificate management server when the network application server system is started, wherein the first certificate request includes a device identifier of the network application server; A receiving module, configured to receive a first certificate response returned by the certificate management server, wherein the first certificate response includes a first SSL certificate corresponding to the device identifier obtained by the certificate management server; A processing module, configured to store the first SSL certificate in the first certificate response as a target SSL certificate; A sending module, configured to periodically send a second certificate request to the certificate management server after the network application server system is started, wherein the second certificate request includes the device identification; A receiving module, configured to receive a second certificate response returned by the certificate management server, wherein the second certificate response includes a second SSL certificate corresponding to the device identifier obtained by the certificate management server; a processing module, configured to update the second SSL certificate in the second certificate response to a target SSL certificate if the version of the second SSL certificate is newer than the version of the first SSL certificate; A communication module is used to communicate with the client based on the target SSL certificate.
9. An SSL certificate management device, characterized in that: Applicable to certificate management servers, including: A receiving module, configured to receive a first certificate request sent by a network application server, wherein the first certificate request includes a device identifier of the network application server, and the first certificate request is sent when the system is started; An acquisition module, used to acquire a first SSL certificate corresponding to the device identifier; A sending module, configured to send a first certificate response to the network application server, wherein the first certificate response includes the first SSL certificate, so that the network application server stores the first SSL certificate in the first certificate response as a target SSL certificate; A receiving module, configured to receive a second certificate request sent by the network application server, wherein the second certificate request includes the device identification, and the second certificate request is sent periodically after the system is started; An acquisition module, used to acquire a second SSL certificate corresponding to the device identifier; The sending module is used to send a second certificate response to the network application server, the second certificate response including a second SSL certificate, so that the network application server updates the second SSL certificate in the second certificate response to a target SSL certificate when the version of the second SSL certificate is newer than that of the first SSL certificate.
10. An electronic device, characterized in that: include: a processor and a machine-readable storage medium storing machine-executable instructions executable by the processor; The processor is used to execute machine executable instructions to implement the method of claim 6 or 7.
11. A secure socket layer (SSL) certificate management system, characterized in that: The SSL certificate management system includes a network application server and a certificate management server, wherein: The network application server is used to send a first certificate request to the certificate management server when the system is started, wherein the first certificate request includes a device identifier of the network application server; The certificate management server is configured to obtain a first SSL certificate corresponding to the device identifier, and send a first certificate response to the network application server, wherein the first certificate response includes the first SSL certificate; The network application server is configured to receive the first certificate response, and store the first SSL certificate in the first certificate response as a target SSL certificate; The network application server is used to periodically send a second certificate request to the certificate management server after the system is started, wherein the second certificate request includes the device identification; The certificate management server is used to obtain a second SSL certificate corresponding to the device identifier, and send a second certificate response to the network application server, where the second certificate response includes the second SSL certificate; The network application server is configured to receive the second certificate response, and if the version of the second SSL certificate in the second certificate response is newer than the version of the first SSL certificate, update the second SSL certificate in the second certificate response to a target SSL certificate; The network application server is used to communicate with the client based on the target SSL certificate.