Information processing apparatus and method for controlling information processing apparatus
The information processing device simplifies digital certificate issuance by allowing users to specify the protocol for each use, automating the process and improving usability through integrated settings and user instructions, addressing the complexity of multiple methods.
Patent Information
- Application Number
- JP2024097503
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-17
- Publication Date
- 2026-01-05
AI Technical Summary
In environments where multiple certificate issuance request methods (e.g., SCEP, EST, ACME) are available, users face reduced usability due to the need to manually check and set the purpose for each method when requesting digital certificates for uses like SSL, TLS, IEEE802.1X, and IPSec.
An information processing device with a setting means to specify the protocol for each certificate use, a receiving means to link user instructions to the appropriate protocol, and an issuance request means to communicate with the issuing server, improving usability by automating the certificate issuance process based on user input.
Enhances usability by allowing users to efficiently request digital certificates tailored to their intended use, reducing the complexity and effort required in selecting and configuring certificate issuance methods.
Smart Images

Figure 2026000262000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing apparatus and a control method for the information processing apparatus. [Background technology]
[0002] To maintain a safe and secure office environment while using information processing devices on a network, it is necessary to authenticate communications using digital certificates (hereinafter also referred to as "certificates"). Generally, secure network communications are identified and authenticated using public key infrastructure (PKI) technology that uses certificates. Specifically, for example, a client can verify the legitimacy of a server by obtaining a certificate from the server and the CA certificate of the certification authority that issued the certificate. In this way, certificates have long been used as an important technology for identifying and authenticating network communications between information processing devices. Certificates are used in protocols such as SSL, TLS, IEEE802.1X, and IPSec, for example.
[0003] Incidentally, as a technique related to the background art described above, Patent Document 1 describes an information processing device that adds and updates a certificate. Furthermore, Patent Document 1 mainly lists SCEP (Simple Certificate Enrollment Protocol) as a protocol (hereinafter referred to as a "certificate issuance request method") that the information processing device uses to request the issuance of a certificate from a certification authority. In addition to SCEP, other certificate issuance request methods include EST (Enrollment over Secure Transport) and ACME (Automatic Certificate Management Environment). By using these certificate issuance request methods, the information processing device can request the issuance of a certificate without requiring user operation. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent No. 7381794 Summary of the Invention [Problem to be solved by the invention]
[0005] However, in an environment where multiple certificate issuance request methods (e.g., the above-mentioned SCEP, EST, ACME, etc.) are available, a certificate may be used for multiple purposes (e.g., the above-mentioned SSL, TLS, IEEE802.1X, IPSec, etc.). In this case, the user must check the setting screen for each certificate issuance request method to determine for which purpose the information processing device is to make a certificate issuance request. This has resulted in a problem of reduced user operability when making the information processing device make a certificate issuance request according to the certificate's purpose.
[0006] The present invention has been made in view of the above-mentioned problems, and aims to provide an information processing device and a control method for the information processing device that can improve usability when requesting the issuance of a digital certificate that is suited to the intended use of the digital certificate. [Means for solving the problem]
[0007] In order to achieve the above-mentioned object, the information processing device of the present invention is characterized by comprising: a setting means for setting the protocol to be used in a request for issuance of an electronic certificate for each use of the electronic certificate in accordance with input by a user; a receiving means for accepting an instruction for a request for issuance of an electronic certificate in accordance with input by a user and linking it to the use of the electronic certificate; and an issuance request means for making a request for issuance of an electronic certificate to an issuing server using the protocol set for the use of the electronic certificate linked to the instruction. [Effects of the Invention]
[0008] According to the present invention, it is possible to improve usability when requesting the issuance of a digital certificate suited to the intended use of the digital certificate. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 is a block diagram showing a configuration of an information processing system. [Figure 2] FIG. 2 is a block diagram showing the hardware configuration of the multifunction peripheral. [Figure 3] FIG. 2 is a block diagram showing software modules included in the multifunction peripheral. [Figure 4] FIG. 1 is a block diagram showing the hardware configuration of a PC (personal computer). [Figure 5] FIG. 2 is a block diagram showing software modules included in a PC. [Figure 6] 10 is a flowchart showing the flow of a certificate issuance request in a multifunction peripheral. [Figure 7] FIG. 10 is a diagram showing an example of a certificate issuance request screen (hereinafter referred to as a "certificate issuance request screen"). [Figure 8] FIG. 10 is a diagram illustrating an example of a connection setting screen. [Figure 9] FIG. 10 is a diagram illustrating an example of an issuance request method setting screen. [Figure 10A] FIG. 10 is a diagram illustrating an example of a CSR (Certificate Signing Request) setting screen for TLS. [Figure 10B] FIG. 10 is a diagram showing an example of a CSR setting screen for IEEE802.1X. [Figure 10C] FIG. 10 is a diagram illustrating an example of a CSR setting screen for IPSec. [Figure 11] FIG. 10 is a diagram illustrating an example of a warning screen. [Figure 12] 10 is a flowchart showing the flow of a certificate issuance request process. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. However, the configurations described in the following embodiments are merely examples, and the scope of the present invention is not limited to the configurations described in the embodiments. For example, each component constituting the present invention can be replaced with any configuration that can perform the same function. Any component may also be added. Any two or more configurations (features) of the present embodiments can be combined. Furthermore, not all combinations of features described in the present embodiments are necessarily essential to the solution of the present invention. In the present embodiments, a multifunction peripheral (MFP: Multi Function Peripheral) that uses and manages certificates will be described as an example of an information processing device of the present invention.
[0011] Fig. 1 is a block diagram showing the configuration of an information processing system 100. As shown in Fig. 1, in the information processing system 100, a multifunction peripheral 101, a certification authority / registration authority 102, and a PC 103 are connected to a network 104. The multifunction peripheral 101 is capable of transmitting and receiving print data, scanned image data, and the like to and from other information processing devices via the network 104. The multifunction peripheral 101 has a function for performing encrypted communications such as TLS, IEEE802.1X, and IPSEC, and holds a public key pair and a certificate used in these encrypted communications.
[0012] The multifunction peripheral 101 has a web server function and exposes a web-page type remote UI function on the network 104 that can execute processes for requesting, obtaining, and updating a certificate. As described above, the multifunction peripheral 101 is an example of the information processing device of the present invention. However, the information processing device of the present invention is not limited to the multifunction peripheral 101, and may be, for example, a facsimile machine, a printer, a copier, a scanner, a PC, a tablet terminal, a smartphone, etc.
[0013] The certification authority / registration authority 102 has the functions of a certification authority (CA) that issues certificates and a registration authority (RA) that accepts certificate issuance requests and registers certificates. In other words, the certification authority / registration authority 102 (issuing server) is a server that has the functions of issuing and registering certificates and distributing CA certificates via the network 104. The multifunction peripheral 101 uses a certificate issuance request method to communicate with the certification authority / registration authority 102 via the network 104 to request the issuance of a certificate or to obtain a certificate.
[0014] When the certification authority / registration authority 102 receives a certificate issuance request from the multifunction peripheral 101 via the network 104, it issues and registers a certificate based on the certificate issuance request, and returns the issued certificate as a response to the certificate issuance request. In this embodiment, the functions of the certification authority and registration authority are realized by the same server (i.e., the certification authority / registration authority 102), but this is not particularly limited. In other words, the certification authority and registration authority may be realized by separate servers. In this embodiment, SCEP, EST, and ACME are listed as certificate issuance request methods, but they may also be realized by separate servers (i.e., separate certification authorities / registration authorities), and this is not particularly limited.
[0015] The PC 103 is a personal computer equipped with a web browser function. Using the web browser function, the PC 103 can view and use HTML documents and websites published by information processing devices connected to the network 104. Therefore, a user of the PC 103 can configure the multifunction peripheral 101 by accessing the remote UI of the multifunction peripheral 101 using the web browser function.
[0016] FIG. 2 is a block diagram showing the hardware configuration of the multifunction peripheral 101. The CPU 201 executes the software program of the multifunction peripheral 101 and controls the entire device. The ROM 202 is a read-only memory. The ROM 202 stores the boot program and fixed parameters of the multifunction peripheral 101. The RAM 203 is a random access memory that is used to store programs and temporary data when the CPU 201 controls the multifunction peripheral 101. The HDD 204 is a hard disk drive. The HDD 204 stores system software, applications, and various data. The CPU 201 executes the boot program stored in the ROM 202, loads the program stored in the HDD 204 into the RAM 203, and controls the operation of the multifunction peripheral 101 by executing the loaded program.
[0017] A network I / F control unit 205 controls transmission and reception of data to and from the network 104. A scanner I / F control unit 206 controls document reading processing and the like by a scanner 207. A printer I / F control unit 208 controls printing processing and the like by a printer 209. A panel control unit 210 controls a touch panel type operation panel 211, and controls the display of various information and the input of instructions from the user. A bus 212 interconnects the CPU 201, ROM 202, RAM 203, HDD 204, network I / F control unit 205, scanner I / F control unit 206, printer I / F control unit 208, and panel control unit 210. Control signals from the CPU 201 and data signals between each device are transmitted and received via the bus 212.
[0018] Fig. 3 is a block diagram showing the software modules of the multifunction peripheral 101. The software modules shown in Fig. 3 are implemented by the CPU 201 loading a program stored in the HDD 204 into the RAM 203 and executing it. A network driver 301 controls the network I / F control unit 205 to send and receive data to and from the outside via the network 104. A network control unit 302 controls communication below the transport layer in a network communication protocol such as TCP / IP to send and receive data.
[0019] The communication control unit 303 is a module for controlling communication of multiple protocols supported by the multifunction peripheral 101. The communication control unit 303 executes communication with the certification authority / registration authority 102 and the PC 103 by generating and analyzing request and response data for HTTP and SOAP protocol communication and controlling data transmission and reception during each process of requesting, obtaining, and updating a certificate. Note that the communication control unit 303 also executes encrypted communication using TLS, IEEE802.1X, and IPSEC supported by the multifunction peripheral 101.
[0020] Web page control unit 304 is a module that generates HTML data for displaying a Web page and controls communication, enabling multifunction peripheral 101 to execute processes for requesting, obtaining, and updating a certificate. Web page control unit 304 executes processes for Web page display requests, certificate issuance requests, and instructions for obtaining and updating a certificate, sent from network driver 301 via network control unit 302 and communication control unit 303. Web page control unit 304 returns HTML data of a default Web page stored in RAM 203 or HDD 204, or HTML data generated in accordance with the contents of the display request, as a response to a request from a Web browser (504 in FIG. 5, described below).
[0021] The key pair and certificate acquisition control unit 305 is a module for executing processes such as certificate acquisition based on instructions from the web page control unit 304. The certificate acquisition process involves saving setting values, controlling communication for the certificate issuance request method, and generating and analyzing encrypted data required for communication such as PKCS#7 and PKCS#10. The setting values for the certificate acquisition process are saved in certificate acquisition information 306. The certificate acquisition information 306 is a database that saves data used by the key pair and certificate acquisition control unit 305 for processing. The information in the certificate acquisition information 306 is saved in the HDD 204. The certificate acquisition information 306 saves values set on each setting screen, which will be described later.
[0022] The key and certificate information 307 is a database that stores public key pairs, certificates, and CA certificates used by the multifunction peripheral 101. CA certificates may be stored in the key and certificate information 307 from the beginning as trusted information, or public key pairs, certificates, and CA certificates may be added and stored later by the user of the multifunction peripheral 101. The encryption processing unit 308 is a module that executes various cryptographic processes such as data encryption and decryption, hash value generation, and digital signature generation and verification. The encryption processing unit 308 executes each cryptographic process required in the generation and analysis of request and response data in the certificate acquisition process.
[0023] The key pair and certificate management unit 309 is a module for executing processes such as certificate update based on instructions from the web page control unit 304. Certificate update processes involve storing acquired certificates in association with their intended use and public key pairs. In other words, the key pair and certificate management unit 309 is a module for managing public key pairs, certificates, and CA certificates held by the multifunction peripheral 101. The key pair and certificate management unit 309 stores data on the public key pairs, certificates, and CA certificates along with various setting values in key and certificate information 307. The information in the key and certificate information 307 is stored in the RAM 203 or HDD 204. In encrypted communications such as TLS, IEEE802.1X, and IPSEC executed by the communication control unit 303, the key pair and certificate management unit 309 acquires data on the public key pairs and certificates to be used from the key and certificate information 307, and the encryption processing unit 308 performs encryption processing.
[0024] The UI control unit 310 controls the panel control unit 210 and the operation panel 211. Although not shown, processes such as displaying details, creating, and deleting public key pairs, certificates, and CA certificates can also be executed in response to user instructions via the operation panel 211. The print / read processing unit 311 is a module for executing functions such as printing by the printer 209 and reading an original by the scanner 207. The device control unit 312 is a module for generating control commands and control data for the multifunction peripheral 101 and for overall control of the multifunction peripheral 101.
[0025] FIG. 4 is a block diagram showing the hardware configuration of PC 103. CPU 401 executes software programs for PC 103 and controls the entire device. ROM 402 is read-only memory. ROM 402 stores a boot program, fixed parameters, and the like for PC 103. RAM 403 is random access memory, and is used to store programs and temporary data when CPU 401 controls PC 103. HDD 404 is a hard disk drive. System software, applications, and various data are stored in HDD 404. CPU 401 executes a boot program stored in ROM 402, loads a program stored in HDD 404 into RAM 403, and controls the operation of PC 103 by executing the loaded program.
[0026] A network I / F control unit 405 controls transmission and reception of data to and from the network 104. An input control unit 406 controls input processing via operations on a keyboard 407 and a mouse 408. A display control unit 409 controls a display 410 to control the display of various information. A bus 411 interconnects the CPU 401, ROM 402, RAM 403, HDD 404, network I / F control unit 405, input control unit 406, and display control unit 409. Control signals from the CPU 401 and data signals between the devices are transmitted and received via the bus 411.
[0027] Fig. 5 is a block diagram showing software modules included in PC 103. The software modules shown in Fig. 5 are implemented by CPU 401 loading a program stored in HDD 404 into RAM 403 and executing it. Network driver 501 controls network I / F control unit 405 to send and receive data to and from the outside via network 104. Network control unit 502 controls communication below the transport layer in a network communication protocol such as TCP / IP to send and receive data.
[0028] The communication control unit 503 is a module for controlling communication of multiple protocols supported by the PC 103. The communication control unit 503 accesses the remote UI of the multifunction peripheral 101 and performs settings for each process of certificate acquisition and renewal by generating and analyzing request and response data for HTTP and SOAP protocol communication and controlling data transmission and reception. The web browser 504 is a web browser application that displays and operates web pages published by the multifunction peripheral 101. The display control unit 505 controls the display control unit 409 and controls the screen that the web browser 504 displays on the display 410. The UI control unit 506 controls the input control unit 406 and controls input from the keyboard 407 and mouse 408 for performing various operations on the web browser 504.
[0029] Fig. 6 is a flowchart showing the flow of a certificate issuance request in the multifunction peripheral 101 (a method of controlling an information processing device). The flowchart in Fig. 6 is implemented by the CPU 201 loading a program stored in the HDD 204 into the RAM 203 and executing it. This also applies to the flowchart in Fig. 12, which will be described later. When the flowchart in Fig. 6 starts, in step S600, the CPU 201 determines, via the communication control unit 303, whether or not a request to display a certificate issuance request screen has been received from the PC 103. The request to display the certificate issuance request screen from the PC 103 is made by a user of the remote UI (hereinafter referred to as "RUI") using the keyboard 407 or mouse 408.
[0030] If CPU 201 determines via communication control unit 303 that a request to display the certificate issuance request screen has been received from PC 103, the process proceeds to step S601. On the other hand, if CPU 201 determines via communication control unit 303 that a request to display the certificate issuance request screen has not been received from PC 103, the process returns to step S600. As a result, CPU 201 repeatedly performs the determination of step S600 via communication control unit 303 until a request to display the certificate issuance request screen is received from PC 103.
[0031] In step S601, the CPU 201 generates a certificate issuance request screen using the key pair / certificate acquisition control unit 305, and further displays the certificate issuance request screen on the RUI using the web page control unit 304. In this embodiment, the administrator of the multifunction peripheral 101 uses the web browser 504 installed on the PC 103 to connect to the RUI published by the multifunction peripheral 101 and perform input operations such as instructions for requesting, obtaining, and updating a certificate. Therefore, in this embodiment, the user of the RUI is the administrator of the multifunction peripheral 101, but this is not limited to this and may be, for example, a general user who has administrative authority over certificates in the multifunction peripheral 101. Note that the CPU 201 functions as a setting unit, a receiving unit, an issuance request unit, and the like of the information processing device by requesting, obtaining, and updating a certificate in accordance with the user's input operations on the RUI, as will be described later.
[0032] An example of the certificate issuance request screen will now be described with reference to FIG. 7. FIG. 7 is a diagram showing an example of an RUI screen that the multifunction peripheral 101 has made public on the network. The screen of FIG. 7 is a web page screen, the HTML data of which is generated by the web page control unit 304 of the multifunction peripheral 101 and displayed on the display 410 of the PC 103 by the web browser 504 of the PC 103. By displaying the screen of FIG. 7 and inputting and changing setting values from the screen of FIG. 7 on the PC 103, settings related to a certificate issuance request for the multifunction peripheral 101 can be executed from the PC 103. In other words, the screen of FIG. 7 is a UI screen that is displayed on the display 410 of the PC 103 by the web browser 504 of the PC 103, and is a certificate issuance request screen for the multifunction peripheral 101 to make a certificate issuance request to the certification authority / registration authority 102.
[0033] The certificate issuance request screen in FIG. 7 has connection settings 701, issuance request method settings 702, CSR settings 703, and immediate issuance execution 704. Connection settings 701 is a link that, when pressed, transitions the certificate issuance request screen in FIG. 7 to a connection settings screen. The connection settings screen will be described later using FIG. 8. Issuance request method settings 702 is a link that, when pressed, transitions the certificate issuance request screen in FIG. 7 to an issuance request method settings screen. The issuance request method settings screen will be described later using FIG. 9. CSR settings 703 has links, one for each certificate use, that, when pressed, transitions the certificate issuance request screen in FIG. 7 to a CSR settings screen. Pressing any link in CSR settings 703 transitions to a CSR settings screen for the certificate use associated with the pressed link. The CSR settings screen will be described later using FIGS. 10A to 10C.
[0034] The immediate issuance execution 704 has an execution button (acceptance button) for immediately executing a certificate issuance request, for each certificate use. In the immediate issuance execution 704, one execution button is associated with one certificate use. In the immediate issuance execution 704, in addition to TLS, IEEE802.1X, and IPSec, no use is also considered one of the certificate uses. When any of the execution buttons in the immediate issuance execution 704 is pressed, a certificate issuance request corresponding to the certificate use associated with the pressed execution button is immediately executed. Therefore, a user of the RUI issues a certificate issuance request by pressing any of the execution buttons in the immediate issuance execution 704. As a result, in step S601, when the execution button in the immediate issuance execution 704 is pressed, the CPU 201 causes the key pair / certificate acquisition control unit 305 to accept the certificate issuance request instruction in association with the certificate use associated with the pressed execution button (acceptance process).
[0035] The connection setting screen, issuance request method setting screen, and CSR setting screen, which can be transitioned to from the certificate issuance request screen in Fig. 7 as described above, are also RUI screens that the multifunction peripheral 101 has made public on the network. In other words, these screens are also web page screens, and the HTML data thereof is generated by the web page control unit 304 of the multifunction peripheral 101 and displayed on the display 410 of the PC 103 by the web browser 504 of the PC 103. This also applies to the screen in Fig. 11, which will be described later.
[0036] The screen in FIG. 8 is a UI screen displayed on the display 410 of the PC 103 by the web browser 504 of the PC 103. It is an example of a connection setting screen that allows the user of the RUI to set items necessary for the multifunction peripheral 101 to connect to the certification authority / registration authority 102. In the following description, the settings necessary for the multifunction peripheral 101 to connect to the certification authority / registration authority 102 are referred to as "server settings." The connection setting screen in FIG. 8 has input fields for server names 801, 802, and 803, port numbers 804, 805, and 806, and a SCEP challenge password 807, as well as an OK button 808 for completing the setting of the values entered in each input field. The host names and destination port numbers of the servers on which the certificate issuance service provided by the certification authority / registration authority 102 operates are entered in the input fields for the server names 801, 802, and 803 and the port numbers 804, 805, and 806. The multifunction device 101 connects to the certification authority / registration authority 102 based on the information set and saved via the connection setting screen of FIG.
[0037] The screen in Fig. 9 is a UI screen that the web browser 504 of the PC 103 displays on the display 410 of the PC 103, and is an example of an issuance request method setting screen that allows the user of the RUI to set a certificate issuance request method for each certificate purpose. The issuance request method setting screen in Fig. 9 has multiple pull-down menus 901 to 904 that allow the user of the RUI to select a certificate issuance request method for each certificate purpose, and an OK button 905 for completing the setting of the value selected in each pull-down menu 901 to 904. In the issuance request method setting screen in Fig. 9, in addition to TLS, IEEE802.1X, and IPSec, no purpose is also one of the certificate purposes.
[0038] Pull-down menus 901, 904 for certificate usage TLS and no usage have ACME, EST, SCEP, and unselected as options for the certificate issuance request method. On the other hand, because ACME does not support protocols other than TLS, pull-down menus 902, 903 for certificate usage IEEE802.1X and IPSec have EST, SCEP, and unselected as options for the certificate issuance request method. In step S601, when OK button 905 is pressed, CPU 201 causes key pair / certificate acquisition control unit 305 to set the certificate issuance request method for each certificate usage in accordance with the user's selection of the RUI in each of pull-down menus 901 to 904 (setting process).
[0039] Each of the screens in Figures 10A to 10C is a UI screen (CSR setting UI screen) that the web browser 504 of the PC 103 displays on the display 410 of the PC 103, and is an example of a CSR setting screen on which the user of the RUI sets a CSR for each certificate purpose. The multifunction peripheral 101 generates a public key pair and a CSR based on the values set on each CSR setting screen in Figures 10A to 10C, and uses the generated CSR, etc. to request the certification authority / registration authority 102 to issue a certificate. The CSR setting screen in Figure 10A is a CSR setting screen for TLS, and includes key / CSR information 1001 and an OK button 1002. The key / CSR information 1001 includes input fields and radio buttons that allow the user of the RUI to input and select each setting information included in the certificate issuance request.
[0040] The setting information items include [Name], which sets the name of the public key pair used by the multifunction peripheral 101 to manage the public key pair, [Key Length], which sets the key length of the public key pair generated by the multifunction peripheral 101, and [Input Issuer Information], which sets the issuer information. The OK button 1002 is a button for completing the setting of the values entered and selected on the CSR setting screen of FIG. 10A. The screen of FIG. 10B is a CSR setting screen for IEEE802.1X. The screen of FIG. 10C is a CSR setting screen for IPSec. The screens of FIG. 10B and FIG. 10C have the same configuration as the screen of FIG. 10A. Therefore, a description of the screens of FIG. 10B and FIG. 10C will be omitted. In step S601, when the OK button 1002 is pressed, the CPU 201 (CSR setting means) causes the key pair / certificate acquisition control unit 305 to set the CSR setting for each certificate purpose in accordance with the user's input and selection of the RUI in the key / CSR information 1001. This allows the RUI user to change each setting information included in the certificate issuance request depending on the purpose of the certificate.
[0041] Returning to the description of Figure 6, in step S602, CPU 201 determines, via Web page control unit 304, whether the user of the RUI has instructed a certificate issuance request. Web page control unit 304 determines that the user of the RUI has instructed a certificate issuance request if any of the execution buttons in immediate issuance execution 704 on the certificate issuance request screen in Figure 7 has been pressed. If CPU 201 determines, via Web page control unit 304, that the user of the RUI has instructed a certificate issuance request, the process proceeds to step S603.
[0042] At this time, CPU 201 notifies key pair / certificate acquisition control unit 305 via web page control unit 304 that the user of the RUI has requested the issuance of a certificate. This notification triggers the execution of the process in step S603. On the other hand, if CPU 201 determines via web page control unit 304 that the user of the RUI has not requested the issuance of a certificate, the process returns to step S602. As a result, CPU 201 causes web page control unit 304 to repeatedly perform the determination in step S602 until the user of the RUI requests the issuance of a certificate.
[0043] In step S603, the CPU 201 causes the key pair / certificate acquisition control unit 305 to acquire, from the certificate acquisition information 306, the certificate issuance request method for the certificate usage associated with the certificate issuance request instructed by the user of the RUI. That is, the key pair / certificate acquisition control unit 305 acquires, from the certificate acquisition information 306, the certificate issuance request method indicated by the value set in the issuance request method setting screen of Fig. 9 for the certificate usage associated with the execute button pressed on the certificate issuance request screen of Fig. 7. For example, when the execute TLS button is pressed on the certificate issuance request screen of Fig. 7, the key pair / certificate acquisition control unit 305 acquires, from the certificate acquisition information 306, the EST indicated by the value set for TLS on the issuance request method setting screen of Fig. 9.
[0044] In step S604, the CPU 201 determines whether or not server settings for the certificate signing request method acquired in step S603 have been made by the key pair / certificate acquisition control unit 305. That is, the key pair / certificate acquisition control unit 305 determines whether or not server settings for the certificate signing request method acquired in step S603 have been made on the connection setting screen in Fig. 8. At this time, the key pair / certificate acquisition control unit 305 makes the determination in step S604 using setting values stored in the certificate acquisition information 306.
[0045] For example, if the certificate signing request method acquired in step S603 is EST, the key pair / certificate acquisition control unit 305 determines whether the setting values for the server name 802 and port number 805 for EST on the connection setting screen in Figure 8 are saved in the certificate acquisition information 306. If the CPU 201 determines that the key pair / certificate acquisition control unit 305 has made server settings for the certificate signing request method acquired in step S603, the process proceeds to step S605. On the other hand, if the CPU 201 determines that the key pair / certificate acquisition control unit 305 has not made server settings for the certificate signing request method acquired in step S603, the process proceeds to step S607, which will be described later.
[0046] In step S605, CPU 201 determines whether key pair / certificate acquisition control unit 305 has configured a CSR for the certificate usage in accordance with the certificate issuance request instructed by the user of the RUI. In other words, key pair / certificate acquisition control unit 305 determines whether a CSR has been configured on a CSR setting screen that targets the certificate usage in accordance with the certificate issuance request instructed by the user of the RUI. At this time, key pair / certificate acquisition control unit 305 makes the determination in step S605 using the setting values stored in certificate acquisition information 306.
[0047] For example, when the TLS execution button is pressed on the certificate issuance request screen of Fig. 7, the key pair and certificate acquisition control unit 305 determines whether the settings of the key and CSR information 1001 on the CSR setting screen for TLS of Fig. 10A are saved in the certificate acquisition information 306. If the CPU 201 determines that the key pair and certificate acquisition control unit 305 has set the CSR for the certificate use corresponding to the certificate issuance request instructed by the user of the RUI, the process proceeds to step S606. On the other hand, if the CPU 201 determines that the key pair and certificate acquisition control unit 305 has not set the CSR for the certificate use corresponding to the certificate issuance request instructed by the user of the RUI, the process proceeds to step S610, which will be described later.
[0048] In step S606, the CPU 201 executes a certificate issuance request process using the key pair and certificate acquisition control unit 305 (issuance request step). At this time, the key pair and certificate acquisition control unit 305 executes the certificate issuance request using the certificate issuance request method acquired in step S603. That is, the CPU 201 issues a certificate issuance request to the certification authority and registration authority 102 using the certificate issuance request method set for the certificate use associated with the certificate issuance request instruction using the key pair and certificate acquisition control unit 305. Note that in step S606, the key pair and certificate acquisition control unit 305 may also execute the certificate issuance request using the certificate issuance request method instructed in step S609, which will be described later. The flowchart in FIG. 6 then ends. Note that the certificate issuance request process in step S606 will be described in detail later with reference to FIG. 12, taking as an example a process in which the certificate issuance request method is SCEP.
[0049] In step S607, the CPU 201 determines whether there are any available certificate signing request methods other than the certificate signing request method acquired in step S603, using the key pair / certificate acquisition control unit 305. In other words, the key pair / certificate acquisition control unit 305 determines, using the setting values acquired from the certificate acquisition information 306, whether any of the certificate signing request methods other than those determined in step S604 have been configured as servers on the connection setting screen in Fig. 8.
[0050] For example, assume that the certificate issuance request method acquired in step S603 is EST, but the EST server settings have not been configured on the connection setting screen of Fig. 8. In this case, the key pair and certificate acquisition control unit 305 determines that a usable certificate issuance request method is available if the SCEP server settings have been configured on the connection setting screen of Fig. 8. This is also true when the ACME server settings have been configured on the connection setting screen of Fig. 8. However, this is limited to cases where the certificate usage in response to the certificate issuance request specified by the RUI user is TLS, which ACME can support, or no usage.
[0051] On the other hand, in this case, if neither SCEP nor ACME server settings have been configured on the connection setting screen of Fig. 8, the key pair and certificate acquisition control unit 305 determines that there is no available certificate issuance request method. Also, even if only ACME server settings have been configured, if the certificate usage in response to the certificate issuance request specified by the RUI user is other than TLS or no usage, the key pair and certificate acquisition control unit 305 determines that there is no available certificate issuance request method.
[0052] If CPU 201 determines via key pair / certificate acquisition control unit 305 that there is a usable certificate issuance request method other than the certificate issuance request method acquired in step S603, processing proceeds to step S608. At this time, CPU 201 notifies Web page control unit 304 via key pair / certificate acquisition control unit 305 that there is a usable certificate issuance request method other than the certificate issuance request method acquired in step S603. On the other hand, if CPU 201 determines via key pair / certificate acquisition control unit 305 that there is no usable certificate issuance request method other than the certificate issuance request method acquired in step S603, processing proceeds to step S610, which will be described later.
[0053] In step S608, the CPU 201 (presentation means) generates the screen of Fig. 11 using the key pair and certificate acquisition control unit 305, and further displays the screen of Fig. 11 on the RUI using the web page control unit 304. As a result, the web page control unit 304 presents to the user of the RUI a certificate issuance request method that can be used for the purpose of the certificate linked to the certificate issuance request instruction and that can connect to the certification authority and registration authority 102. The screen of Fig. 11 is a UI screen (presentation UI screen) that the web browser 504 of the PC 103 pops up and displays on the display 410 of the PC 103, and is an example of a warning screen when a certificate issuance request instruction is issued.
[0054] The warning screen in Fig. 11 has a message 1101, an OK button 1102, and a Cancel button 1103. Message 1101 indicates that the certificate issuance request method obtained in step S603 cannot be used and suggests that a certificate issuance request be made using another available certificate issuance request method. Note that the certificate issuance request method obtained in step S603 is the certificate issuance request method that the RUI user set on the issuance request method setting screen in Fig. 9 for the purpose of the certificate associated with the execute button pressed on the certificate issuance request screen in Fig. 7.
[0055] Returning to the description of Figure 6, in step S609, CPU 201 (determination means) determines whether the user of the RUI has issued an instruction via Web page control unit 304 to execute a certificate issuance request using the proposed certificate issuance request method. Web page control unit 304 makes the determination in step S609 based on whether OK button 1102 (determination button) or cancel button 1103 (determination button) on the warning screen in Figure 11 has been pressed. If OK button 1102 on the warning screen in Figure 11 has been pressed, CPU 201 determines via Web page control unit 304 that the user of the RUI has issued an instruction to execute a certificate issuance request using the proposed certificate issuance request method.
[0056] In this case, the process proceeds to step S605. Furthermore, the web page control unit 304 notifies the key pair / certificate acquisition control unit 305 that it has received an instruction to execute a certificate issuance request using the certificate issuance request method proposed in message 1101 on the warning screen of Fig. 11. On the other hand, if the cancel button 1103 on the warning screen of Fig. 11 is pressed, the CPU 201 determines that the web page control unit 304 has not issued an instruction from the user of the RUI to execute a certificate issuance request using the proposed certificate issuance request method. In this case, the flowchart of Fig. 6 ends.
[0057] In step S610, the CPU 201 performs error processing using the key pair / certificate acquisition control unit 305. After that, the flowchart in Fig. 6 ends. Note that in step S610, the key pair / certificate acquisition control unit 305 may display a screen on the RUI via the web page control unit 304 indicating that the certificate issuance request could not be executed. In this case, the screen indicating that the certificate issuance request could not be executed is displayed on the display 410 of the PC 103 by the web browser 504 of the PC 103.
[0058] 12 is a flowchart showing the flow of the certificate issuance request process in step S606. Here, as described above, a case will be described in which the certificate issuance request method is SCEP. In step S1201, CPU 201 causes key pair and certificate acquisition control unit 305 to acquire, from certificate acquisition information 306, values set via the certificate issuance request screen in FIG. 7, that is, values set on each setting screen to which access can be made from the certificate issuance request screen in FIG. 7. In step S1202, CPU 201 causes key pair and certificate acquisition control unit 305 to acquire, via key pair and certificate management unit 309, the CA certificate of certification authority and registration authority 102 stored in key and certificate information 307.
[0059] In step S1203, CPU 201 performs a process of generating a public key pair based on the values (such as [key length] and [issuer information input]) acquired in step S1201 by key pair / certificate acquisition control unit 305. Furthermore, key pair / certificate acquisition control unit 305 performs a process of generating CSR (certificate signing request) data in PKCS#10 format via encryption processing unit 308. PKCS#10 stands for RFC2986-PKCS#10: Certification Request Syntax Specification.
[0060] In step S1204, the CPU 201 determines whether the generation of the public key pair and CSR data in step S1203 was successful using the key pair and certificate acquisition control unit 305. If the CPU 201 determines that the generation of the public key pair and CSR data in step S1203 was successful using the key pair and certificate acquisition control unit 305, the process proceeds to step S1205. On the other hand, if the CPU 201 determines that the generation of the public key pair and CSR data in step S1203 was not successful using the key pair and certificate acquisition control unit 305, the process proceeds to step S1221, which will be described later.
[0061] In step S1205, CPU 201 generates certificate issuance request data using key pair and certificate acquisition control unit 305. The certificate issuance request data generated in step S1205 is in PKCS#7 format, as defined by SCEP. In step S1206, CPU 201 determines whether key pair and certificate acquisition control unit 305 has successfully generated the certificate issuance request data in step S1205. If CPU 201 determines that key pair and certificate acquisition control unit 305 has successfully generated the certificate issuance request data in step S1205, the process proceeds to step S1207. On the other hand, if key pair and certificate acquisition control unit 305 determines that the certificate issuance request data has not been successfully generated in step S1205, the process proceeds to step S1221, which will be described later.
[0062] In step S1207, the CPU 201, using the key pair and certificate acquisition control unit 305, establishes a connection to the certification authority and registration authority 102, which is the SCEP server, via the communication control unit 303 using the TCP / IP protocol. At this time, the communication control unit 303 uses the values acquired in step S1201 (the SCEP server name, port number, and challenge password set on the connection setting screen in FIG. 8 ). In step S1208, the CPU 201, using the key pair and certificate acquisition control unit 305, determines whether the connection made in step S1207 was successful. If the CPU 201, using the key pair and certificate acquisition control unit 305, determines that the connection made in step S1207 was successful, the process proceeds to step S1209. On the other hand, if the CPU 201, using the key pair and certificate acquisition control unit 305, determines that the connection made in step S1207 was not successful, the process proceeds to step S1221, which will be described later.
[0063] In step S1209, the CPU 201 causes the key pair and certificate acquisition control unit 305 to transmit the certificate issuance request data generated in step S1205 to the certification authority and registration authority 102, which is the SCEP server, via the communication control unit 303. At this time, the communication control unit 303 transmits the certificate issuance request data using the GET or POST method of HTTP protocol communication. In step S1210, the CPU 201 causes the key pair and certificate acquisition control unit 305 to determine whether the transmission in step S1209 was successful. If the CPU 201 determines that the key pair and certificate acquisition control unit 305 determined that the transmission in step S1209 was successful, the process proceeds to step S1211. On the other hand, if the CPU 201 determines that the key pair and certificate acquisition control unit 305 determined that the transmission in step S1209 was not successful, the process proceeds to step S1221, which will be described later.
[0064] In step S1211, the CPU 201 receives response data to the certificate issuance request from the certification authority / registration authority 102 via the communication control unit 303 using the key pair / certificate acquisition control unit 305. The response data received in step S1211 is data in the PKCS#7 format defined by SCEP. In step S1212, the CPU 201 determines whether the reception in step S1211 was successful using the key pair / certificate acquisition control unit 305. If the CPU 201 determines that the reception in step S1211 was successful using the key pair / certificate acquisition control unit 305, the process proceeds to step S1213. On the other hand, if the CPU 201 determines that the reception in step S1211 was not successful using the key pair / certificate acquisition control unit 305, the process proceeds to step S1221, which will be described later.
[0065] In step S1213, CPU 201 causes key pair and certificate acquisition control unit 305 to verify the signature data in the response data received in step S1211 via encryption processing unit 308, using the public key in the CA certificate acquired in step S1202. In step S1214, CPU 201 causes key pair and certificate acquisition control unit 305 to determine whether the verification in step S1213 was successful. If CPU 201 determines that key pair and certificate acquisition control unit 305 has verified that the verification in step S1213 was successful, the process proceeds to step S1215. On the other hand, if CPU 201 determines that key pair and certificate acquisition control unit 305 has verified that the verification in step S1213 was not successful, the process proceeds to step S1221, which will be described later.
[0066] In step S1215, the CPU 201 acquires certificate data contained in the response data by analyzing the response data received in step S1211 using the key pair and certificate acquisition control unit 305 via the encryption processing unit 308. In step S1216, the CPU 201 determines whether the acquisition in step S1215 was successful using the key pair and certificate acquisition control unit 305. If the CPU 201 determines that the acquisition in step S1215 was successful using the key pair and certificate acquisition control unit 305, the process proceeds to step S1217. On the other hand, if the CPU 201 determines that the acquisition in step S1215 was not successful using the key pair and certificate acquisition control unit 305, the process proceeds to step S1221, which will be described later.
[0067] In step S1217, the CPU 201 causes the key pair and certificate acquisition control unit 305 to register the certificate data acquired in step S1215 as a certificate corresponding to the public key pair generated in step S1203. At this time, the key pair and certificate acquisition control unit 305 links the public key pair generated in step S1203 with the certificate data acquired in step S1215 via the key pair and certificate management unit 309, and stores the linked data in the key and certificate information 307. In step S1218, the CPU 201 causes the key pair and certificate acquisition control unit 305 to determine whether the registration in step S1217 was successful. If the CPU 201 determines that the key pair and certificate acquisition control unit 305 determined that the registration in step S1217 was successful, the process proceeds to step S1219. On the other hand, if the CPU 201 determines that the key pair and certificate acquisition control unit 305 determined that the registration in step S1217 was not successful, the process proceeds to step S1221, which will be described later.
[0068] In step S1219, the CPU 201 (storage means) causes the key pair and certificate acquisition control unit 305 to set the certificate usage based on the certificate usage information acquired in step S1201. At this time, the key pair and certificate acquisition control unit 305 links the public key pair and certificate data saved in step S1217 with the certificate usage information acquired in step S1201 via the key pair and certificate management unit 309, and saves the linked data in the key and certificate information 307. In step S1220, the CPU 201 causes the key pair and certificate acquisition control unit 305 to determine whether the setting in step S1219 was successful. If the CPU 201 determines that the key pair and certificate acquisition control unit 305 has determined that the setting in step S1219 has been successful, the process returns to the flowchart of FIG. 6. On the other hand, if the CPU 201 determines that the key pair and certificate acquisition control unit 305 has determined that the setting in step S1219 has not been successful, the process proceeds to step S1221.
[0069] In step S1221, CPU 201 executes error processing using key pair / certificate acquisition control unit 305. In step S1221, key pair / certificate acquisition control unit 305 may display a screen on the RUI via web page control unit 304 indicating what type of error has occurred. In this case, the screen indicating what type of error has occurred is displayed on display 410 of PC 103 by web browser 504 of PC 103. Thereafter, processing returns to the flowchart of FIG. 6. When processing returns to the flowchart of FIG. 6, the flowchart of FIG. 6 ends.
[0070] As described above, the multifunction peripheral 101 can use multiple certificate issuance request methods and can use certificates for multiple purposes, but the certificate issuance request method is set for each certificate purpose in accordance with the RUI user's selection from each of the pull-down menus 901 to 904. This allows the RUI user to set a certificate issuance request method in combination with the certificate purpose, making it easy to understand which certificate issuance request method is set for which certificate purpose.
[0071] Furthermore, in the multifunction peripheral 101, an instruction for a certificate issuance request is accepted in association with the certificate purpose associated with the execution button pressed by the RUI user out of multiple execution buttons on the immediate issuance execution 704. Furthermore, the certificate issuance request is made to the certification authority / registration authority 102 using the certificate issuance request method set for the certificate purpose associated with the instruction. This allows the RUI user to easily understand the certificate purpose for which the multifunction peripheral 101 is to make a certificate issuance request and the certificate issuance request method used. In this way, the multifunction peripheral 101 can improve usability when making a certificate issuance request that matches the certificate purpose.
[0072] While the preferred embodiment of the present invention has been described above, the present invention is not limited to the above embodiment, and various modifications and variations are possible within the spirit and scope of the present invention. For example, in this embodiment, a certificate issuance request is immediately executed by pressing one of the execute buttons included in the immediate issuance execution 704 on the certificate issuance request screen of FIG. 7. In this regard, the RUI user may set the timing of the certificate issuance request by pressing each execute button (hereinafter referred to as "timing") on a screen accessible from the certificate issuance request screen of FIG. 7, and the certificate issuance request may be executed at the respective timing. In this case, the CPU 201 causes the key pair / certificate acquisition control unit 305 to store each timing set on the screen accessible from the certificate issuance request screen in the certificate acquisition information 306. Furthermore, when the timing set by the key pair / certificate acquisition control unit 305 arrives, the CPU 201 (timing setting means) executes the processing from step S602 onward for the certificate use associated with the execute button for which the timing has been set. The timing may be set, for example, by date and time.
[0073] In this embodiment, the immediate issuance execution 704 on the certificate issuance request screen in FIG. 7 has an execution button for executing a certificate issuance request for each certificate use, but a batch execution button may also be provided. The batch execution button is an execution button for executing a certificate issuance request for all certificate uses. In other words, the batch execution button is associated with all certificate uses. In this case, in step S601, in response to pressing the batch execution button, the CPU 201, via the key pair and certificate acquisition control unit 305, accepts an instruction for a certificate issuance request linked to all certificate uses. Furthermore, the CPU 201, via the key pair and certificate acquisition control unit 305, executes the processing from step S602 onwards for each certificate use associated with each execution button in the immediate issuance execution 704. Note that the immediate issuance execution 704 on the certificate issuance request screen in FIG. 7 may have a batch execution button in addition to the execution buttons provided for each certificate use, or may have only the batch execution button.
[0074] In this embodiment, as described above, the administrator of the multifunction peripheral 101 uses the web browser 504 installed on the PC 103 to connect to the RUI published by the multifunction peripheral 101 and perform operations such as issuing a certificate request, obtaining a certificate, and issuing instructions for updating a certificate. However, the administrator of the multifunction peripheral 101 may also perform operations such as issuing a certificate request, obtaining a certificate, and issuing instructions for updating a certificate on the multifunction peripheral 101. In this case, the screens shown in FIGS. 7 to 11 are displayed on the operation panel 211 of the multifunction peripheral 101.
[0075] The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or storage medium, and having one or more processors in the computer of the system or device read and execute the program. The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.
[0076] The disclosure of this embodiment includes the following configuration, method, and program. (Configuration 1) A setting means for setting a protocol to be used in a request for issuance of a digital certificate for each purpose of the digital certificate according to input by a user; a receiving means for receiving an instruction for requesting issuance of a digital certificate in association with a purpose of the digital certificate in response to an input by a user; an issuance request means for making a request for issuance of an electronic certificate to an issuing server using a protocol set for the purpose of the electronic certificate linked to the instruction. (Configuration 2) The information processing device according to configuration 1, wherein the setting means and the receiving means acquire input from a user via a UI screen. (Configuration 3) The information processing device according to configuration 2, wherein the setting means acquires an input by the user from a pull-down menu included in the UI screen. (Configuration 4) The information processing device according to configuration 2 or 3, wherein the accepting means acquires an input from a user via an accepting button on the UI screen. (Configuration 5) The information processing apparatus according to any one of configurations 2 to 4, wherein the setting means and the receiving means acquire an input from a user through a remote UI that displays the UI screen. (Configuration 6) An information processing device described in any one of configurations 1 to 5, characterized in that it is provided with a presentation means that, if it is not possible to connect to the issuing server using a protocol set for the use of the electronic certificate linked to the instruction, presents to the user a protocol that can be used for the use of the electronic certificate linked to the instruction and that can connect to the issuing server. (Configuration 7) The information processing device according to configuration 6, further comprising a determination means for determining, in response to a user's input, whether to cause the issuance request means to make an issuance request for an electronic certificate using the protocol presented to the user by the presentation means. (Configuration 8) The information processing device according to configuration 7, wherein the determining means acquires an input from a user via a presentation UI screen. (Configuration 9) The information processing device according to configuration 8, wherein the determination means acquires an input from a user via a determination button provided on the presentation UI screen. (Configuration 10) The information processing device according to configuration 8 or 9, wherein the determining means acquires an input from a user from a remote UI that displays the presentation UI screen. (Configuration 11) The information processing device according to any one of configurations 1 to 10, wherein the accepting means accepts the instruction by linking it to one use of the electronic certificate. (Configuration 12) The information processing device according to any one of configurations 1 to 10, wherein the accepting means accepts the instruction in association with all uses of the electronic certificate. (Configuration 13) An information processing device according to any one of configurations 1 to 12, characterized in that it comprises a storage means for storing an electronic certificate issued in response to an electronic certificate issuance request made by the issuance request means, in association with the purpose of the electronic certificate linked to the instruction. (Configuration 14) A CSR setting means is provided for setting a CSR for each use of the digital certificate according to input by a user, The information processing device described in any one of configurations 1 to 13, characterized in that when a CSR setting has been made for the use of the electronic certificate linked to the instruction, the issuance request means makes a request for issuance of the electronic certificate to the issuing server using a protocol set for the use of the electronic certificate linked to the instruction. (Configuration 15) The information processing device according to configuration 14, wherein the CSR setting means acquires an input from a user via a CSR setting UI screen. (Configuration 16) The information processing device according to configuration 15, wherein the CSR setting means acquires input from the user from radio buttons and input fields provided on the CSR setting UI screen. (Configuration 17) The information processing apparatus according to configuration 15 or 16, wherein the CSR setting means acquires an input from a user from a remote UI that displays the CSR setting UI screen. (Configuration 18) The information processing device according to any one of configurations 1 to 17, further comprising a timing setting means for setting the timing at which the issuance request means executes the issuance request for the digital certificate in response to an input from a user. (Configuration 19) An information processing device described in any one of configurations 1 to 18, characterized in that the protocols that the setting means can set for each use of the electronic certificate are SCEP (Simple Certificate Enrollment Protocol), EST (Enrollment over Secure Transport), and ACME (Automatic Certificate Management Environment). (Method 1) A setting process for setting the protocol to be used in a request for issuance of a digital certificate for each purpose of the digital certificate according to input by a user; an accepting step of accepting an instruction for requesting issuance of a digital certificate by associating it with the purpose of the digital certificate according to an input by a user; an issuance request step of making an issuance request for an electronic certificate to an issuing server using a protocol set for the use of the electronic certificate linked to the instruction. [Explanation of symbols]
[0077] 101 Multifunction machines (information processing devices) 102 Certification Authority / Registration Authority (Issuing Server) 201 CPU (setting means) (receiving means) (issuing request means)
Claims
1. a setting means for setting a protocol to be used in a request for issuance of a digital certificate for each purpose of the digital certificate in accordance with input by a user; a receiving means for receiving an instruction for requesting issuance of a digital certificate in association with a purpose of the digital certificate in response to an input by a user; an issuance request means for making a request for issuance of an electronic certificate to an issuing server using a protocol set for the purpose of the electronic certificate linked to the instruction.
2. 2. The information processing apparatus according to claim 1, wherein the setting means and the receiving means acquire input from the user via a UI screen.
3. 3. The information processing apparatus according to claim 2, wherein the setting unit acquires an input from a user from a pull-down menu on the UI screen.
4. 3. The information processing apparatus according to claim 2, wherein the accepting unit acquires an input from the user via an accepting button on the UI screen.
5. 5. The information processing apparatus according to claim 2, wherein the setting unit and the receiving unit acquire input from a user from a remote UI that displays the UI screen.
6. The information processing device according to claim 1, further comprising a presentation means for presenting to the user a protocol that can be used for the purpose of the electronic certificate linked to the instruction and that can connect to the issuing server if the issuing server cannot be connected to using the protocol set for the purpose of the electronic certificate linked to the instruction.
7. 7. The information processing apparatus according to claim 6, further comprising a determination unit that determines, in response to an input from a user, whether to cause the issuance request unit to make a request for issuance of an electronic certificate using the protocol presented to the user by the presentation unit.
8. 8. The information processing apparatus according to claim 7, wherein the determining means acquires an input from a user via a UI screen.
9. 9. The information processing apparatus according to claim 8, wherein the determination means acquires an input from a user via a determination button on the UI screen.
10. 10. The information processing apparatus according to claim 8, wherein the determining unit acquires an input from a user through a remote UI that displays the UI screen.
11. 2. The information processing apparatus according to claim 1, wherein the accepting unit accepts the instruction by linking it to one use of the digital certificate.
12. 2. The information processing apparatus according to claim 1, wherein the accepting unit accepts the instruction in association with all uses of the electronic certificate.
13. 2. The information processing device according to claim 1, further comprising a storage means for storing an electronic certificate issued in response to an electronic certificate issuance request made by the issuance request means, in association with the purpose of the electronic certificate associated with the instruction.
14. a CSR setting means for setting a CSR for each use of the electronic certificate in response to an input by a user; The information processing device described in claim 1, characterized in that, when CSR settings have been made for the use of the electronic certificate linked to the instruction, the issuance request means makes a request to the issuing server for the issuance of the electronic certificate using a protocol set for the use of the electronic certificate linked to the instruction.
15. 15. The information processing apparatus according to claim 14, wherein the CSR setting means acquires an input from a user via a UI screen.
16. 16. The information processing apparatus according to claim 15, wherein the CSR setting means acquires input from a user through radio buttons and input fields on the UI screen.
17. 17. The information processing apparatus according to claim 15, wherein the CSR setting unit acquires an input from a user through a remote UI that displays the UI screen.
18. 2. The information processing apparatus according to claim 1, further comprising a timing setting unit that sets the timing at which the issuance request unit executes the issuance request for the digital certificate in response to an input from a user.
19. 2. The information processing device according to claim 1, wherein the protocols that the setting means can set for each use of the electronic certificate are SCEP (Simple Certificate Enrollment Protocol), EST (Enrollment over Secure Transport), and ACME (Automatic Certificate Management Environment).
20. a setting process for setting a protocol to be used in a request for issuance of a digital certificate for each purpose of the digital certificate in accordance with input by a user; an accepting step of accepting an instruction for requesting issuance of a digital certificate by associating it with the purpose of the digital certificate according to an input by a user; an issuance request step of making an issuance request for an electronic certificate to an issuing server using a protocol set for the use of the electronic certificate linked to the instruction.
Citation Information
Patent Citations
Information processing system, its control method and program
JP7381794B2