Automated Provisioning of Unknown Computer Systems via Bootstrap Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Provisioning unknown computer systems in a data center requires manual intervention for initial setup, which is insecure and inefficient, as existing methods rely on pre-execution environment (PXE) booted systems but still necessitate administrator-driven steps for system recognition.
Innovation Solution
A method that detects unknown computer systems, communicates a global identifier and digital certificate to enable secure automated provisioning, using a network-based boot strap server or boot strap media before loading the operating system, thereby facilitating secure and automated system management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual intervention is used to make the system known before initial provisioning, then system security can be maintained through administrator control, but provisioning efficiency and automation are reduced
Solution Approach 1:
The system performs preliminary actions by pre-configuring security policies, digital certificates, and authorization rules in the configuration management database before the unknown system boots. This allows automated secure provisioning without requiring manual administrator intervention during the initial boot process, resolving the contradiction between security and efficiency
Solution Approach 2:
A bootstrap application acts as an intermediary between the unknown system and the configuration management system. This intermediary automatically retrieves security policies and digital certificates, establishing secure communication channels without manual intervention while maintaining security controls, thus improving provisioning efficiency without compromising security
2Extent of automation
If pre-execution environment (PXE) booted systems are used, then automated provisioning can be enabled, but manual administrator intervention is still required for system recognition
Solution Approach 1:
The unknown system performs self-service by automatically executing the bootstrap application during boot, which autonomously identifies the system, retrieves security policies, and establishes secure communication with the configuration management system. This eliminates the need for administrator intervention while maintaining full automation, resolving the contradiction between automation extent and ease of operation
3Reliability
If manual steps are required for initial provisioning, then security control is maintained, but administrative overhead and time consumption increase
Solution Approach 1:
Security controls, digital certificates, and authorization policies are pre-configured in the configuration management database before the unknown system boots. This preliminary preparation enables automated secure provisioning, eliminating time-consuming manual security configuration steps while maintaining security control, thus resolving the contradiction between security control and time loss
Data Source
AI summary
A method of provisioning an unknown computer system is disclosed. The method includes detecting a computer system to be provisioned, determining that the computer system is unknown to a configuration management system, and identifying a global identifier and a digital certificate to be used to provision the computer system. The method further includes communicating the global identifier and the digital certificate from a network based boot strap server or from boot strap media to the computer system prior to loading an operating system onto the computer system.


