- Santa Clara CA, US Gregor Maier - Alameda CA, US Carl D. Roth - Santa Cruz CA, US Jeffrey Townsend - Morgan Hill CA, US Jason Parraga - Sunnyvale CA, US Cham Ho Li - San Jose CA, US Tomasz Klimczyk - Lgota Wielka, PL
International Classification:
H04L 29/06 G06F 9/44 G06F 13/40
Abstract:
Methods, systems, and computer programs are presented for creating a secure network fabric and for adding trusted devices to an existing secure network fabric. One method includes an operation for setting a switch into a provisioning mode where the switch does not enforce secure communications. While the switch is in provisioning mode, the method performs operations including establishing a connection from the switch to a provisioning controller, sending a certificate signing request (CSR) from the switch to the provisioning controller, and receiving, from the provisioning controller, a security certificate generated by a certificate authority. The method further includes an operation for entering a lockdown mode by the switch after receiving the security certificate, where the switch, while in lockdown mode, secures communications utilizing the security certificate.