Certificates management

The Certificates management task manages operational certificates in ABT Site projects for:

BACnet/SC requires a proper set of certificates for each entity (device, management station, ABT Site, diagnostic tool) on the network to 1) authenticate the devices and 2) encrypt/decrypt traffic. Each entity (both sides) must have two types of certificates::

  1. A common root certificate (certificate authority (CA) certificate) which is identical for all devices on a single BACnet/SC project and regardless of device manufacturer. “I belong to project X”.
  2. Individual operational certificates (client certificates) are unique per device and are used to authenticate each device and encryp/decrypt traffic. Client certificates are bound to a permanent and unique identifier such as the device’s serial number. “I am device A”, “I am device B”, etc.

ABT Site handles and manages certificates for Siemens devices and provides easy and intuitive workflows. ABT Site online help can also access tool-specific instructions on BACnet/SC network configuration and certificate management. ABT Site generates certificates for embedded Siemens devices based on their unique and permanent identifier (here device serial number). Desigo CC certificates are generated on the machine (PC or server) operating the Desigo CC management platform software and bound to the machine by using some unique identifier such as MAC address of Network Interface Cart, serial number of the hard drive, or combination thereof.
Operational certificates
Certificate workflows

 

1

Task selector

2

Work area (Certificate management table)

3

Details pane

4

Web interface, BACnet/SC and IEEE 802.1X tab

5

Toolbar

6

Context menu

 

① Task selector

Column

Description

Building Structure

Building structure

Central functions

Central functions

Device list

Device list

Application & device overview

Application & device overview

Certificates management

Current task

Network check

Network check

BACnet/SC

BACnet/SC

② Work area: Certificates management table

Column

Description

Name

Application template or automation station.

Location

Application template or automation station.

Description

Application template or automation station.

Address

IP address of the device.

Serial number

Device serial numbers can be automatically added with a barcode scanner or when data is read back after commissioning.
Adding the serial number

Certificate type

Possible values are None, Internal, or External.

Issuing authority

Read-only.

Displays the root certificate authority.

Internal types must be read from the root certificate for the project.

External certificates read the external certificate authority name to from the certificate. The certificate must be imported to show the name of the external authority, otherwise the value is Not imported.

For certificate type None the issuing authority displays "~".

Valid until

Certificate expiration date.

Note: BACnet/SC communication fails once a single certificate expires. This may be the root certificate, or the operational/client certificate of a node, or the hub certificate.

③ Details pane

The contents of the Details pane vary depending on the selected element.
Building element details
Details pane of the device version ≤ 1.5
Details pane of the device version ≥ 1.6
Room and segment details
Application template details

 

④ Web interface, BACnet/SC and IEEE 802.1X tab

Switches between web certificate, BACnet/SC and IEEE 802.1X certificate entries.

 

⑤ Toolbar

Toolbar web certificate

Command

Description

Show details

Displays the Certificate Information.

Report

Generates a certificate report. The certificate report contains the information in the Certificates management table. The report opens in the Reports component.
Reports

Renew internal

Updates internal certificates.
Renewing web internal operational certificate

Export root certificate (Web)

Exports the public key of the root certificate to the folder defined in Project Manager > Settings > Projects and paths.
Exporting the web root certificate

Import external

Imports device certificates issued by an external certificate authority.
Importing a web operational certificate from an external CA

Export CSR

Exports a certificate signing request for the selected devices. Only works for devices with external certificate type.
Exporting a web operational certificate signing request

 

Toolbar BACnet/SC certificate

Command

Description

Show details

Displays the Certificate Information.

Report

Generates a certificate report. The certificate report contains the information in the Certificates management table. The report opens in the Reports component.
Reports

Renew internal

Updates internal certificates.
Renewing BACnet/SC internal operational certificate

Export root certificate (/SC)

Exports the public key of the root certificate to the folder defined in Project Manager > Settings > Projects and paths.
Exporting the BACnet/SC root certificate

Import external

Imports device certificates issued by an external certificate authority.
Importing a BACnet/SC certificate from an external CA

Export CSR

Exports a certificate signing request for the selected devices. Only works for devices with external certificate type.
Exporting a BACnet/SC operational certificate signing request

 

Toolbar IEEE 802.1X certificate

info

IEEE 802.1X certificates are only supported as of device version V1.6 (check the device version in the Details pane > System folder > Device version).

Command

Description

Show details

Displays the Certificate Information.

Report

Generates a certificate report. The certificate report contains the information in the Certificates management table. The report opens in the Reports component.
Reports

Renew internal

Updates internal certificates.
Renewing IEEE 802.1X internal operational certificate

Export root certificate (IEEE 802.1X)

Exports the public key of the root certificate to the folder defined in Project Manager > Settings > Projects and paths.
Exporting the IEEE 802.1X root certificate

Import external

Imports device certificates issued by an external certificate authority.
Importing a IEEE 802.1X operational certificate from an external CA

Export CSR

Exports a certificate signing request for the selected devices. Only works for devices with external certificate type.
Exporting a IEEE 802.1X operational certificate signing request

⑥Context menu

Command

Description

Edit

Highlights the selected column value for renaming.

Change certificate authority

Change the certificate type of the device. Possible values are None, Internal, or External.