Certificates management
The Certificates management task manages operational certificates in ABT Site projects for:
- Web interface
- BACnet/SC
- IEEE 802.1X
BACnet/SC requires a proper set of certificates for each entity (device, management station, ABT Site, diagnostic tool) on the network to 1) authenticate the devices and 2) encrypt/decrypt traffic. Each entity (both sides) must have two types of certificates::
- A common root certificate (certificate authority (CA) certificate) which is identical for all devices on a single BACnet/SC project and regardless of device manufacturer. “I belong to project X”.
- Individual operational certificates (client certificates) are unique per device and are used to authenticate each device and encryp/decrypt traffic. Client certificates are bound to a permanent and unique identifier such as the device’s serial number. “I am device A”, “I am device B”, etc.
ABT Site handles and manages certificates for Siemens devices and provides easy and intuitive workflows. ABT Site online help can also access tool-specific instructions on BACnet/SC network configuration and certificate management. ABT Site generates certificates for embedded Siemens devices based on their unique and permanent identifier (here device serial number). Desigo CC certificates are generated on the machine (PC or server) operating the Desigo CC management platform software and bound to the machine by using some unique identifier such as MAC address of Network Interface Cart, serial number of the hard drive, or combination thereof.
Operational certificates
Certificate workflows
1 | Task selector | 2 | Work area (Certificate management table) |
3 | Details pane | 4 | Web interface, BACnet/SC and IEEE 802.1X tab |
5 | Toolbar | 6 | Context menu |
① Task selector
Column | Description |
|---|---|
Building Structure | |
Central functions | |
Device list | |
Application & device overview | |
Certificates management | Current task |
Network check | |
BACnet/SC |
② Work area: Certificates management table
Column | Description |
|---|---|
Name | Application template or automation station. |
Location | Application template or automation station. |
Description | Application template or automation station. |
Address | IP address of the device. |
Serial number | Device serial numbers can be automatically added with a barcode scanner or when data is read back after commissioning. |
Certificate type | Possible values are None, Internal, or External. |
Issuing authority | Read-only. Displays the root certificate authority. Internal types must be read from the root certificate for the project. External certificates read the external certificate authority name to from the certificate. The certificate must be imported to show the name of the external authority, otherwise the value is Not imported. For certificate type None the issuing authority displays "~". |
Valid until | Certificate expiration date. Note: BACnet/SC communication fails once a single certificate expires. This may be the root certificate, or the operational/client certificate of a node, or the hub certificate. |
③ Details pane
The contents of the Details pane vary depending on the selected element.
Building element details
Details pane of the device version ≤ 1.5
Details pane of the device version ≥ 1.6
Room and segment details
Application template details
④ Web interface, BACnet/SC and IEEE 802.1X tab
Switches between web certificate, BACnet/SC and IEEE 802.1X certificate entries.
⑤ Toolbar
Toolbar web certificate
Command | Description |
|---|---|
Show details | Displays the Certificate Information. |
Report | Generates a certificate report. The certificate report contains the information in the Certificates management table. The report opens in the Reports component. |
Renew internal | Updates internal certificates. |
Export root certificate (Web) | Exports the public key of the root certificate to the folder defined in Project Manager > Settings > Projects and paths. |
Import external | Imports device certificates issued by an external certificate authority. |
Export CSR | Exports a certificate signing request for the selected devices. Only works for devices with external certificate type. |
Toolbar BACnet/SC certificate
Command | Description |
|---|---|
Show details | Displays the Certificate Information. |
Report | Generates a certificate report. The certificate report contains the information in the Certificates management table. The report opens in the Reports component. |
Renew internal | Updates internal certificates. |
Export root certificate (/SC) | Exports the public key of the root certificate to the folder defined in Project Manager > Settings > Projects and paths. |
Import external | Imports device certificates issued by an external certificate authority. |
Export CSR | Exports a certificate signing request for the selected devices. Only works for devices with external certificate type. |
Toolbar IEEE 802.1X certificate

IEEE 802.1X certificates are only supported as of device version V1.6 (check the device version in the Details pane > System folder > Device version).
Command | Description |
|---|---|
Show details | Displays the Certificate Information. |
Report | Generates a certificate report. The certificate report contains the information in the Certificates management table. The report opens in the Reports component. |
Renew internal | Updates internal certificates. |
Export root certificate (IEEE 802.1X) | Exports the public key of the root certificate to the folder defined in Project Manager > Settings > Projects and paths. |
Import external | Imports device certificates issued by an external certificate authority. |
Export CSR | Exports a certificate signing request for the selected devices. Only works for devices with external certificate type. |
⑥Context menu
Command | Description |
|---|---|
Edit | Highlights the selected column value for renaming. |
Change certificate authority | Change the certificate type of the device. Possible values are None, Internal, or External. |