Certificate (Crtf)

The object Certificate (Crtf) represents an external visible feature of a X509 certificate.

The TLS/SSL client certificate is depicted as the certificate object and includes a reference to the corresponding file. The client certificate for BACnet Secure Connect nodes is used in this case to establish a mutual TLS connection to the server. The certificate object assumes the depiction and warning as to the validity of the certificate.

Basic model

Reliability

 

 

'Reliability' provides information on whether the 'Present value' of the certificate object is reliable. Property 'Reliability' indicates the source of the failure if 'Present value' is not reliable on the certificate object.

Present value

 

 

'Present value' displays the present output value of the certificate state.

Certificate states:

  • 1: Activated
    The certificate is active.
  • 2: Expiration warning
    The certificate has an expiration warning.
  • 3: Expired
    The certificate is expired.
  • 4: Inactive
    There is no valid certificate.

State flag

 

 

'State flag' indicates the four states for the certificate object.

  • Out of service
    Out of service indicates via property 'Out of service' whether the certificate object was decoupled.
    The applicable certificate management program no longer updates properties 'Present value' and 'Reliability' if "Out of service" is set.
    Properties 'Present value' and 'Reliability' can be updated for simulations and testing if "Out of service" is set.
  • Overridden
    Value = False
  • Fault
    "Fault" indicates whether the certificate is reliable or not. "Fault" indicates whether property 'Reliability' has a value of "No fault" or not.
  • In alarm
    Value = True if intrinsic reporting is possible and the alarm states are set.

Out of service

 

 

'Out of service' decouples the certificate object to prevent the certificate management program from changing it.

Event state

 

 

'Event state' determines whether the object belongs to an active event state. The value of this property is NORMAL if the object does not support intrinsic reporting.

Tracking value

 

 

'Tracking value' represents the calculated value regardless of whether the object is decoupled via 'Out of service'. Certificate management provides the value.

Number of states

 

 

'Number of states' defines the number of states that can report 'Present value'.

Property ID: 74

State text

 

 

'State text' describes the states that can report 'Present value'.

 

Object model

X509 version

 

 

'X509 version' indicates the version number of the X509 certificate.

Signature algorithm

 

 

'Signature algorithm' indicates the signature algorithm ID of a X509 certificate.

Max length: Maximum 32 characters.

X509 serial number

 

 

'X509 serial number' indicates the serial number number of the X509 certificate.

Max length: 32 characters.

Valid from

 

 

'Valid from' indicates the validity period "NotBefore" of a X509 certificate.

The property of type date and time is displayed in GMT and UTC.

Valid to

 

 

'Valid to' indicates the validity period "NotAfter" of a X509 certificate.

The property of type date and time is displayed in GMT and UTC.

Issuer

 

 

'Issuer' indicates the name of the X509 certificate issuer.

Max length: 512 characters

Issuer chain

 

 

'Issuer chain' indicates the certificate chain for the issuer via the attribute "CommonName" of a X509 certificate.

Subject

 

 

'Subject' indicates the attribute "Subject.Name" of an X509 certificate.

Maximum length: 512 characters

Subject name

 

 

'Subject name' indicates the attribute "Subject.CommonName" of an X509 certificate.

This is the identity of the certificate. This is a FQDN (Fully-Qualified Domain Name) for an externally signed TLS/SSL certificate. For a self-signed TLS/SSL certificate, this can be the automation station name, ID, or serial number (or combination thereof).

Maximum length: 63 characters

Subject alternative name

 

 

'Subject alternative name' indicates the default extension attribute "Subject.AltName" of an X509 certificate.

Maximum length: 63 characters (without prefix)

Certificate reference

 

 

'Certificate reference' references the file containing the certificate.

Expiration warning

 

 

'Expiration warning' indicates when an expiration warning is triggered for a X509 certificate. The expiration date is used to trigger an alarm. The alarm is intended to renew the certificate before final expiration.

Expiration warning time

 

 

'Expiration warning time' represents a configurable permanent value that can trigger a warning prior to final expiration of the certificate. The property 'Valid to' of an X509 certificate defines the final expiration. 'Expiration warning time' is indicated as a relative value in days (e.g. 90).

 

Alarming

Alarming is triggered as per the principle of intrinsic messaging within a BACnet object.

An alarm is triggered as soon as the alarm value changes to 2 (expiration warning) or 3 (expired).

Alarm values

 

 

'Alarm values' represents a selection of "OffNormal" values.

Monitoring time deviation

 

 

'Monitoring time deviation' determines the time in [s], during which the present state is equal to a state defined for 'Alarm values' before an event "To-OffNormal" is triggered. The time is also considered for a change between alarm values.

Property ID: 113

Notification type

 

 

"Notification type" conveys whether the notifications generated by the object should be of type "Event" or "Alarm".

Event state

 

 

'Event state' determines whether the object belongs to an active event state. The value of this property is NORMAL if the object does not support intrinsic reporting.

Notification class

 

 

'Notification class' determines the priority of an event and whether the event must be acknowledged or reset. The following are the notification classes:
1: Highest priority notification (acknowledge, reset)
2: Highest priority notification (acknowledge)
3: Highest priority notification
4: High priority notification (acknowledge, reset)
5: High priority notification (acknowledge)
6: High priority notification
7: Medium priority notification (acknowledge, reset)
8: Medium priority notification (acknowledge)
9: Medium priority notification
10: Low priority notification (acknowledge, reset)
11: Low priority notification (acknowledge)
12: Low priority notification
13: Lowest priority notification (acknowledge, reset)
14: Lowest priority notification (acknowledge)
15: Lowest priority notification
16: None priority notification
17: Buffer ready notification
18: Device alert notification

Property ID: 17

Time stamp of event

 

 

"Time stamp of event" conveys the times of the last event notifications for TO-OFFNORMAL, TO-FAULT, and TO-NORMAL events, respectively.

Event message texts

 

 

'Event message texts' consists of one set of three writable character strings, one per state transition (To-Offnormal, To-Fault, and To-Normal).