Signing an external BACnet/SC CSR
ABT Site can act as a CA (certificate authority) for Desigo based BACnet/SC projects. You can sign an external certificate signing request for example from Desigo CC in order to sign certificates for Desigo CC.
By standard specification, a BACnet/SC project can only have one CA. The CA needs to have the root certificate of the project in order to sign certificates. Therefore, it is important to clarify at the very beginning of a project who shall be the CA of that project.
If the project owner decides to use a CA of its own choice, or if the project is a multi-vendor project and another vendor than Siemens takes the role of the project’s CA, the certification process splits up.
- For operational certificates:
- ABT Site creates operational certificates for its Desigo BACnet/SC-devices
- ABT Site exports the certificates as files, extended by certificate signing requests (CSR) and hands these files over to that project’s CA
- The CA checks the authenticity of that request and signs the operational certificates. The CA then exports those properly signed certificates in a standardized file format and hands them back to ABT Site
- ABT Site re-imports the certificates and provides them to the Desigo devices
- For root certificates:
- ABT Site imports the external CA’s root certificate and checks its authenticity
- ABT Site provides the public part of the root certificate to all Desigo devices
ABT Site can handle CSRs created by external devices, such as Desigo CC.
That means that ABT Site can provide a root certificate file to Desigo CC, then import an operational certificate from Desigo CC, process its CSR, sign that certificate and export it back into a file format to be imported by Desigo CC.
Sign an external certificate signing request
- You have a certificate signing request from an external device, for example, Desigo CC.
- Go to Settings.
- Open the Certificates task.
- Select the BACnet/SC certificates tab.
- In the toolbar, click Sign external CSR.
- Select the external certificate signing request, and click Open.
- In the confirmation dialog, click Yes.
- Certificate requests from Desigo CC are now signed. A log entry is written in Settings > Root certificates > External CSR signing activities.