BACnet/SC certification management in the projects
The process shows the phases from project creation to a service life, that may span over 30 years. This means that various certificates have to be renewed and replaced over time. The different colors illustrate when and where they are created, and where they are loaded. When a certificate renewal is due, a parameter upload or a program upload must first be performed.
ABT Site supports several topologies with internal or external certificates, both with ABT Site or an external issuing authority as the single trust root for the whole BACnet/SC network:
- For a project that will use an external certificate authority, a certificate signing request must be created in ABT Site per BACnet/SC device. The signed certificates then can be imported back in ABT Site. If required, the external common root CA certificate can be imported separately. Certificates will be provided to all BACnet/SC devices on download.
- In case of larger sites or if communication between BACnet/SC and non-BACnet/SC devices is needed, BACnet routing between the networks must be properly configured. By default all hubs are configured as BACnet/IP to BACnet/SC routers. The default setting can be disabled.
- For a project that will use ABT Site as certificate authority a common root CA certificate will be automatically created and provided to all BACnet/SC devices on download. The same will happen with operational certificates.