ABT Site as CA when using internal certificates
This example shows ABT Site as CA (certification authority). Only internal certificates are applied. The certificate color shows when a change is made in the workflow.
NOTICE

Devices do not work correctly if parameters or program structure are not correct
This can lead to high cost for reengineering and commissioning of plants or items
- Obtain the latest control program from the ABT Site project.
- Commissioning with the IP configuration is completed.
- Always first upload parameter data or control program on customer site.
- Always perform the first time a full download of the control program with BACnet/SC certificate. Afterwards, use Only updated certificates to update BACnet/SC operational and root certificates.
| Description |
1 | A root certificate (white) and an ABT Site operational certificate (green) are created at the time the ABT Site project is created. This root certificate can be valid until the expiry date is reached or if the customer requests a renewal of the root certificate (see step 7). Notes:
|
2 | The device operational certificate (pink) can be created after assigning the device to ABT Site. At this point, no certificate is loaded into the device. Configuring BACnet/SC with hubs, failover hubs and nodes. Note: Each device has its own operational certificate based on the serial number. Multiple use of a certificate is not possible. |
A full download is required for downloading the operational certificate. After the download, the device is operational with BACnet/SC. Note: In an existing project, a read-back of the current parameter and engineering data from the device is required. | |
The periodic renewal of the device operational certificates (yellow) must be planned in good time in advance. A reminder alarm from the device is sent 90 days before the certificate expires. It is recommended to budget this one year in advance. As soon as the date of the update of the certificates is determined, the update can be made in ABT Site. | |
Use Only updated certificates for updating the device operational certificate. | |
The renewal of the ABT Site operational certificate (gray) is possible at any time, independent of other devices in the BACnet/SC network because the root certificate is still the same and all devices trust certificates signed by that root. | |
If the IT department believes the existing root certificate to be compromised, or the ca. 30 years are over, a regeneration of the root certificate (white) is required. When regenerating the root certificate (dark-blue), all certificates on all devices in the project have to be renewed. This renewal process requires several steps in order to prevent any BACnet/SC communication interruptions during this process. For this reason, the existing root certificate becomes a temporary certificate and is valid until all devices are updated based on the new root certificate. | |
Use Only updated certificates for updating the device root certificate. After the certificate download, the device is operational with trust for both root certificates. | |
The renewal of the ABT Site operational certificate (blue) is possible at any time between step 7 and 12. If this step is not carried out, ABT Site will try to create a new operational certificate automatically in step 12. | |
Renewal of the device operational certificate (orange) based on the new root certificate (red) is required. Use Only updated certificates for updating the device root certificate (red). After the update, AS1 will have a certificate based on the new root. Because of steps 7 and 8, all devices trust certificates that are signed either by the old or the new root. Therefore the operation of the system is uninterrupted. | |
Renewal of the device operational certificate (orange) based on the new root certificate (red) is required. Use Only updated certificates for updating the device root certificate (red). After the update, AS2 will have a certificate based on the new root. Because of steps 7 and 8, all devices trust certificates that are signed either by the old or the new root. Therefore, the operation of the system is uninterrupted. | |
When all devices are updated with the new root certificate, the temporary root certificate in ABT Site must be deleted. Note: if a new ABT Site operational certificate has not yet been created, we will try to create it automatically. | |
Use Only updated certificates for updating the device root certificate (white) in the device. The old root certificate is deleted. This means that certificates signed by the old root will no longer be trusted by the BACnet/SC network. The renewal process has been completed. When certificates have expired or there is a new request from IT, these steps must be performed again from step 4 or 7. |