ABT Site as CA with 3rd party BACnet devices

This example shows ABT Site as CA (certification authority) for the BACnet/SC network. Internal certificates are applied to Desigo devices. Certificates for 3rd party devices have to be signed by the same CA (for example, the same ABT Site project), based on certificate signing requests provided by the 3rd party system. The certificate color shows when a change is made in the workflow.

info

The diagram shows the process with the same certificate validity length. If the 3rd party certificate is only valid, for example, for 1 or 2 years, the renewal of the 3rd party certificates is repeated several times before the Siemens certificates have to be renewed. This may lead to additional costs for Siemens and must be taken into account accordingly.

 

NOTICE

notice

Devices do not work correctly if parameters or program structure are not correct

This can lead to high cost for reengineering and commissioning of plants or items

  1. Obtain the latest control program from the ABT Site project
  2. Commissioning with the IP configuration is completed.
  3. Always first upload parameter data or control program on customer site.
  4. Always perform the first time a full download of the control program with BACnet/SC certificate. Afterwards, use Only updated certificates to update BACnet/SC operational and root certificates.

 

 

Description

1

A root certificate (white) and an ABT Site operational certificate (green) are created at the time the ABT Site project is created. This root certificate can be valid until the expiry date is reached or if the customer requests a renewal of the root certificate (see step 16).

Notes:

  • The root certificate is bound to the ABT Site project and not to the computer environment.
  • In a multi-project scenario, project A must be defined as a CA and the certificate imported into project B.

2

The device operational certificate (pink) can be created after assigning the device to ABT Site. At this point, no certificate has be loaded into the device.

Configuring BACnet/SC with hubs, failover hubs and nodes.

Note: Each device has its own operational certificate based on the serial number. Multiple use of a certificate is not possible.

3

A full download is required for downloading the operational certificate. After the download, the device can be operational with BACnet/SC.

Note: In an existing project, a read-back of the current parameter and engineering data from the device is required.

4

The “certificate signing request” (csr) that is received from the 3rd party system is signed by ABT Site as CA, to create the BACnet operational certificate for that device. Each individual device has its own operational certificate that must be signed by ABT Site.
Note: Do not underestimate the administrative effort involved in this step.

5

The signed operational certificate is sent back to the 3rd party system or installer as a P12 container and/or as a PEM file.

Note: When the vendor is using a PEM format, the root certificate and the signed device certificate must be loaded into the device. Depending on the vendor, different certification processes can be used. For this reason it is not discussed in detail here.

6

If the 3rd party system cannot extract the root certificate from the container, the root certificate must be sent to the 3rd party manufacturer or installer.

7

The ABT Site signed certificate is imported into the 3rd party device. In this case, the 3rd party manufacturer must import its certificate with the root certificate into the 3rd device. This process is outside of the scope of ABT Site.

8

Shows the state in which the entire project is operational with BACnet/SC. Step 9 or 16 may become necessary as time progresses.

9

The periodic renewal of the device operational certificates (yellow) must be planned in good time in advance. A reminder alarm from the device is sent 90 days before the certificate expires. It is recommended to budget this one year in advance. As soon as the date of the update of the certificates is determined, the update can be made in ABT Site.

Note: The 3rd party device will not send any alarm.

10

Use Only updated certificates for updating the device operational certificate.

11

The renewal of the ABT Site operational certificate (gray) is possible at any time, independent of other devices in the BACnet/SC network because the root certificate is still the same and all devices trust certificates signed by that root.

12

See description in step 4.

13

See description in step 5.
Note: If the 3rd party device does not support a P12 certificate type, the root certificate does not have to be sent again because the same root certificate is still used.

14

The ABT Site signed certificate is imported into the 3rd party device by the manufacture.

15

Shows the state in which the entire project is operational with valid BACnet/SC certificates.

16

If the IT department believes the existing root certificate to be compromised, or the formal lifetime of the root certificate comes to an end, a regeneration of the root certificate (white) is required. When regenerating the root certificate (dark-blue), all certificates on all devices in the project have to be renewed (note that this applies system-wide, that is: also on any potential 3rd party BACnet/SC devices of a project, too). This renewal process requires several steps in order to prevent any BACnet/SC communication interruptions during this process. For this reason, the existing root certificate becomes a temporary certificate and is valid until all devices are updated based on the new root certificate.

17

Use Only updated certificates for updating the device root certificate. After the update, the device remains operational with trust for both root certificates.

18

The renewal of the ABT Site operational certificate (blue) is possible at any time between step 16 and 23. If this step is not carried out, a new ABT Site operational certificate will automatically be created in step 23 at the latest.

19

Renewal of the device operational certificate (orange) based on the new root certificate (red) is required. Use Only updated certificates for updating the device root certificate (red). After the update, AS1 will have a certificate based on the new root. Because of steps 16 and 17, all devices trust certificates that are signed either by the old or the new root. Therefore, the operation of the system is uninterrupted.”

20

See description in step 4.
Note: The 3rd party certificates must be replaced in a timely manner with the replacement of the certificates in the devices. If steps 24 and 25 are performed before all certificates have been replaced, there may be problems with data exchange between devices.

21

See description in step 5.

22

See description in step 6.

23

The ABT Site signed certificate is imported into the 3rd party device by the manufacture.

24

When all devices are updated with the new root certificate, the temporary root certificate in ABT Site must be deleted.
Note: if a new ABT Site operational certificate has not yet been created, a new one will be created automatically.

25

Use Only updated certificates for updating the device root certificate (white) in the device. The old root certificate is deleted. This means that certificates signed by the old root will no longer be trusted by the BACnet/SC network. The renewal process has been completed. When certificates have expired or when there is a new request from IT, these steps must be performed again from step 9 or 16.