FAQ BACnet/SC

 

 

Questions:

  • Can I commission a network directly as BACnet/SC?
  • Can I subsequently put a device into operation directly as BACnet/SC?

Answer: No

A BACnet/SC network must always be commissioned as an IP network first. In an existing BACnet/SC network, a new device or a device to be replaced must always be commissioned as an IP device first. Be aware, that there is a security gap within this network at the time of this commissioning.

Question:

What happens if I have activated the Disable BACnet/IP option for a device in the BACnet/SC network?

Answer:

All devices communicate and data exchange is guaranteed. However, there is a security vulnerability in the device that has IP enabled. Thus, the network is no longer a BACnet/SC network that guarantees 100% security.

Question:

Can I only configure a part of a system as a BACnet/SC network?

Answer:

A change to a BACnet/SC network can be done in stages. However, it is advisable to always convert an entire sub-area within a hub or floor. The areas that have not been converted are still a potential risk of a hacker attack.

Question:

What are the unique (and permanent – are there any permanent ones) identifiers in ABT Site project settings that ABT Site uses to automatically create the root certificate when ABT Site is the internal/self-signed CA?

Answer:

All ABT Site projects have the so called unique UUID (universal unique identifier) which is set when they are created. The root certificate is bound to that, also meaning certificates are always bound to a project not to a particular ABT Site installation.

Question:

What are the unique and permanent identifiers (besides device serial number and perhaps NIC MAC address) of the embedded devices that ABT Site uses to create the operational certificates when ABT Site is the internal/self-signed CA?

Answer:

The unique identifier that is used is the serial number, so certificates are issued to a particular device and cannot be transferred. The certificate also contains "FullyQualifiedDomainName" (i.e. domain + hostname) for DHCP-devices, or the IP-Address for non-DHCP devices.

Questions:

  • What device configuration changes (which objects/properties) would require new operational certificates to be generated for embedded devices (PXC, DXR, etc.,)? Changing network config from IP to DNS?
  • Device name property?

Answer:

As previously stated serial number and FQDN/IP is used. The need to reissue a certificate will come when you re-configure your network (so that hostname and/or IP changes) , or when you have to, for example, replace a broken controller.

Questions:

  • Are BACnet/SC certificates stored as part of the ABT Site project?
  • If I archive an entire project, are the certificates included in the archive?
  • Can that archive be opened by another ABT Site installation?

Answer: Yes.

Certificates are a part of the project they will be transferred with it. As long as you have the needed credentials you can open the project with another ABT Site installation. They are of course encrypted so unless you have the username and password you cannot access them.

Questions:

  • When a new technician needs access to a site which has been configured for BACnet/SC and BACnet/IP UDP ports are all closed, how do they get access when ABT Site is the internal/self-signed CA?
  • Do they need a copy of the entire archived ABT Site project?
  • Can they simply get an export of the Root certificate only from the original project and import into their ABT Site installation?

Answer:

For security reasons the root cannot be exported. There are two ways to access those devices. Pack and go will provide the needed operational certificates, since pack and go is also password protected.

The second method I to issue a certificate signing request from the second ABT installation. The original project then can sign it and give back the signed operational certificate, like what we internally do for the controllers.

Questions:

  • How securely are BACnet/SC certificates stored in ABT Site project folders?
  • Are they in an encrypted folder?
  • What would have to be done to further harden ABT Site in this use case?

Note: This is a question for internal/self-signed use cases when ABT Site resides in IT/building operations office. ABT Site installation could be “hardened” by having strong login credentials on the machine, strong password on the ABT Site project itself, as well as restricted physical access to the room where the machine with ABT Site resides.

Answer:

Everything is indeed encrypted, and the solution has been reviewed and synchronized with Siemens standards of security. For certificate storage we use the same mechanisms that are also used to protect data to access the controller and the project itself (for example, the mechanism that protect username/password data).

Questions:

  • Do BACnet/SC certificates work with pack and go/pack and return?
  • How are certificates handled with pack and go/pack and return workflows?

Answer:

Yes, it works.

The package contains the root and all operational certificates created with the exported devices. You can create new devices, create certificates for them and return when needed. No changes in the workflows are introduced because of the certificate management. On pack and return all data will be merged back except if you have made changes on the root certificate, this will be then ignored as it will otherwise mess with the existing data.

Questions:

Is it possible to remove a valid certificate from the device?

Answer:

The device must be cleared and a fake certificate must be assigned.
See the chapter Configure and download and read the section “Additional information required for clear device and clear application commands”.