Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.




Scroll ignore Scroll ignoreArticle statuskb-articleINLINE

Greenexternal  

Link to be provided outside of Bosch

kb-articleINLINE

Yellowinternal

Internal document. This article cannot be provided outside of Bosch.

Step-by-step guide

New behavior

Configuration Manager 7.60 by default will only trust CA signed certificates.

CM has default Access / Security set to:

  • Encrypted Communication: Required = Only HTTPS connects are permitted.
    • Other options:
    • Preferred = will suggest HTTPS first – possible to change connection method to HTTP or RCP+
    • Optional = will suggest HTTP – possible to change connect method to HTTPS or RCP+
  • Certificate requirement: Trusted = CM 7.60 only trusts CA signed Certificates.
    • Other options:
    • Valid = As long as the Certificate is valid
    • None = Does not check the certificate on the device
    • Issued by this CA = Only if CM on local PC created the CA

Changing the security requirements will change the behavior of how CM displays the connection/access. You may need to Close the application and reopen to get the new settings to take effect!

All IP Camera's Produced with FW 6.60 or newer since ~2019 come with a factory installed Device Certificate and has HTTPS set for the Usage by default.

  • These devices will automatically be trusted by CFM.
  • The device will be shown with a Green Icon.

See at the bottom for:

  • BVMS dependency
  • DIP dependency

Any additional added Certificates must be signed by a CA,


If Devices are to old to upload certificates or Device does not have a Factory installed Certificate the device will show up in RED color with an Error (pop-up message at the Icon) Remote certificate name mismatch

  • CFM offers the possibility to Add a Session Exception, this will allow continued configuring of the device till the CFM Application is closed.

After Confirming the security exception, the icon will change to Orange with an Alert



Below you see the device does not have the Factory install Device Certificate.


Below you see the same device after loading a CA signed Cert, Icon changes to Green with no Warning or Error.

  • Note My MicroCA certificate is located on my local PC (Personal Certificate Store), any other PC would not trust this.

Below you see a device that does not have any Security options - No Certificates!


BVMS Dependency:

If CFM 7.60 is installed on a PC which has BVMS Cc, the Security requirements settings of CM affect BVMS Cc behavior.

(BVMS and CM share some files ?? e.g. "AppConfig")

  • Suggest to change in CM - Encrypted Communication to Preferred

DIP Dependency:

When Encrypted Communication is set to Required, it will not be possible to configure the target (Targets do not support "HTTPS only" as they work on iSCSI only)

  • Suggest to change in CM - Encrypted Communication to Preferred
Scroll ignoreadvancedINLINEgreenINLINE

MANDATORY --> after finishing this article, if you wrote advanced content in this section , you must to manually add the "advanced" label  This action is required to indicate that this article contains ADVANCED instructions for CTS/ SG or GK.

DO NOT CHANGE ANYTHING IN THIS SECTION!

advanced section
Please contact CTS / SG or GK team to view this section from draft space, if necessaryadINLINE

IMPORTANT! --> the content itself from here will be not displayed. The content from here will be displayed only when the "ad" label will be set after article creation. Only CTS/ SG or GK are allowed to use "ad" label.

PLEASE do not set "ad" label from beginning. Use it only when you need this info and REMOVE the "ad" label when finished!

Information below is for CTS, SG, GK reference and must be kept internal only.

If you are part of CTS, SG or GK team, please hide this section when you have finished using this article!

DO NOT CHANGE ANYTHING IN THIS SECTION!

This section will not be published externally and / or automatically downloaded in the PDF file!

Type your text/ advanced information here

Please write here the statement/answer/explanation

Add pictures, if necessary





Scroll only
scroll-pdftrue
scroll-officetrue
scroll-chmtrue
scroll-docbooktrue
scroll-eclipsehelptrue
scroll-epubtrue
scroll-htmltrue


You are using an Offline Version of these Article, please ensure to regularly check the corresponding online article on the Bosch Building Technologies Knowledge Base for any updates. Use the date and version information of the document as reference.

This is  created  

Check for Updateprimaryhttps://community.boschsecurity.com/t5/Bosch-Building-Technologies/ct-p/bt_community