Control Station Duetto
WebConfig configuration
1.7/1217
103
Shared administration: CERTIFICATES
In this section, a trusted identity can be set up for the DUETTO device in order to establish a secure
HTTPS connection between a web browser and the WebConfig of the DUETTO device.
The bct CA certificate, based on the X.509v3 standard (defined in RFC 5280), is a public key certificate
that includes the digital identity that is used to verify the validity of certificates. This bct CA certificate
can be imported in a web browser in order to guarantee a trusted identity of DUETTO devices. When
accessing the WebConfig, the web browser checks the digital signature of the server certificate (offered
by the DUETTO device) using the bct CA certificate (“chain of trust”). When the trusted identity is con-
firmed, a secure HTTPS connection is established without asking to trust the server certificate.
It is also possible to upload a custom server certificate to the DUETTO device. In this case, the bct CA
certificate is not used anymore to guarantee a trusted identity. It is recommended to import the corre-
sponding CA certificate into the web browser.
GOOD TO KNOW: What is a CA certificate?
A certificate authority (CA) certificate certifies the ownership of a public key by the named subject of
the certificate. This allows the device to rely on signatures or assertions made about the private key that
corresponds to the certified public key. In this model of trusted relationships, a CA is a trusted third par-
ty – trusted both by the subject (owner) of the certificate and by the party relying upon the certificate.
In detail, the authentication mechanism works as follows:
1. The “Certificate Authority” (CA) signs the server and client certificate. When using the bct CA certif-
icate, this step is already completed.
2. Optionally, a custom server certificate can be uploaded to the DUETTO device. In this case, the bct
CA certificate is not used anymore.
3. The client certificate can be imported in a web browser in order to guaranty a trusted identity of
DUETTO devices when accessing the web browser.
4. When accessing the WebConfig, the web browser checks the digital signature of the server certifi-
cate using the bct CA certificate.
1.4