background image

Managing Certificates

Trusted certificates are used by the device to authenticate other servers and clients to which it needs to
connect, and to secure those connections. Avigilon provides a self-signed Web Certificate to secure the
connection to the ACC ES Admin Web UI and to the WebEndpoint service, and a set of system-level signed
certificates from well-known trusted CAs to ensure secure connections to any needed servers. Optionally,
you can provide your own certificates and CAs.

The level of security provided by the certificates included with the device should be sufficient for any
organization that does not deploy a Public Key Infrastructure (PKI) on its internal servers.

The certificate management feature on the appliance controls only the appliance web certificate used by
the ACC ES Admin Web UI and the ACC WebEndpoint product. Within the ACC server the certificate
authorities configured by this feature are only used to validate secure email servers used by ACC Email and
Central Station Monitoring features. ACC Server to ACC Server and ACC Server to ACC Client connections
are not controlled or validated using the appliance certificate management feature.

For example, if your organization uses a public email server such as Google Mail, when email notifications
are triggered, ACC accesses the Google Mail server and receives a certificate identifying the Google Mail
server. The ACC software verifies the certificate by confirming the CA that signed the Google Mail
certificate is from the list of well-known trusted CAs, and the connection is secured.

Note:

The signed certificates shipped with the device are the same as those shipped with Mozilla's

browser, and are publicly available from

The Debian Project

The certificates allow SSL-based

applications to check for the authenticity of SSL connections. Avigilon can neither confirm nor deny
whether the certificate authorities whose certificates are included with this appliance have in any
way been audited for trustworthiness or RFC 3647 compliance. Full responsibility to assess them
belongs to the local system administrator.

Organizations that deploy their own PKI can use the Certificates pane of the ACC ES Admin Web UI to
manage certificates on the device.

For example, you can:

l

Replace the default self-signed Web Certificate with your own organization's certificate.

l

Add CAs, such as internal CAs used within your organization, to the device.

l

Disable (and enable) any of the system-level CA certificates.

Replacing the Web Certificate

Manage the device's Web Certificate from the Web Certificate tab on the Certificates pane. The
ACC ES Admin Web UI and the WebEndpoint service use this certificate to authenticate themselves to
devices that connect to them. Only one Web Certificate can be active at any time.

You can replace the default Web Certificate with a custom certificate.

Managing Certificates

23

Summary of Contents for AVIGILON ACC VMA-RPO-4P2

Page 1: ...User Guide Avigilon ACC ES HD Recorder VMA RPO 4P2 and VMA RPO 4P4 ...

Page 2: ...iled and published using product descriptions and specifications available at the time of publication The contents of this document and the specifications of the products discussed herein are subject to change without notice Avigilon Corporation reserves the right to make any such changes without notice Neither Avigilon Corporation nor any of its affiliated companies 1 guarantees the completeness ...

Page 3: ... Settings 11 Monitoring the Storage Drive State 13 Connecting the Device to Users and Cameras 13 Assigning a PoE Power Budget 14 Providing Device Logs for Support 16 Installing and Starting the ACC Client 17 Connecting to ACC Software and ACS 17 Activating and Configuring ACC Software 18 Connecting to Avigilon Cloud Services 18 Starting Up and Shutting Down the ACC Client Software 18 Connecting to...

Page 4: ...he Reset Button 28 Restarting the System 28 Restoring Factory Default Settings 28 Troubleshooting 30 Cannot Discover the Device 30 Network Configuration 30 Checking System Health 30 For More Information 31 iv ...

Page 5: ...eo surveillance system hardware A UPS system is used to protect critical equipment from mains supply problems including spikes voltage dips fluctuations and complete power failures using a dedicated battery It can also be used to power equipment during the time it takes for a standby generator to be started and synchronized Any UPS connection must include configuration to shut down the operating s...

Page 6: ... operations For more information see LED Indicators on page 20 Rear View 1 Corporate network uplink port Accepts a 1GbE Ethernet connection to the general network to allow users access to the web interface and connected camera video 2 Camera network uplink port Accepts a 1GbE Ethernet connection to the cameras that are connected to the PoE switch Overview 2 ...

Page 7: ...Mozilla Firefox browser version 3 6 or later l Google Chrome browser 8 0 or later l Microsoft Edge browser 25 or later l Safari 5 0 or later l Chrome on Android 2 2 or later l Safari on Apple iOS 5 or later l Windows Internet Explorer browser version 7 0 or later Note Your web browser must be configured to accept cookies or the web interface will not function correctly Supported Network Configurat...

Page 8: ...nf IP addresses Camera LAN Uplink only Yes Unconnected leave as DHCP Static DHCP assigned DHCP Zeroconf Corporate and Camera LAN Uplink via Camera LAN Uplink only Static DHCP assigned DHCP Zeroconf Static DHCP assigned DHCP Zeroconf Corporate and Camera LAN Uplinks must be on different subnets Supported NetworkConfigurations 4 ...

Page 9: ...dicators display the correct status See LED Indicators on page 20 for more information 2 If you are configuring the device with a static IP address connect a DHCP enabled port on your configuring laptop with an Ethernet cable directly to the camera network eth0 port on the device Otherwise connect the device to the corporate network using the corporate network eth1 port 3 On the connected laptop o...

Page 10: ...rom Certificate Authorities CAs that are not provided with the device can be added and the signed certificates from CAs for public servers such as Google Mail that are provided with device can be disabled For more information see Managing Certificates on page 23 7 When you are prompted by the Web Interface enter a new password for the administrator username The Strength meter measures the complexi...

Page 11: ...e device to the corporate network port b Disconnect the configuring laptop from the camera network port 12 Connect the cameras to the PoE ports For more information about the Web Interface see Configuring the Recorder on page 8 You are now ready to install the ACC Client software and connect the ACC ES HD Recorder to an ACC site You can then configure the device and cameras for daily operation thr...

Page 12: ...station with network access to the device The first time you access the ACC ES Admin Web UI of your device use one of the following methods l Discovering the Device 1 Open the Network tab in File Explorer Windows or Finder Macintosh to locate the device You are looking for a network device labeled VMA RPO 4Px serial number 2 Right click and select View Device Webpage to open the device sign in pag...

Page 13: ...device is restarting The panel provides technical information about your device product name part number serial number and firmware version Use the menu options under Services and System in the Dashboard navigation bar to access all the other web interface panels l Services Expand ACC in the left sidebar to navigate to l The Server page to control the ACC Server on the device See Managing ACC Serv...

Page 14: ...General pane To Do this Shut down all the services before you shut down the device Click Stop Start up all the services after they have been shut down Click Start Format the storage drive Click Reinitialize to delete all configuration and recorded video data l Network Storage Management pane To allow users to archive video from this device using the ACC Client software 1 Click Enabled 2 From the P...

Page 15: ...esolve an issue By default the page displays 100 warning messages from the logs Typically Avigilon Technical Support assists you to access and filter the logs on this panel to isolate the logs that they require You then copy and paste the logs into a text file save it and send it to Avigilon Technical Support You can filter the logs to display the information that you need 1 In the drop down list ...

Page 16: ...nd configuration data if you forget your password To reset the administrator password you must reset the device to the factory default settings This will also format the hard drives and delete the configuration data and recorded video For more information on performing a factory restore see Restoring Factory Default Settings on page 28 l Time pane to customize how the device keeps time l Select yo...

Page 17: ...form any of the following actions in the pane in the Storage panel To Do this View the capacity and status of the storage drive When the device is l Correctly working Ready and is displayed l Not correctly working Error and is displayed View details about the drive 1 Click the in the upper right of the pane to open the storage details pane 2 Click the to display details about the drive including i...

Page 18: ...ngs In each of the panes in the Network panel toggle Automatic IP on to discover connected networks automatically the default setting or off to manually specify the connections Enter the appropriate values in the following fields if you are manually entering the connection settings l IP Address l Subnet Mask l Default Gateway Click Apply to save your changes Set how the device obtains a named addr...

Page 19: ...hange the Power setting to Auto or Manual Tip Devices that support both PoE and PoE 802 3at modes of operation can be forced into non PoE mode 802 3af by using a manual 15W budget Use the Power bar for each port to configure a PoE power budget l Click Off to disable power output to the port When power to a port is disabled the port no longer outputs power but can act as a standard network connecti...

Page 20: ...uire You then copy and paste the logs into a text file save it and send it to Avigilon Technical Support You can filter the logs to display the information that you need 1 In the drop down list select the type of application log that you need The options are o System Logs o Boot Logs o Web Server Logs 2 In the Maximum Logs drop down list select the number of log messages you want to display each t...

Page 21: ...access to the Internet 2 Download the ACC Client software from the Avigilon website avigilon com support software Click through to the installation software for the latest version of the ACC Client software Note The first time you access the web site from which you download the software you will be prompted to register Enter all of the required information and click Complete Registration Your regi...

Page 22: ...bilities and features that provide centralized access across distributed systems To connect your site to Avigilon Cloud Services see help avigilon com cloud For information about the cloud services see Avigilon Cloud Services Support Starting Up and Shutting Down the ACC Client Software To open the ACC Client software l Double click the desktop shortcut icon l In the Start menu select All Programs...

Page 23: ...inals are open when inactive Maximum load is 30 V 2 A or 200 V 250 mA 2 OUT 2 3 Ground GND 4 OUT 1 Relay Output Form A dry contact outputs When active terminals are connected Terminals are open when inactive Maximum load is 30 V 2 A or 200 V 250 mA 5 OUT1 6 GND 7 IN 4 Alarm In Active Low inputs To activate connect the Input to the Ground pin GND To deactivate leave disconnected or apply between 3 ...

Page 24: ...er Ethernet PoE power Orange Camera is only using the switch for a network connection Orange slow blinking l One port l All ports System over power budget warnings For more details review the PoE panel in the Web Interface Port off due to system over PoE power budget System over PoE power budget For more information see Assigning a PoE Power Budget on page 14 and Viewing PoE Port Status on page 9 ...

Page 25: ...el LEDs Icons LED Status Description Green Network activity is present Orange On for GigE speed Off for 10 100 speed Green Network activity is present Orange On for 100M speed Off for 10M speed BackPanelLEDs 21 ...

Page 26: ...ou must also account for potential power loss in the cable Unless the amount of power loss in the cable is known use the following estimates l If the device uses less than or equal to 16 W expect 2 5 W of power loss l If the device uses more than 16 W expect 4 5 W of power loss To calculate the recommended power budget for each port use the following equation Power budget Camera power consumption ...

Page 27: ...ves a certificate identifying the Google Mail server The ACC software verifies the certificate by confirming the CA that signed the Google Mail certificate is from the list of well known trusted CAs and the connection is secured Note The signed certificates shipped with the device are the same as those shipped with Mozilla s browser and are publicly available from The Debian Project The certificat...

Page 28: ...r does not accept the CSR use the certificate issuer s preferred method to generate the CSR 2 After you receive the crt file containing the new certificate from the certificate issuer save it to a location accessible to the device 3 Upload the new certificate to the device a Open the Web UI click Device in the navigation bar and scroll down to the Certificates pane b On the Web Certificate tab cli...

Page 29: ...known trusted CAs to the ACC software when it tries to access the mail server The certificate cannot be verified unless a certificate signed by that CA is uploaded to the User Certificate Authorities tab of the Certificates pane If you are required to upload a signed certificate from a CA complete the following steps 1 Open the Web UI click Device in the navigation bar and scroll down to theCertif...

Page 30: ...s Otherwise from a workstation connected to the Internet navigate to partners avigilon com and download the appropriate ACC ES firmware 2 Save the file to a location accessible to the ACC ES Admin Web UI To upgrade the firmware from the ACC ES Admin Web UI 1 Navigate to the Device panel 2 If necessary scroll to show the Upgrade Firmware pane 3 Use one of these methods l Drag and Drop 1 Use Windows...

Page 31: ... during the upload and verification phase Click Cancel upload before the file has uploaded Note If an error occurs during the upload phase or the upgrade process or if the firmware becomes corrupted you are prompted to remove the file Upgrading the Firmware 27 ...

Page 32: ...from the physical recorder l Using a straightened paperclip or similar tool gently press and release the reset button CAUTION Do not apply excessive force Inserting the tool too far will damage the recorder and void the warranty Important Do not hold down the reset button for too long or you will revert to the factory default settings Restoring Factory Default Settings If the ACC Server software n...

Page 33: ...ly press and hold the reset button CAUTION Do not apply excessive force Inserting the tool too far will damage the recorder and void the warranty 2 Do not release the button until the LED is orange and starts to blink Restoring Factory Default Settings 29 ...

Page 34: ... see Installing and Starting the ACC Client on page 17 2 Log into the site that uses this naming convention VMA PRO 4Px serial number Note The username and password for the Web Interface application is separate from the administrator username and password for the ACC Server 3 Display the server Setup tab At the top of the window the recorder IP address is displayed 4 Open a web browser and enter t...

Page 35: ...Information For additional product documentation and software and firmware upgrades visit avigilon com support Technical Support Contact Avigilon Technical Support at avigilon com contact For More Information 31 ...

Page 36: ...al Support Avigilon warranty terms for this product are provided at avigilon com warranty Warranty service and technical support can be obtained by contacting Avigilon Technical Support avigilon com contact For More Information 32 ...

Reviews: