Page | 564
o
TLS_RSA_WITH_AES_256_SHA,
o
TLS_RSA_WITH_AES_128_SHA2,
o
TLS_RSA_WITH_AES_128_SHA,
21.6.1.6Verify
Whether or not client/server authentication should be performed on the peer:
•
The certificate must be valid
•
The certificate must be signed by a CA (see #d. CA Certificates), through a certificate
path, which is known to ISY
Care should be taken when Verify is checked for Server Settings. In this case, all clients
(including browsers and mobile devices) must provide ISY with a valid certificate. This
might not be optimal in normal operations since most browsers/mobile devices do not
offer any certificates and thus ISY may not be reachable over HTTPS.
Care should also be taken when Verify is checked for Client Settings. In this case all
communications initiated from ISY to external HTTPS resources shall be validated. This
might cause problems with Portals (such as MobiLinc) and Network resources which
communicate with devices that do not have valid certificates. This may also interfere with
SMTP operations that require TLS.
In short
–
and unless you have explicit requirements, such as OpenADR
–
then it’s best to
keep Verify unchecked.
21.6.1.7CA Certificates
In order for Verify (Client/Server Authentication) to work, you will need to import
Certificate Authority signing certificates into ISY.
Please note that if you would like to support a certificate that goes through a chain to reach
the root signing certificate, then you must import all the certificates in the chain and all the
way up to the root.
To import CA Certificates, click on the CA Certificates button and then click on Import to
import CA certificates (see below).
Summary of Contents for ISY-994i Series
Page 1: ...The ISY 994i Home Automation Cookbook ...
Page 35: ...Page 12 Figure 6 UDAjax Main Screen ...
Page 36: ...Page 13 Figure 7 UDAjax Devices Scenes Screen ...
Page 68: ...Page 45 Figure 44 NodeServer Configuration popup 5 2 5 Tools Menu Figure 45 Tools Menu ...
Page 102: ...Page 79 6 6 3 2Activate My OpenADR Portlet Figure 77 OpenADR My OpenADR Menu Option ...
Page 103: ...Page 80 6 6 3 3Configure OpenADR Settings Figure 78 OpenADR Settings Menu Option ...
Page 104: ...Page 81 Figure 79 OpenADR Settings Display ...
Page 108: ...Page 85 6 6 3 7Issue an Event Figure 84 OpenADR Issue and Event ...
Page 110: ...Page 87 Figure 86 OpenADR Event Viewer ...
Page 116: ...Page 93 Figure 92 ElkRP2 Account Details M1XEP Setup Button In the M1XEP Setup Window ...
Page 267: ...Page 244 Figure 189 State Variables ...
Page 268: ...Page 245 Figure 190 Programs and Folders ...
Page 292: ...Page 269 Figure 192 Irrigation Folders Figure 193 Irrigation Devices ...
Page 376: ...Page 353 Figure 209 Save Topology File ...
Page 433: ...Page 410 Figure 242 X 10 recognized as Living Room East Device ...
Page 540: ...Page 517 Figure 357 In Car Detection 12 Figure 358 In Car Detection 13 ...
Page 602: ...Page 579 Figure 382 SecureCRT SSH Raspberry PI Session ...
Page 685: ......