l
How to Use Datalogger Security Codes
l
How Can Data be Made More Secure on a CRBasic PakBus Datalogger
16.2.3 Creating a .csipasswd file
The data logger employs a security code scheme that includes three levels of security (see
(p. 104) for more information). This scheme can be used to limit access to a data
logger that is publicly available. However, the security codes are visible in Device Configuration
Utility. In addition, the range of codes is relatively small. To provide a more robust means of
security, Basic access authentication was implemented with the HTTP API interface in the form of
an encrypted password file named
.csipasswd
. Read/write access to the web interface
requires a
.csipasswd
file. The web interface provides access to real-time and stored data
logger data. For more information on the web interface, watch an instructional
NOTE:
Ethernet over USB (RNDIS) is considered a direct communications connection. Therefore, it is
a trusted connection and csipasswd does not apply.
When a file named
.csipasswd
is stored on the data logger CPU drive, basic access
authentication is enabled in the data logger and read/write access to the web interface can be
defined. Multiple user accounts with differing levels of access can be defined for one data
logger. Four levels of access are available:
l
None: Disable a user account.
l
Read Only: Data collection is unrestricted. Clock and writable variables cannot be changed.
Programs cannot be viewed, stopped, deleted, or retrieved.
l
Read/Write: Data collection is unrestricted. Clock and writable variables can be changed.
Programs cannot be viewed, stopped, deleted, or retrieved.
l
All: Data collection is unrestricted. Clock and writable variables can be changed. Programs
can be viewed, stopped, deleted and retrieved.
NOTE:
All levels of access allow data collection.
16. CR300 series maintenance
107