5. Device Concept
UCX series – User's Manual
41
Applied firmware package: v1.2.0b9 | LDC software: v2.5.10b1
User
#new
▪
The switcher can manage one user (with fixed username: admin) with full access.
Password
▪
No password is set for default, the authentication can be enabled after setting a password. The old
password is not necessary for modifying.
▪
The following characters are allowed: Letters (A-Z) and (a-z) and numbers (0-9). Max length: 100
characters.
▪
The device does not store the password string, so it can not be queried.
▪
The password can be reset by calling factory defaults (
Reset to Factory Default Settings
).
Follow the instructions to set the authentication:
Step 1.
Set the password with Lightware Device Controller software (
) or LW3 protocol command
Set Password for Authentication
Step 2.
Enable the authentication on the chosen port (HTTP: 80 or HTTPS: 443) with Lightware Device
Controller software (
) or LW3 protocol command (
).
Step 3.
Restart network services.
ATTENTION!
The password will not be encrypted by this authentication mode, it remains accessible when
the communication happens on HTTP.
5.7.3.
Encryption (HTTPS, WSS)
HTTP protocol uses clear text format for data transport. This method allows a third-party to listen in and
eavesdrop on the transferred information.
HTTP request-response
To ensure the secure data transmission, the HTTP port (80) can be disabled, and the all the information can
be transferred via HTTPS (443 port). HTTPS protocol encrypts the clear text, so it becomes incomprehensible
for a third-party and keeps the data secure.
HTTPS request-response
#new
The same services are available on HTTPS than HTTP (for the detailed service list, see
section).
▪
The
UCX series switcher generates a self-signed certificate, so the user does not have to deal with
the configuration.
▪
New certificate is generated after the hostname changing or restoring the factory default settings.
▪
Please ensure proper UCX time and date setting in UCX because it affects the self-signed certificate
(SSL) generation when using WSS or HTTPS. Improper time and date setting may lead to certificate
rejection.
ATTENTION!
HTTPS does not guarantee that the communication is secure. Make sure that the client
communicates with the server directly, without any third-party element in the communication route
(Man-in-the-middle attack).
Basic Security System Example
To keep the system protected, the unsecured ports should be disabled and manage the data traffic to the
secured channels.
Step 1.
Disable the Ethernet layer of the USB-C ports towards the laptops. The video and USB data transmission still work.
The setting is available with the following ways:
▪
Lightware Device Controller software (see the details in
section)