Failed certificate validation

All system components should use secure communication. Since each station (Supervisor and remote controller) can serve as both a client and a server, each station requires a root CA certificate in its User Trust Store and a server certificate signed by the root CA certificate in its User Key Store. Each connected device, such as a camera may also require a server certificate signed by a root CA certificate.

Failure to add or join

An attempt to add or join a remote station to a Supervisor station is an example of a server (the remote station) connecting to a client (the Supervisor station). If the remote controller station does not have a server certificate signed by a root CA certificate in the Supervisor station’s system or user trust store, the add or join fails and one or more error messages appear in the Remote Config window.

Figure 38.   Foxs requires certificate approval for station join or add
Image

If you get this message because the remote station presented its self-signed certificate, you may approve the certificate and the add or join may complete, but a better solution is to figure out why the remote station presented its self-signed certificate or, if it presented a signed server certificate, why the root CA certificate that signed the server certificate is missing from the Supervisor station’s system or user trust store. Import the correct certificates into each station’s trust store and attempt the add or join again.

 NOTE: Relying on a self-signed certificate provides encryption only. It cannot verify server identity, which is required to prevent man-in-the-middle attacks. 

Failure to connect to a remote camera

A browser connection between a local station and a camera requires a secure connection. The browser, serving as a client to a remote camera, requires the root CA certificate in its trust store that signed the server certificate in the remote camera.

If these certificates are not in place, the camera will not connect to the browser, and through the browser to the station. Refer to the “System Security” chapter in this document for how to work with certificates.