2.8.3 How to configure HTTPS settings
The settings relating to the HTTPS protocol that can enhance the network security by encrypting the access to cameras on this page.
HTTPS settings can be configured by either using the certificate pre-installed to the camera, or using a CA certificate that you obtained by yourself from the CA (CA: Certification Authority). The settings will be configured in the following procedure.
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
When using a pre-installed certificate:
 
When using a CA certificate:
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
When a pre-installed certificate is selected
 
 
 
When a CA certificate is selected
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Generate CSR (Certificate Signing Request)
 
 
 
 
 
 
Apply for the approval and the issue of CA certificate by CA
 
 
 
 
 
Obtain the root certificate
 
Install the CA certificate
 
 
 
 
 
Configure HTTPS connections
 
 
 
 
 
Access a camera using HTTPS
 
Access a camera using HTTPS
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
When a pre-installed certificate is selected
 
 
 
 
 
When a CA certificate is selected
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Configuring the HTTPS connection (→2.8.3.3 Configuration of HTTPS connections)
Obtain the root certificate (→2.8.3.2 Obtaining the root certificate)
Generation of the CRT key (SSL encryption key) (→2.8.3.4 Generation of the CRT key (SSL encryption key))
Generation of CSR (Certificate Signing Request) (→2.8.3.5 Generation of CSR (Certificate Signing Request))
Install the CA certificate (→2.8.3.6 Installation of the CA certificate)
Note
To use the CA certificate, you need to apply for the approval and the issue of CA certificate by CA.
2.8.3.1 Select the certificate to use when accessing with HTTPS
Select the certificate to be used with HTTPS with [HTTPS – Select certificate].
When using a pre-installed certificate: Select “Pre-installed”.
When “Pre-installed” is selected, a root certificate (2.8.3.2 Obtaining the root certificate) must be obtained.
When using a CA certificate: Select “CA”.
Note
“CA” can only be selected when a CA certificate has been added. Refer to 2.8.3 How to configure HTTPS settings for information on how to add a CA certificate.
2.8.3.2 Obtaining the root certificate
This procedure only needs to be done once for each PC that accesses the camera.
1.
Access the camera, and click the [Execute] button for “Pre-installed certificate - Download root certificate” under “HTTPS” in the [Advanced] tab in the settings menu of the “Network” page. Click “Open” displayed on the bottom of the browser.
2.
Click “Install Certificate...”.
3.
Click “Next” displayed in “Certificate Import Wizard”.
4.
Select “Place all certificates in the following store”, and click “Browse...”.
5.
Select “Trusted Root Certificate Authorities”, and click “OK”.
6.
Click “Next”.
7.
Click “Finish”.
8.
Confirm that the content shown next to “Thumbprint” in the “Security warning” window is as follows and then click “Yes”.
Thumbprint (sha1): 0B886A3C E7F2DBA8 1035DDFA 2B21F80B 06778932
Note
Other parties cannot create another thumbprint with the same values. You can confirm that you have retrieved the correct root certificate from the specified camera by confirming the values of the thumbprint.
 
→ When the import is successfully completed, the screen “The import was successful.” will be displayed.
9.
Click the [OK] button.
10.
Click the [OK] button in the “Certificate” window to close the window.
2.8.3.3 Configuration of HTTPS connections
1.
Select “HTTPS” to access the camera in [HTTPS – Connection].
2.
Designate the HTTPS port number to be used for [HTTPS – HTTPS port].
Available port number: 1 - 65535
Default: 443
The following port numbers are unavailable since they are already in use.
20, 21, 23, 25, 42, 53, 67, 68, 69, 80, 110, 123, 161, 162, 554, 995, 10669, 10670, 32768-49151, 59000-61000
3.
Click the [Set] button.
It will become possible to access to the cameras using the HTTPS protocol.
Restart the browser and access again.
Refer to the following for information on methods to access cameras using HTTPS.
Monitor images on a PC: 1.1 Monitor images on a PC
Monitor images on a tablet device: 1.2.2 Monitor images on a tablet device
4.
If “Certificate error” is displayed, refer to the following.
When using a pre-installed certificate: 2.8.3.2 Obtaining the root certificate
Note
When the connection setting is changed, after waiting for a while, access the camera again with either “http://IP address of the camera” or “https://IP address of the camera” depending on the changed setting.
When using the pre-installed certificate:
In advance, install the root certificate of the Pre-installed certificate on the PC in use. Refer to 2.8.3.2 Obtaining the root certificate for information on the setting procedure.
When the camera is accessed using the HTTPS protocol, the refresh interval and frame rate of images may be lower.
When the camera is accessed using the HTTPS protocol, it may take time to display images.
When the camera is accessed using the HTTPS protocol, the images may be distorted or audio may be interrupted.
The maximum number of concurrent access user varies depending on the maximum image size and transmission format.
2.8.3.4 Generation of the CRT key (SSL encryption key)
IMPORTANT
When the CA certificate is valid, it is impossible to generate the CRT key.
When the CA certificate is used, the available key size varies depending on the CA. Confirm the available key size in advance.
To generate the CRT key, it may take about 2 minutes. Do not operate the web browser until the generation of CRT key is complete. While the CRT key is being generated, the refresh interval and line speed may be lower.
1.
Click the [Execute] button of “CRT key generate”.
The “CRT key generate” dialog box will be displayed.
2.
Click the [Execute] button.
The generation of CRT key will be started. When the generation is finished, the key size and generation time & date of the generated key will be displayed on “Current CRT key”.
Note
To change (or update) the generated CRT key, perform step 1 to 2. The CRT key and CA certificate are valid in a set. When the CRT key is changed, it is necessary to re-apply for the CA certificate.
When the CRT key is updated, the log of the previous CRT key is saved. When the [History] button of “Current CRT key” on the “CRT key generate” dialog box is clicked, the “Previous CRT key” dialog box will be displayed, and it is possible to check the key size and generation time & date of the previous key. When the [Apply] button is clicked on the “Previous CRT key” dialog box, it is possible to replace the current CRT key with the previous one.
2.8.3.5 Generation of CSR (Certificate Signing Request)
IMPORTANT
If the CRT key is not generated, it is impossible to generate the CSR.
Before generating the CSR file, configure the following settings on [Internet Options] of the web browser in advance. Click [Internet Options...] under [Tools] of the menu bar of Internet Explorer, and then click the [Security] tab.
Register the camera for [Trusted Sites].
Click the [Custom level] button to open the [Security Settings] window, and check the [Enable] radio button of [File Download] under [Downloads].
Click the [Custom level] button to open the [Security Settings] window, and check the [Enable] radio button of [Automatic prompting for file downloads] under [Downloads].
1.
Click the [Execute] button of “CA Certificate - Generate Certificate Signing Request”.
The “CA Certificate - Generate Certificate Signing Request” dialog box will be displayed.
2.
Enter the information of the certificate to be generated.
Item
Description
Available number of characters
[Common Name]
Enter the camera address or host name.
64 characters
[Country]
Enter the country name.
2 characters (Country code)
[State]
Enter the state name.
128 characters
[Locality]
Enter the locality name.
128 characters
[Organization]
Enter the organization name.
64 characters
[Organizational Unit]
Enter the unit name of the organization.
64 characters
[CRT key]
Displays the key size and generation time & date of the current key.
Note
To use the CA certificate, follow the requests from the CA about the information to be entered.
The available characters for [Common Name], [State], [Locality], [Organization], [Organizational Unit] are 0-9, A-Z, a-z and the following marks.
- . _ , + / ( )
3.
Click the [OK] button after entering the items.
The [Save As] dialog box will be displayed.
4.
Enter a file name for the CSR in the [Save As] dialog box to save on the PC.
The saved CSR file will be applied to the CA.
IMPORTANT
The CA certificate will be issued for the set of the generated CSR and CRT key. If the CRT key is re-generated or updated after applying to the CA, the issued CA certificate will be invalidated.
Note
This camera generates the CSR file in the PEM format.
2.8.3.6 Installation of the CA certificate
IMPORTANT
If the CSR file is not generated, it is impossible to install the CA certificate.
For the installation of the CA certificate, the CA certificate issued by CA is required.
1.
Click the [Browse...] button of “CA Certificate - CA Certificate install”.
The [Open] dialog box will be displayed.
2.
Select the CA certificate file and click the [Open] button. Then, click the [Execute] button.
The CA certificate will be installed.
Note
The host name registered in the installed CA certificate will be displayed on “CA Certificate - Information”. Depending on the status of the CA certificate, the following are displayed.
Indication
Description
Invalid
The CA certificate is not installed.
[CA certificate Host name]
The CA certificate has already been installed and validated.
Expired
The CA certificate has already expired.
When the [Confirm] button is clicked, the registered information of the CA certificate will be displayed in the “CA Certificate - Confirm” dialog box. (Only “Organizational Unit” will be displayed with an asterisk (*).)
When the [Delete] button is clicked, the installed CA certificate will be deleted.
When “HTTPS” is selected for “Connection”, it is impossible to delete the CA certificate.
To update the CA certificate, perform step 1 and 2.
IMPORTANT
Before deleting the valid CA certificate, confirm that there is a backup file of the CA certificate on the PC or another media. The backup file of the CA certificate will be required when installing the CA certificate again.
When the CA certificate has expired, the HTTPS function will become unavailable. When the camera is restarted, the connection protocol will be changed to HTTP. Update the CA certificate before it expires.
The expiration date of the CA certificate can be checked by double-clicking the CA certificate file issued by CA.