2.8.3 Configure IEEE 802.1X [IEEE 802.1X]
Click the [IEEE 802.1X] tab on the “User mng.” page. (→For menu display and how to operate, refer to 2.2.1 How to display the setup menu, 2.2.2 How to operate the setup menu)
The settings relating to IEEE 802.1X can be configured on this page.
The procedures differ depending on the EAP method. Set up in the following procedures. If “On” is set for “IEEE 802.1X”, set it “Off” before starting setup.
[IEEE 802.1X]
Select “On” or “Off” to determine whether or not to perform port authentication using IEEE 802.1X.
Default: Off
[User name]
Enter the user name to access the authentication LAN switch.
Available number of characters: 1 - 32 characters
Unavailable characters: " & : ; \
[Password]
[Retype password]
Enter the password to access the authentication LAN switch.
Available number of characters: 4 - 32 characters
Unavailable characters: " &
[CA Certificate] - [Certificate install]
Install the root CA Certificate. Do not include the intermediate CA Certificate.
Installation is possible only when “Off” is selected for “IEEE 802.1X”.
n Specification of CA Certificate
Item
Specifications
Remarks
Data format
Format: PEM or DER
Extension: pem or der
Max. number of certificates included in the PEM format
1 pc.
Max. size of certificate
Approx. 10 Kbyte
[CA Certificate] - [Information]
not installed: indicates that the certificate is not installed.
CA certificate host name: indicates that the certificate is installed.
Expired: indicates that the certificate is expired.
The details of CA Certificate can be checked with the [Confirm] button.
Note
Check that the CA certificate has not expired. If you use a certificate that have expired, you may not be able to connect to authentication LAN switches.
[Private key or Client Certificate including private key] - [Installation]
Install the private key or Client Certificate that includes private key.
Installation is possible only when “Off” is selected for “IEEE 802.1X”.
n Specification of private key and Client Certificate including private key
Item
Specifications
Remarks
Data format
Format: PEM or PFX
Extension: pem or pfx
Key size [bit]
1024 /1536 /2048 /3072 /4096
Max. number of certificates included in the PEM format
6 pc.
Max. size of certificate (including intermediate CA Certificate)
Approx. 10 Kbyte
[Private key or Client Certificate including private key] - [Password]
Enter the password if the private key is encrypted or the password is set for Client Certificate for the PFX method. Leave password blank when not encrypted.
Available number of characters: 0 - 30 characters
[Private key or Client Certificate including private key] - [Install status of private key]
not installed: Private key is not installed.
installed: Private key is installed.
[Client Certificate] - [Installation]
Install the Client Certificate.
If signed by the intermediate CA Certificate, install the Client Certificate including the intermediate CA Certificate.
Installation is possible only when “Off” is selected for “IEEE 802.1X”.
n Specification of Client Certificate
Item
Specifications
Remarks
Data format
Format: PEM
Extension: pem
Max. number of certificates included in the PEM format
6 pc.
Max. size of certificate (including intermediate CA Certificate)
Approx. 10 Kbyte
[Client Certificate] - [Information]
not installed: indicates that the certificate is not installed.
Certificate host name: indicates that the certificate is installed.
Expired: indicates that the certificate is expired.
The details of Client Certificate can be checked with the [Confirm] button.
Note
Check that the client certificate has not expired. If you use a certificate that has expired, you may not be able to connect to authentication LAN switches.
[EAP method]
Select the authentication method from EAP-MD5, EAP-PEAP or EAP-TLS.
EAP-MD5/EAP-PEAP
1.
Select “On” for “IEEE 802.1X”.
2.
Select “EAP-MD5” or “EAP-PEAP” for “EAP method”.
3.
Click the [Set] button after entering the user name, the password, and confirming the password.
EAP-TLS
1.
Click the [Browse] button of “CA Certificate” - “Certificate install”. Then, select a CA Certificate and click the [Execute] button. The host name (CommonName) specified when creating certificates will be displayed for “Information”.
2.
Click the [Browse] button of “Private key or Client Certificate including private key”, and select a private key or Client Certificate that includes Private key.
3.
Enter the password if the private key is encrypted or the password is set for Client Certificate for the PFX method. Leave password blank when not encrypted.
4.
Click the [Execute] button to start installation.
“installed” will be displayed for “Install status of private key”.
In the case of selecting Client Certificate including the private key, “installed” will be displayed for “Client Certificate” - “Information” as well.
5.
When the private key is installed in step 2, select a Client Certificate after clicking the [Browse] button of “Client Certificate”, and then click the [Execute] button. The host name (CommonName) specified when creating certificates will be displayed for “Information”.
6.
Select “On” for “IEEE 802.1X”. Then, select “EAP-TLS” for “EAP method”.
7.
Enter the user name registered to the server in “User name”. Then, click the [Set] button.
If no user name is registered to the server, enter an arbitrary user name.
“Password” and “Retype password” can be left blank.
Note
To delete each certificate, set [IEEE 802.1X] to “Off”.
Check that the CA certificate and client certificate have not expired. If you use certificates that have expired, you may not be able to use the port notification feature.
 
Example of CA Certificate check screen
Example of Client Certificate check screen
IMPORTANT
After selecting “On” for “IEEE 802.1X”, if access to the camera fails for some reason, connect to a switch or port without authentication. It disables IEEE 802.1X, and enables access to the camera.
If the Client Certificate includes intermediate CA Certificate, the Client Certificate needs to come first, then the intermediate CA Certificate.
When a certificate over 10 Kbyte is installed, no error will be displayed during installation. However, an error may occur at the time of connection.