2.8.3 Configure IEEE 802.1X [IEEE 802.1X]
The settings relating to IEEE 802.1X can be configured on this page.
The procedures differ depending on the EAP method. Set up in the following procedures. If “On” is set for “IEEE 802.1X”, set it “Off” before starting setup.
[IEEE 802.1X]
Select “On” or “Off” to determine whether or not to perform port authentication using IEEE 802.1X.
[User name]
Enter the user name to access the authentication LAN switch.
•
Available number of characters: 1 - 32 characters
•
Unavailable characters: " & : ; \
[Password]
[Retype password]
Enter the password to access the authentication LAN switch.
•
Available number of characters: 4 - 32 characters
•
Unavailable characters: " &
[CA Certificate] - [Certificate install]
Install the root CA Certificate. Do not include the intermediate CA Certificate.
Installation is possible only when “Off” is selected for “IEEE 802.1X”.
n Specification of CA Certificate
Item
|
Specifications
|
Remarks
|
Data format
|
Format: PEM or DER
|
Extension: pem or der
|
Max. number of certificates included in the PEM format
|
1 pc.
|
—
|
Max. size of certificate
|
Approx. 10 Kbyte
|
—
|
[CA Certificate] - [Information]
not installed: indicates that the certificate is not installed.
CA certificate host name: indicates that the certificate is installed.
Expired: indicates that the certificate is expired.
The details of CA Certificate can be checked with the [Confirm] button.
Note
•
Check that the CA certificate has not expired. If you use a certificate that have expired, you may not be able to connect to authentication LAN switches.
[Private key or Client Certificate including private key] - [Installation]
Install the private key or Client Certificate that includes private key.
Installation is possible only when “Off” is selected for “IEEE 802.1X”.
n Specification of private key and Client Certificate including private key
Item
|
Specifications
|
Remarks
|
Data format
|
Format: PEM or PFX
|
Extension: pem or pfx
|
Key size [bit]
|
1024 /1536 /2048 /3072 /4096
|
—
|
Max. number of certificates included in the PEM format
|
6 pc.
|
—
|
Max. size of certificate (including intermediate CA Certificate)
|
Approx. 10 Kbyte
|
—
|
[Private key or Client Certificate including private key] - [Password]
Enter the password if the private key is encrypted or the password is set for Client Certificate for the PFX method. Leave password blank when not encrypted.
Available number of characters: 0 - 30 characters
[Private key or Client Certificate including private key] - [Install status of private key]
not installed: Private key is not installed.
installed: Private key is installed.
[Client Certificate] - [Installation]
Install the Client Certificate.
If signed by the intermediate CA Certificate, install the Client Certificate including the intermediate CA Certificate.
Installation is possible only when “Off” is selected for “IEEE 802.1X”.
n Specification of Client Certificate
Item
|
Specifications
|
Remarks
|
Data format
|
Format: PEM
|
Extension: pem
|
Max. number of certificates included in the PEM format
|
6 pc.
|
—
|
Max. size of certificate (including intermediate CA Certificate)
|
Approx. 10 Kbyte
|
—
|
[Client Certificate] - [Information]
not installed: indicates that the certificate is not installed.
Certificate host name: indicates that the certificate is installed.
Expired: indicates that the certificate is expired.
The details of Client Certificate can be checked with the [Confirm] button.
Note
•
Check that the client certificate has not expired. If you use a certificate that has expired, you may not be able to connect to authentication LAN switches.
[EAP method]
Select the authentication method from EAP-MD5, EAP-PEAP or EAP-TLS.
EAP-MD5/EAP-PEAP
1.
Select “On” for “IEEE 802.1X”.
2.
Select “EAP-MD5” or “EAP-PEAP” for “EAP method”.
3.
Click the [Set] button after entering the user name, the password, and confirming the password.
EAP-TLS
1.
Click the [Browse] button of “CA Certificate” - “Certificate install”. Then, select a CA Certificate and click the [Execute] button. The host name (CommonName) specified when creating certificates will be displayed for “Information”.
2.
Click the [Browse] button of “Private key or Client Certificate including private key”, and select a private key or Client Certificate that includes Private key.
3.
Enter the password if the private key is encrypted or the password is set for Client Certificate for the PFX method. Leave password blank when not encrypted.
4.
Click the [Execute] button to start installation.
“installed” will be displayed for “Install status of private key”.
In the case of selecting Client Certificate including the private key, “installed” will be displayed for “Client Certificate” - “Information” as well.
5.
When the private key is installed in step 2, select a Client Certificate after clicking the [Browse] button of “Client Certificate”, and then click the [Execute] button. The host name (CommonName) specified when creating certificates will be displayed for “Information”.
6.
Select “On” for “IEEE 802.1X”. Then, select “EAP-TLS” for “EAP method”.
7.
Enter the user name registered to the server in “User name”. Then, click the [Set] button.
If no user name is registered to the server, enter an arbitrary user name.
“Password” and “Retype password” can be left blank.
Note
•
To delete each certificate, set [IEEE 802.1X] to “Off”.
•
Check that the CA certificate and client certificate have not expired. If you use certificates that have expired, you may not be able to use the port notification feature.
Example of CA Certificate check screen
Example of Client Certificate check screen
IMPORTANT
•
After selecting “On” for “IEEE 802.1X”, if access to the camera fails for some reason, connect to a switch or port without authentication. It disables IEEE 802.1X, and enables access to the camera.
•
If the Client Certificate includes intermediate CA Certificate, the Client Certificate needs to come first, then the intermediate CA Certificate.
•
When a certificate over 10 Kbyte is installed, no error will be displayed during installation. However, an error may occur at the time of connection.