2.8.3 How to configure HTTPS settings
The settings relating to the HTTPS protocol that can enhance the network security by encrypting the access to cameras on this page.
HTTPS settings can be configured by either using the Self-signed Certificate, or using a CA certificate that you obtained by yourself from the CA (CA: Certification Authority).
 
The HTTPS settings will be configured in the following procedure.
Generation of the CRT key (SSL encryption key) (→2.8.3.1 Generation of the CRT key (SSL encryption key))
Generation of CSR (Certificate Signing Request) (→2.8.3.3 Generation of CSR (Certificate Signing Request))
Installation of the CA certificate (→2.8.3.4 Installation of the CA certificate)
Configuration of the connection protocol (→2.8.3.5 Configuration of the connection protocol)
Note
To use the CA certificate, you need to apply for the approval and the issue of CA certificate by CA.
Either of the self-signed certificate or the CA certificate is available. If both of them are installed, the CA certificate will be used prior to the self-signed certificate.
2.8.3.1 Generation of the CRT key (SSL encryption key)
IMPORTANT
When the CA certificate is valid, it is impossible to generate the CRT key.
When the CA certificate is used, the available key size varies depending on the CA. Confirm the available key size in advance.
To generate the CRT key, it may take about 2 minutes. Do not operate the web browser until the generation of CRT key is complete. While the CRT key is being generated, the refresh interval and line speed may be lower.
1.
Click the [Execute] button of “CRT key generate”.
The “CRT key generate” dialog box will be displayed.
2.
Click the [Execute] button.
The generation of CRT key will be started. When the generation is finished, the key size and generation time & date of the generated key will be displayed on “Current CRT key”.
Note
To change (or update) the generated CRT key, perform step 1 to 2. The CRT key and CA certificate are valid in a set. When the CRT key is changed, it is necessary to re-apply for the CA certificate.
When the CRT key is updated, the log of the previous CRT key is saved. When the [History] button of “Current CRT key” on the “CRT key generate” dialog box is clicked, the “Previous CRT key” dialog box will be displayed, and it is possible to check the key size and generation time & date of the previous key. When the [Apply] button is clicked on the “Previous CRT key” dialog box, it is possible to replace the current CRT key with the previous one.
2.8.3.2 Generation of the self-signed certificate (security certificate)
IMPORTANT
If the CRT key is not generated, it is impossible to generate the self-signed certificate.
1.
Click the [Execute] button of “Self-signed Certificate - Generate”.
The “Self-signed Certificate - Generate” dialog box will be displayed.
2.
Enter the information of the certificate to be generated.
Item
Description
Available number of characters
[Common Name]
Enter the camera address or host name.
64 characters
[Country]
Enter the country name. (Omission is OK.)
2 characters (Country code)
[State]
Enter the state name. (Omission is OK.)
128 characters
Locality
Enter the locality name. (Omission is OK.)
128 characters
[Organization]
Enter the organization name. (Omission is OK.)
64 characters
[Organizational Unit]
Enter the unit name of the organization. (Omission is OK.)
64 characters
[CRT key]
Displays the key size and generation time & date of the current key.
-
Note
The available characters for [Common Name], [State], [Locality], [Organization], [Organizational Unit] are 0-9, A-Z, a-z and the following marks.
- . _ , + / ( )
When the camera is connected to the Internet, enter the address name or host name to access via the Internet for “Common Name”. In this case, the security alert window will be displayed each time the camera is locally accessed, even if the security certificate is installed.
When entering the IPv6 address for “Common Name”, put the address in brackets [ ].
Example: [2001:db8::10]
3.
Click the [OK] button after entering the items.
The self-signed certificate will be generated.
Note
The information of the generated self-signed certificate will be displayed on “Self-signed Certificate” - “Information”.
Depending on the status of the self-signed certificate, the following are displayed.
Indication
Description
Not generated
The self-signed certificate are not generated.
Invalid (Reason: CA Certificate installed)
The self-signed certificate has already been generated, and the CA certificate has been installed.
In this case, the CA certificate is validated.
Common name of the self-signed certificate
The self-signed certificate has already been generated and validated.
When the [Confirm] button is clicked, the registered information of the self-signed certificate (security certificate) will be displayed in the “Self-signed Certificate - Confirm” dialog box.
When the [Delete] button is clicked, the generated self-signed certificate (security certificate) will be deleted.
When “HTTP” is selected for “Connection”, it is impossible to delete the self-signed certificate.
2.8.3.3 Generation of CSR (Certificate Signing Request)
IMPORTANT
If the CRT key is not generated, it is impossible to generate the CSR.
Before generating the CSR file, configure the following settings on [Internet Options] of the web browser in advance. Click [Internet Options...] under [Tools] of the menu bar of Internet Explorer, and then click the [Security] tab.
Register the camera for [Trusted Sites].
Click the [Custom level] button to open the [Security Settings] window, and check the [Enable] radio button of [File Download] under [Downloads].
Click the [Custom level] button to open the [Security Settings] window, and check the [Enable] radio button of [Automatic prompting for file downloads] under [Downloads].
1.
Click the [Execute] button of “CA Certificate - Generate Certificate Signing Request”.
The “CA Certificate - Generate Certificate Signing Request” dialog box will be displayed.
2.
Enter the information of the certificate to be generated.
Item
Description
Available number of characters
[Common Name]
Enter the camera address or host name.
64 characters
[Country]
Enter the country name.
2 characters (Country code)
[State]
Enter the state name.
128 characters
[Locality]
Enter the locality name.
128 characters
[Organization]
Enter the organization name.
64 characters
[Organizational Unit]
Enter the unit name of the organization.
64 characters
[CRT key]
Displays the key size and generation time & date of the current key.
Note
To use the CA certificate, follow the requests from the CA about the information to be entered.
The available characters for [Common Name], [State], [Locality], [Organization], [Organizational Unit] are 0-9, A-Z, a-z and the following marks.
- . _ , + / ( )
3.
Click the [OK] button after entering the items.
The [Save As] dialog box will be displayed.
4.
Enter a file name for the CSR in the [Save As] dialog box to save on the PC.
The saved CSR file will be applied to the CA.
IMPORTANT
The CA certificate will be issued for the set of the generated CSR and CRT key. If the CRT key is re-generated or updated after applying to the CA, the issued CA certificate will be invalidated.
Note
This camera generates the CSR file in the PEM format.
2.8.3.4 Installation of the CA certificate
IMPORTANT
If the CSR file is not generated, it is impossible to install the CA certificate (Security certificate).
For the installation of the CA certificate, the CA certificate issued by CA is required.
1.
Click the [Browse...] button of “CA Certificate - CA Certificate install”.
The [Open] dialog box will be displayed.
2.
Select the CA certificate file and click the [Open] button. Then, click the [Execute] button.
The CA certificate will be installed.
Note
The host name registered in the installed CA certificate will be displayed on “CA Certificate - Information”. Depending on the status of the CA certificate, the following are displayed.
Indication
Description
Invalid
The CA certificate is not installed.
[CA certificate Host name]
The CA certificate has already been installed and validated.
Expired
The CA certificate has already expired.
When the [Confirm] button is clicked, the registered information of the CA certificate (security certificate) will be displayed in the “CA Certificate - Confirm” dialog box. (Only “Organizational Unit” will be displayed with an asterisk (*).)
When the [Delete] button is clicked, the installed CA certificate (security certificate) will be deleted.
When “HTTPS” is selected for “Connection”, it is impossible to delete the CA certificate (security certificate).
To update the CA certificate, perform step 1 and 2.
IMPORTANT
Before deleting the valid CA certificate (security certificate), confirm that there is a backup file of the CA certificate (security certificate) on the PC or another media. The backup file of the CA certificate (security certificate) will be required when installing the CA certificate again.
When the CA certificate has expired, the HTTPS function will become unavailable. When the camera is restarted, the connection protocol will be changed to HTTP. Update the CA certificate before it expires.
The expiration date of the CA certificate can be checked by double-clicking the CA certificate file issued by CA.
2.8.3.5 Configuration of the connection protocol
1.
Select “HTTP” or “HTTPS” for “Connection” to determine the protocol used to access the camera.
HTTP: Only the HTTP connection is available.
HTTPS: Only the HTTPS connection is available.
2.
Designate the HTTPS port number to be used for “HTTPS port”.
Available port number: 1 - 65535
Default: 443
The following port numbers are unavailable since they are already in use.
20, 21, 23, 25, 42, 53, 67, 68, 69, 80, 110, 123, 161, 162, 554, 995, 10669, 10670, 59000 - 61000
3.
Click the [Set] button.
It will become possible to access to the cameras using the HTTPS protocol. (→1.1 Monitor images on a PC, 1.2 Monitor images on a mobile terminal (smartphones, etc.)/tablet terminal)
Note
When the connection setting is changed, after waiting for a while, access the camera again with either “http://IP address of the camera” or “https://IP address of the camera” depending on the changed setting.
When using the self-signed certificate:
If the camera is accessed using the HTTPS protocol for the first time, the warning window will be displayed. In this case, follow the instructions of the wizard to install the self-signed (security) certificate. (→2.8.4 Access the camera using the HTTPS protocol)
When using CA certificate:
In advance, install the root certificate and intermediate certificate on the browser in use. Follow the instructions of CA for how to obtain and install these certificates.
When the camera is accessed using the HTTPS protocol, the refresh interval and frame rate of images may be lower.
When the camera is accessed using the HTTPS protocol, it may take time to display images.
When the camera is accessed using the HTTPS protocol, the images may be distorted.
The maximum number of concurrent access user varies depending on the maximum image size and transmission format.