Automating camera server TLS X.509 certificate updates

Jiri

n3wb
Joined
May 3, 2019
Messages
12
Reaction score
4
Location
WA
Hello,

I have used in the past the camera web UI to delete and upload new certificates upon the expiry of the older ones. However, it is royally painful. To remove older ones, you need to switch from https to http, reauth, go back, upload new certs and switch back to https to make sure everything is working. And do this per camera, per the lifetime of the leaf cert. I can always extend that lifetime, but before I do that, I was wondering if you folks have a better/faster flow for updating the certificates. I know that ONVIF supports certificate update, but looking online, I could not find any readily available/free tools that could do that.
 

wittaj

IPCT Contributor
Joined
Apr 28, 2019
Messages
24,939
Reaction score
48,645
Location
USA
Why not just isolate the cameras from the internet and then you don't need to mess with this process...
 

Jiri

n3wb
Joined
May 3, 2019
Messages
12
Reaction score
4
Location
WA
I have the cameras on a dedicated VLAN that does not have Internet connectivity. Still, I wanted to get the certificates deployed to limit any non-encrypted traffic.
 
Top