Overview of the scenarios and procedures used with certificates
The procedures for configuring secure communication in an XProtect VMS environment vary, depending on server type, network type (WORKGROUP vs DOMAIN network), and the types of XProtect VMS client applications used in the system.
Note
For single-server installations, certificates are usually optional except as an extra safeguard when communicating with the management server.
This list shows the different scenarios:
XProtect Mobile Server
In XProtect VMS, encryption is enabled or disabled per Mobile Server during installation or by using the Server Configurator. When you enable encryption on a Mobile Server, you then use encrypted communication with all clients, services, and integrations that retrieve data streams.
The Mobile Server connects to the XProtect Mobile client and XProtect Web Client. Browsers, operating systems, and mobile devices that host these clients maintain a list of trusted CA root certificates.
These clients, then, already have certificate keys installed and work with most any third-party certificate that is available to install on the Mobile Server itself.
Since each third-party CA has their own requirements for requesting a certificate, it is best to investigate the individual requirements directly with the CA.
This document describes how to create and install certificates on the Mobile Server.
See:
Install certificates for communication with the Mobile Server
Milestone XProtect Management Server and Recording Server
You can encrypt the two-way connection between the Management Server and the Recording Server. When you enable encryption on the Management Server, it applies to connections from all the Recording Servers that connect to the Management Server. If you enable encryption on the Management Server, you must also enable encryption on all of the Recording Servers. Before you enable encryption, you must install security certificates on the Management Server and all Recording Servers, including Failover Recording Servers.
Third-party or commercial CA certificate
The process for requesting certificates from third-party CAs for use with Management Servers and Recording Servers is the same as with the Mobile Server. The only difference is the configuration with the Server Configurator.
See:
Domain
When client and server endpoints are all operating within a Domain environment with its own certificate authority infrastructure, there is no requirement to distribute CA certificates to client workstations. As long as you have a Group Policy within the Domain, that will handle the automatic distribution of all trusted CA certificates to all users and computers in the Domain.
The process for requesting a certificate and installing a server certificate is the same as in a Workgroup.
See:
Install certificates in a domain for communication with the Management Server or Recording Server
Workgroup
When operating in a Workgroup environment, it is assumed that there is no certificate authority infrastructure. To distribute certificates, it is required to create a certificate authority infrastructure. There is also a requirement to distribute the certificate keys to client workstations. Except for these requirements, the process of requesting and installing a certificate on a server is similar to both the Domain and third-party scenarios.
See:
XProtect Event Server
You can encrypt the two-way connection between the Event Server and the components that communicate with the Event Server, including the LPR Server. When you enable encryption on the Event Server, it applies to connections from all the components that connect to the Event Server. Before you enable encryption, you must install security certificates on the Event Server and all connecting components.
See:
Install certificates for communication with the Event Server
Client
In the Third-party/commercial and Domain scenarios, clients do not need certificate keys installed. You only need to install client certificate keys in a Workgroup environment.
When you enable encryption on a Recording Server, communication to all clients, servers, and integrations that retrieve data streams from the Recording Server are encrypted.
For solutions built with MIP SDK 2018 R3 or earlier that access recording servers: If the integrations are made using MIP SDK libraries, they need to be rebuilt with MIP SDK 2019 R1; if the integrations communicate directly with the Recording Server APIs without using MIP SDK libraries, the integrators must add HTTPS support themselves.
See: