Warning
Potential for Data Loss: The steps detailed in the resolution of this article may result in a loss of critical data if not performed properly. Before beginning these steps, make sure all important data is backed up in the event of data loss. If you are unsure or unfamiliar with any complex steps detailed in this article, please contact Product Support for assistance.
Issue
Unique SSL Root Certificate is self-generated using Device Administrator and it needs to be backed up, restored or transferred to another machine
Product Line
EcoStruxure Building Operation
Environment
- Building Operation Device Administrator
- Building Operation Automation Server
Cause
Without a self-generated SSL Root Certificate installed on Windows OS that is running Device Administrator, Automation Servers with certificates installed will not be trusted. Use cases involve the transfer of data from one installation of Device Administrator to another and are not limited to:
- Transfer from a laptop used during startup to another laptop
- Transfer from a laptop used during startup to Enterprise Server machine
Resolution
Before starting ensure the following:
- Automation Servers will not be connected via browser for Webstation where a trusted certificate authority should be used to generate the certificates.
- Device Administrator has SSL Root Certificate installed and Automation Server is successfully communicating via HTTPS per Device Administrator Certificate Workflow
Backup data from Device Administrator to be transferred or restored using the following process:
- Backup Existing DA by exporting the SSL Root Certificate
- Click SSL Root Certificate
- Check Include Private Key
- Select the Destination Folder and ZIP filename
- Provide a password for the Export File
- Confirm the password
- Click Export button and verify Root CA Certificate has been exported to the destination folder
- Backup Existing DA Server List
- Click Save current server list or Save as new server list button
- Default location: C:\ProgramData\Schneider Electric EcoStruxure\Building Operation [n.n]\Device Administrator
- Default Filename: Servers.xml
- Export Server list
- Click Export Server List button
- Provide a password and confirm password
- Click OK button
Restore data to the Device Administrator using the following process:
- Import SSL Root Certificate
- Click SSL Root Certificate
- Click Import Certificate
- Check import encrypted Archive
- Select file
- Enter password
- Click Install to Windows Certificate Store to add to Windows for Enterprise Server or Device Administrator to be able to trust certificates. Install into Windows Certificate Store
- Restore the server list to replace the default list.
- Click Import server list
- Navigate to and select the file, then click Open
- Enter file password, then click OK
- Provide the default location in the address bar (see Default Location above), select Servers.xml, and click Save
- Click YES to replace the existing file
- Click YES to overwrite the existing file
- When server list import is complete, click OK