Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

We Value Your Feedback!
Could you please spare a few minutes to share your thoughts on Cloud Connected vs On-Premise Services. Your feedback can help us shape the future of services.
Learn more about the survey or Click here to Launch the survey
Schneider Electric Services Innovation Team!

Building Automation Knowledge Base

Schneider Electric Building Automation Knowledge Base is a self-service resource to answer all your questions about EcoStruxure Building suite, Andover Continuum, Satchwell, TAC…

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • Home
  • Schneider Electric Community
  • Knowledge Center
  • Building Automation Knowledge Base
Options
  • My Knowledge Base Contributions
  • Subscribe
  • Bookmark
  • Invite a Friend
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close
Labels
Top Labels
  • Alphabetical
  • Andover Continuum 2,208
  • TAC Vista 2,045
  • EcoStruxure Building Operation 1,838
  • TAC IA Series 1,821
  • TAC INET 1,458
  • Field Devices 721
  • Satchwell BAS & Sigma 474
  • EcoStruxure Security Expert 325
  • Satchwell MicroNet 252
  • EcoStruxure Building Expert 228
  • EcoStruxure Access Expert 147
  • CCTV 53
  • Project Configuration Tool 46
  • EcoStruxure Building Activate 13
  • EcoStruxure Building Advisor 12
  • ESMI Fire Detection 6
  • Automated Engineering Tool 4
  • EcoStruxure Building Data Platform 3
  • EcoStruxure Workplace Advisor 1
  • EcoStruxure for Retail - IMP 1
  • Previous
  • 1 of 2
  • Next
Top Contributors
  • Product_Support
    Product_Support
  • DavidFisher
    DavidFisher
  • Cody_Failinger
    Cody_Failinger
See More Contributors
Related Products
Thumbnail of EcoStruxure™ Building Operation
Schneider Electric
EcoStruxure™ Building Operation
4
Thumbnail of SmartX IP Controllers
Schneider Electric
SmartX IP Controllers
1
Thumbnail of EcoStruxure™ Building Advisor
Schneider Electric
EcoStruxure™ Building Advisor
1

Related Forums

  • Intelligent Devices Forum

Previous Next

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite

Building Automation Knowledge Base

Sort by:
Date
  • Date
  • Views
  • Likes
  • Helpfulness
Options
  • Subscribe
  • Bookmark
  • Invite a Friend
  • « Previous
    • 1
    • …
    • 15
    • 16
    • 17
    • …
    • 507
  • Next »

Changing Block Type in Function Block Editor While Keeping the Same Name

Issue Want to modify the type of a block in the Function Block Editor while retaining the original block's name Product Line EcoStruxure Building Operation. Environment Building Operation Workstation. Function Block Editor. Cause Altering the block type without removing the block first can result in the persistence of old block parameters even if they are incompatible with the new block type. For instance, transitioning from an "Integer Input" block type while the input is in a forced state may cause the new block to retain the forced state, even if it is not applicable, leading to potential issues with un-forcing. Resolution To ensure correct functionality, it is recommended that the old block is removed and the application saved before adding the new block with the original name. This process effectively clears out the old configuration, enabling the new block to contain only the parameters of the new block type.
View full article
Kirk MikaelKrantz Kirk
‎2024-03-12 04:33 PM

on ‎2024-03-12 04:33 PM

Labels:
  • EcoStruxure Building Operation
1804 Views

Will EcoStruxure Building Operation provide any indication of a failure sending a SNMP trap?

Issue Will EcoStruxure Building Operation provide any indication of a failure sending a SNMP trap? Product Line EcoStruxure Building Operation Environment Building Operation Enterprise Server Building Operation Automation Server Cause Need to receive an alarm and event if an EBO server couldn't send an SNMP trap. Resolution If there is a failure sending an SNMP trap, EBO will generate a system alarm/event indicating that the trap could not be sent. Note though, that if the trap is sent successfully there is no indication or log entry to indicate so. System Alarm ID Description SNMP send trap failure Failed to send SNMP message.
View full article
Picard Product_Support
‎2018-09-11 08:21 AM

Last Updated: Administrator CraigEl Administrator ‎2024-03-11 11:49 PM

Labels:
  • EcoStruxure Building Operation
1180 Views

Can EBO serve data via Web Services

Issue Need to serve data via Web Services to 3rd party systems.  Product Line EcoStruxure Building Operation Environment Building Operation Enterprise Server Building Operation Enterprise Central Building Operation Automation Server Cause Generic Web Services SOAP, Simple XML or Script Web Services cannot act as a server. They can only act as a client to other web servers. Resolution EcoStruxure BMS servers can serve information to another EcoStruxure system using the EcoStruxure Web Services standard. For 3rd party systems, SmartConnector RESTful EWS Gateway can be used to serve EBO data to 3rd party system in a RESTful manner, refer to: Configure SmartConnector RESTful EWS Gateway to serve EBO data - Schneider Electric Community
View full article
Picard Product_Support
‎2018-09-06 09:37 AM

Last Updated: Administrator CraigEl Administrator ‎2024-03-11 11:46 PM

Labels:
  • EcoStruxure Building Operation
1320 Views

Changing the Priority of System Alarms in EcoStruxure Building Operation

Issue How to change the priority of system generated alarms in EcoStruxure Building Operation. Product Line EcoStruxure Building Operation Environment Building Operation Enterprise Server Building Operation Enterprise Central Building Operation Automation Server Cause Need to change EBO system priority. Resolution Currently, it is not possible to change the priority of system alarms. The default is value 100.  There are currently no plans to add the feature. 
View full article
Picard Product_Support
‎2018-09-06 12:17 PM

Last Updated: Administrator CraigEl Administrator ‎2024-03-11 11:43 PM

Labels:
  • EcoStruxure Building Operation
1603 Views

Convert PEM certificate file to CRT certificate file

Issue Device Administrator requires CRT certificate file to add a certificate to CA Certificates. Product Line EcoStruxure Building Operation Environment Building Operation Automation Server Cause If you rename the filetype from .pem to .crt and add via Device Administrator, the Automation Server will still present the following alarm: Alarm Text: System alarm: unable to get local issuer certificate System alarm ID: Invalid certificate for https communications   NOTE: The alarm will be known to have originated from the Automation Server because, in the Source field, the Automation Server will be the root, and the server it is connecting to will be the last. Example: /AS01/System/Communication/Server Certificate/To/ES01 AS01 - Automation Server with the CA Certificate issue ES01 - the EBO server which is was connected as client, which generated the alarm Resolution Reference this article to find OpenSSL installed: OpenSSL installed with EBO Use and modify this command with your filenames:  openssl x509 -in ca.pem -out ca.crt​ Add the .crt certificate file via Device Administator's CA Certificates tab. Reference: CA Certificate Tab (WebHelp)
View full article
Picard David_Purser Picard
‎2024-03-07 08:39 AM

on ‎2024-03-07 08:39 AM

Labels:
  • EcoStruxure Building Operation
2357 Views

Ensure a version of TLS is disabled using OpenSSL

Issue Ensure a version of TLS is disabled using OpenSSL Product Line EcoStruxure Building Operation Environment Enterprise Central Enterprise Server Automation Server Cause Need to verify TLS is disabled on an EBO server in case of incorrect text entry Resolution It is possible to check which TLS protocols are set to be disabled using WorkStation Control Panel's Security Settings or in the Device Administrator SSL Security Settings tab. If the version required is not disabled then consult Disabling TLS and SSH. Once the protocol is set to disabled follow the steps below to verify using OpenSSL Open a command prompt and change directory to the OpenSSL folder. If OpenSSL is not available consult OpenSSL installed with EBO or install OpenSSL as mentioned in Ensuring the SSL Host Certificate and key file are a matching pair To check if TLS is disabled enter the command openssl s_client -connect 'server address':'port'-'TLS version'.  For example if the server IP address is 192.168.5.95 and using port 443:- openssl s_client -connect 192.168.5.95:443 -tls1    openssl s_client -connect 192.168.5.95:443 -tls1_1 openssl s_client -connect 192.168.5.95:443 -tls1_2 openssl s_client -connect 192.168.5.95:443 -tls1_3 If an error is returned (1) and no certificates are available (2) then the TLS version is Disabled. If a certificate chain (3) and certificate details (4) are returned the TLS version is Enabled. The image illustrates only the start of the returned information, more will be available.   For additional information search "OpenSSL s_client" using an online web browser.  The s_client command can be used to test TLS server connectivity, TLS/SSL version support, check cipher suites, and verify server certificates.  
View full article
Admiral GavinHe Admiral
‎2024-03-06 03:19 PM

on ‎2024-03-06 03:19 PM

Labels:
  • EcoStruxure Building Operation
1959 Views

Side-by-side error when starting SigmaX, RegSigmaX or SigView

Issue The following errors are seen when trying to run SigmaX, RegSigmaX or SigView.  The application has failed to start because its side-by-side configuration is incorrect. Please see the application event log or use the command-line sxstrace.exe tool for more detail.  Application event log: Activation context generation failed for "C:\SigmaX\Bin\RegSigmaX.exe". Dependent Assembly Microsoft.VC80.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762" could not be found. Please use sxstrace.exe for detailed diagnosis. Product Line Satchwell Sigma Environment SigmaX 7.0.6 on Windows 7 32-bit SigmaX 7.09 on Windows 10 64bit SigView Cause Microsoft Visual C++ 2005 redistributable has not been installed. It appears that SigmaX requires this version to run. Resolution Either the Microsoft C++ 2005 is not installed, or if it is, then the Service Pack 1 (SP1) is required to be installed. This can be checked under the Windows 'Apps and Features'. Install Microsoft Visual C++ 2005 SP1 Redistributable Package (x86). In some cases,  Microsoft Visual C++ 2005 SP1 Redistributable Package Security Update (x86) is required to resolve the issue. The 32bit (x86) version should be installed if installing Microsoft Visual C++ 2005 SP1 does not fix the problem. 
View full article
Picard Product_Support
‎2018-09-11 01:47 PM

Last Updated: Gary Schneider Alumni (Retired) ‎2024-03-06 04:07 AM

Labels:
  • Satchwell BAS & Sigma
4122 Views

Error replacing IOU module

Issue Changing the Module ID after physically replacing a modules gives error "Incorrect response (or no response) from IO module" Product Line Andover Continuum Environment CyberStation CX9900 CX9940 CX9680 IOU Module Cause Controller's OMS database is out of sync with SQL database. Resolution To synchronize the OMS database with the SQL database:- Put CyberStation in offline edit mode. Edit the IOU Module object and enter the new Module ID. Save the object Return CyberStation to online edit mode. Perform a Send to controller, reloading the controller will sync the OMS db in the controller with the SQL database. Note the following: Make sure to use the option to reload attached objects but not attached controllers If IOUs go offline when sending to controller after doing this, manually get IOUs online, perform a send to database and send to controller. If a number of IOUs were replaced this process may need to be repeated several times until the send to controller works with no errors.
View full article
Picard Product_Support
‎2018-09-06 12:25 PM

Last Updated: Admiral GavinHe Admiral ‎2024-03-04 02:55 AM

Labels:
  • Andover Continuum
1875 Views

Webclient "There was an error trying to create the .NET control for this page"

Issue A dialog of "Cannot open .NET editor with .NET Framework" comes up with new installation of Webclient or after a Microsoft update of .NET 4.5.x. There was an error trying to create the .NET control for this page. Product Line Andover Continuum Environment Continuum Webclient Windows 7 Windows Server 2008 Windows 10 Internet Explorer Cause Microsoft changed the behavior of Internet Explorer when .net 4.5.x is installed on a PC. It turns off .net 2.0 support which is needed for several editors to function on Webclient browser PCs Resolution See web.Client v2.0 .Net Editor Hotfix on the EcoXpert Extranet This is a registry key file that installs the registry keys mentioned further down in this article. It allows Internet Explorer to utilize .net 2.0 that several webclient editors use. This hotfix contains a .reg file which changes the registry, it is recommended to make a Windows Restore point or a backup (export) of the existing registry folder (hive). The hotfix only updates the following keys, so the changes can also easily be made manually. On an 32-bit (x86) Operating System Add a DWORD attribute with the name EnableIEHosting to KEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework Set the value to 1 On an 64-bit Operating System Add a DWORD attribute with the name EnableIEHosting to KEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework Set the value to 1 A reboot of the webclient browser PC is required after the change is made. Each browser PC will need to have this fix applied. Microsoft Edge can also be used on newer client PCs, see the following article: Microsoft Edge can be used for webclient client PCs   
View full article
Picard Product_Support
‎2018-09-11 01:51 PM

Last Updated: Administrator CraigEl Administrator ‎2024-03-04 02:57 PM

Labels:
  • Andover Continuum
2834 Views

Error when trying to activate embedded license

Issue When trying to activate a license in an AS-P/B the following error message was shown and the activation failed: Online activation: 12:57:24: Executing licensing command 12:57:24: Executing embedded operation: Activate ActivationID: ACT-xxx 12:57:32: Embedded operation: Activate failed: ASEmbeddedAPI internal error: Binary response does not contain feature information Error status information: FNO server response: Z(BACK_OFFICE%DEBACK_OFFICE+']\dBl&%MSM230312018I|B}~%ACT-xxxxx/jlSkkj1%<K!,b7OnpUy7 zqDFG#I$QGGR0:SYWJVGIuW}+iea 0\wR/`;yX'HGX*;;nEl]d0I+nHWh(VD"+a uwpf%XF[N6~!,^?R]y?VPCw\gB{"dSy2K7ph;_=qw.|c]Vp;.nlMbLl-~Z!UY<:=TFZEL~h=\V)>ML)ld0g'PPcjrosy&]p9Y((?II#*B5/U16X;o- 12:57:32: Licensing command completed 12:57:34: Activating licenses failed   Offline activation: 12:56:02: Executing licensing command 12:56:02: Executing embedded operation: ProcessResponseFile ResponseFile: C:\Users\Mitthem\Desktop\Garage\response\xxxxxxx\8ba20b60-b19c-4a5d-8fea-693ef9282c8c.bin 12:56:03: Embedded operation: ProcessResponseFile failed: ASEmbeddedAPI internal error: Binary response does not contain feature information Error status information:  12:56:03: Licensing command completed 12:56:05: Activating licenses failed Product Line  EcoStruxure Building Operation Environment Building Operation Automation Server Premium (AS-P) Building Operation Automation Server Bundled (AS-B) Building Operation Device Administrator (DA)  Embedded Licenses Cause The reason for the issue was that the number of available licenses for activation was 0, but the error message in DA was not indicating that. The Device Administrator (DA) showed that two licenses were available but were out of sync. Resolution When looking at the Entitlement in DA, it had a yellow dot on it, indicating that it was added offline. In DA version 5.0.2 and later, DA contacts the License server directly when adding an Entitlement in prior versions this was done through the AS-P. In DA version 5.0.2 and later, it is enough that the computer where DA is installed has an internet connection when adding an Entitlement online. After upgrading DA to version 5.0.2 and refreshing the Entitlement, the Device Administrator showed the correct number of available licenses.    If upgrading the site to this version is not possible, the Entitlement ID / Activation ID availability and device list can be verified by using the User Portal FlexNet Login (flexnetoperations.com) It is also possible to run Device Administrator version 5.0.2 with the concurrent site version used as long as the Servers are at 4.0.4 and above to check, verify and activate licenses.     Important Note: Device Administrator 5.0.3 and above will NOT support lower-version Automation Servers as 5.0.2 does.  This is due to new features of embedded licenses for servers as well as the handling of servers without internet connections.  In this case, ALL servers must run the same version as the Device Administrator version when handling licenses.         Further information on Automation Server Licensing Overview is available through the online WebHelp.  
View full article
Janeway Jonas_Brissman Janeway
‎2023-05-01 07:02 AM

Last Updated: Guinan RobertAndriolo Guinan ‎2024-02-29 10:43 PM

Labels:
  • EcoStruxure Building Operation
4759 Views

Error 'The UPREV engine was asked to process an invalid code type' when flashing the firmware in the controller.

Issue Error 'The UPREV engine was asked to process an invalid code type' when flashing the firmware in the controller. Product Line Andover Continuum Environment bCX9640 CX9680 ACX5720 ACX5740 Cause RAM issues Resolution Using a browser login to the controller and perform a 'Clear Database Backup', commit changes and restart the controller. When the controller has re-started  disconnect the battery, power down the controller and after a minute power the controller up and re-connect the battery. Wait for the controller to come back online and then try the uprev operation once again.
View full article
Picard Product_Support
‎2018-09-06 11:15 AM

Last Updated: Admiral GavinHe Admiral ‎2024-02-26 04:26 AM

Labels:
  • Andover Continuum
2106 Views

PCT 1.x Server shows Added to Parent after being detached from ES

Issue When attempting to detach an AS, PCT continues to shown the server as being attached to the ES.   Product Line EcoStruxure Building Operation Environment Building Operation Project Configuration Tool 1.x (PCT) Cause In PCT, when an AS is detached from its parent ES, the ES name still appears in the Added to parent column of the Servers list. Resolution Once the AS has been detached from an ES it can be added to another ES though Workstation using the following steps even though the "Added to parents" column shows otherwise.   To create a SmartX server In WorkStation, in the System Tree panel, select the Servers folder. On the File menu, point to New and then click Server . In the Create Object wizard, in the Name box, type a name for the SmartX server. In the Description box, type descriptive information about the SmartX server. Click Next . In the Configure IP/DNS Address and Port page, in the Address box, type the IP address or fully qualified domain name of the SmartX server. Notice If the SmartX server has been assigned a dynamic IP address, use the fully qualified domain name of the SmartX server instead of the IP address. In the Protocol box, select a protocol for the SmartX server. For more information, see EcoStruxure BMS Server Communication . In the Port box, enter a port number. Click Create. In the Log on dialog box, in the Password box, type the custom password if required. Click OK.   For more information, see Creating a SmartX Server
View full article
Admiral StephenYang Admiral
‎2019-06-21 06:11 AM

Labels:
  • EcoStruxure Building Operation
  • Project Configuration Tool
2079 Views

Embedded License activation fails with error FLXERR_RESPONSE_EXPIRED

Issue Cannot activate embedded license on Automation server, either online or offline, with error: FlexNet Embedded error: The allowed time to process the response has expired.   Product Line EcoStruxure Building Operation Environment Building Operation Automation Server Premium Building Operation Automation Server Bundled Building Operation Edge Server - Standard Cause Automation Server has wrong date and time. Resolution Make sure that Automation Server has correct date, time and time zone. Automation Server can be connected to NTP server to synchronize its clock, refer to Synchronizing the Automation Server Clock.
View full article
Kirk Mahmoud_Sayed Kirk
‎2024-02-28 02:00 AM

Last Updated: Janeway PeterEdvik Janeway ‎2024-02-28 02:02 AM

Labels:
  • EcoStruxure Building Operation
2067 Views

Use Static IP instead of DHCP for critical data exchange with SpaceLogic BACnet/IP controller(s)

Issue In SpaceLogic BACnet/IP controllers, a DHCP configuration takes longer than a Static IP configuration to start BACnet communications after a power cycle or restart. Product Line EcoStruxure Building Operation Environment Building Operation Multi-purpose Controller (MP-C) Building Operation Multi-purpose VAV (MP-V) Building Operation Room Controller (RP-C) Building Operation Room VAV (RP-V) Cause The DHCP IP address assignment flow diagram is depicted in this WebHelp article: IP Address Settings for IP Communications. As a part of the failover process, once the controller receives a DHCP lease, it will send multiple ARP requests to ensure the IP address is not being used by another device, further delaying BACnet communications. If it does not detect another device using that IP, it will use the IP it was given to lease. Also, SpaceLogic BACnet/IP controllers store the IP address and port of the controllers for which they have External Binds (Consumers/Producers). If a device is unavailable at that IP address because the DHCP lease has changed, the controller will have to use WHO-IS to find the new address of that controller. Resolution Configure the SpaceLogic BACnet/IP controller with a Static IP address, so the controller will boot directly using a Static IP address and start communicating via BACnet/IP. If on the AS-P Secondary Network with 10.110.210.0/24 network where AS-P DHCP server leases IP addresses from 2 and goes higher, assign static IP in a higher number range (0-254) for the last octet.
View full article
Picard David_Purser Picard
‎2024-02-26 07:36 AM

on ‎2024-02-26 07:36 AM

Labels:
  • EcoStruxure Building Operation
2394 Views

BACnet alarm doesn't work in Project configuration tool (PCT)

Issue BACnet alarm state doesn't update when the monitored variable triggers the alarm in PCT. Product Line EcoStruxure Building Operation Environment Project Configuration Tool Cause BACnet alarms require a live device to send alarms to EBO. Since PCT doesn't have any live devices, BACnet alarms don't work in PCT. Resolution The BACnet alarm feature is not supported in PCT.
View full article
Admiral StephenYang Admiral
‎2024-01-23 03:00 PM

Labels:
  • EcoStruxure Building Operation
  • Project Configuration Tool
1985 Views

How to disable HTTP in Security Expert SOAP web service and Web Client

Issue Need to disable HTTP access for both SOAP web service and Web Client to allow HTTPS access only. Product Line EcoStruxure Security Expert Environment Security Expert Server Security Expert SOAP Web Service Security Expert Web Client Cause Need to disable HTTP access for enhanced cybersecurity Resolution Disable HTTP access for SOAP: Navigate to the SOAP IIS Directory, by default this is "C:\inetpub\wwwroot\SecurityExpertSOAPService" and open the "Web.config" file using a text editor such as Notepad or Notepad++. Scroll down to the <services> section and comment out the following two lines: <endpoint address="" binding="basicHttpBinding" bindingConfiguration="basicHttpEndpointBinding" contract="GXWCF2.IService1" /> <endpoint address="mex" binding="mexHttpBinding" contract="IMetadataExchange" />   To confirm that the HTTPS version of the service is accessible, paste the following link into the URL bar and replace the placeholders with the relevant values: https://<pcname>.<domainname>:<portnumber>/SecurityExpertSOAPService/service.svc. A web page will open with a message saying that the service has been created, this confirms SOAP is working correctly. Disable HTTP access for Web Client: Open Internet Information Server (IIS) manager.  Right click on the SecurityExpertWeb site and select "Edit Bindings".   Remove the HTTP site binding. Configure Web Client to connect to SOAP via HTTPs: Navigate to the IIS directory for the Web Client, by default this is "C:\inetpub\wwwroot\SecurityExpertWebClient". Go to the 'include' directory and open the file 'soap.connect.php" Modify the address on the $wsdl = to the HTTPS SOAP address, and change the port number as well. Additionally, 'localhost' does not work, and it must be changed to hostname with qualified domain name. See below image for reference: Once this change is made it should now be possible to browse to the web client over HTTPS.
View full article
Kirk Mahmoud_Sayed Kirk
‎2024-02-21 03:48 PM

on ‎2024-02-21 03:48 PM

Labels:
  • EcoStruxure Security Expert
2420 Views

Understanding a certificate PEM file

Issue Unsure whether a certificate is in the required PEM file format and what fields it includes to ensure the correct file is installed on the correct server. Sample of certificate -----BEGIN CERTIFICATE----- MIIF+TCCBOGgAwIBAgIRAOUXUXsbB/LpS0VTQsz/HFcwDQYJKoZIhvcNAQELBQAw gY8xCzAJBgNVBAYTAkdCMRswGQYDVQQIExJHcmVhdGVyIE1hbmNoZXN0ZXIxEDAO BgNVBAcTB1NhbGZvcmQxGDAWBgNVBAoTD1NlY3RpZ28gTGltaXRlZDE3MDUGA1UE AxMuU2VjdGlnbyBSU0EgRG9tYWluIFZhbGlkYXRpb24gU2VjdXJlIFNlcnZlciBD QTAeFw0xOTAxMTcwMDAwMDBaFw0xOTA0MTcyMzU5NTlaMFAxITAfBgNVBAsTGERv bWFpbiBDb250cm9sIFZhbGlkYXRlZDERMA8GA1UECxMIRnJlZSBTU0wxGDAWBgNV BAMTD3dlYi1zZWN1cml0eS5jejCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC ggEBAMNC5twUz78YyvW9Y+avpBZLZjGFLZbNZN3tukWL/1wuwLUrhuCju1IDXWnJ a7vu4IFA/m/fgD68Y+I6BEF/tdw94TGc/X0n+Q326ZB3ff8e5+GF2o2oXQCUEX60 wGv17zIx8jCYZtaP9rWekUzWmkNPagImboWeYSLWkt7GvdJCU7VY8kpKm7Y/JF/P Qs4Z5+d4HMsfknJ+PofI7Ve3wT0aPE4aiQ3+MWryxcnZYzH7xNpeB7UbkfFIeDki 4X1vkVFM2Do07IkY9dO8d0UNI3lDDJDpxCCW4kVOl8yQTRtmyPZmtXk5uoyFcCEh KP5/T2gxNr9KNzIornE0F7LZfpMCAwEAAaOCAowwggKIMB8GA1UdIwQYMBaAFI2M XsRUrYrhd+mb+ZsF4bgBjWHhMB0GA1UdDgQWBBSHdiVoz7sMpYkdFsQWYHoMcJZU IzAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIwADAdBgNVHSUEFjAUBggrBgEF BQcDAQYIKwYBBQUHAwIwSQYDVR0gBEIwQDA0BgsrBgEEAbIxAQICBzAlMCMGCCsG AQUFBwIBFhdodHRwczovL3NlY3RpZ28uY29tL0NQUzAIBgZngQwBAgEwgYQGCCsG AQUFBwEBBHgwdjBPBggrBgEFBQcwAoZDaHR0cDovL2NydC5zZWN0aWdvLmNvbS9T ZWN0aWdvUlNBRG9tYWluVmFsaWRhdGlvblNlY3VyZVNlcnZlckNBLmNydDAjBggr BgEFBQcwAYYXaHR0cDovL29jc3Auc2VjdGlnby5jb20wLwYDVR0RBCgwJoIPd2Vi LXNlY3VyaXR5LmN6ghN3d3cud2ViLXNlY3VyaXR5LmN6MIIBBAYKKwYBBAHWeQIE AgSB9QSB8gDwAHYAu9nfvB+KcbWTlCOXqpJ7RzhXlQqrUugakJZkNo4e0YUAAAFo Ww+ePQAABAMARzBFAiEAtZoULgmDyEppYK9nmDWNRjRGcE+BBo/DLaaoaYWg7C8C IH+0UCda6Txcl05inAsMpzlePELyZ3hawgEdmMugK3bXAHYAdH7agzGtMxCRIZzO JU9CcMK//V5CIAjGNzV55hB7zFYAAAFoWw+eiwAABAMARzBFAiEAmdEbql+1pWWf HmpkY34JziCOQzaDlFVtUFen+blgIWwCIBVnwDD3vnwSsrO2T5Clo5Pjqa+xxU7O trLo/ZRGkICBMA0GCSqGSIb3DQEBCwUAA4IBAQAzOM9lS3RSU7rLy8T3BfixHvua ErZ+YOHCHpYhlCeSuFZ66jVHueYWvgfF8A+enRdMM0k0z0PC9enREnumNDq3msCf WYhSLd5lDXiEddg2GCrXkwhOFfOiG0tywS5CD+hLsTq1LQkWDQg7EKlIb6ddhaZO IYEQ9xwE7aehynQEvAjv3UyevMYfvw7glY+MW5bkMfsxPndDD1gDbnYt8kyenjcv odjnkvTw4ngnCy1gF9mVWkgQsE1j34FER1bVtR/FlspI0FB+ogV4Qhso1N23DwtF VDKxH8p+ddYh1LX4b6Oy3dZqzt4HOcunPKsFv36ABpeTs8FPOjgQueTWfHQ4 -----END CERTIFICATE----- Product Line EcoStruxure Building Operation Environment Building Operation Enterprise Central Building Operation Enterprise Server Building Operation Automation Server Building Operation Edge Server Cause A third party provides the certificate files and can have names different from the server installed on and in different formats. Resolution Open the file with a text editor (as seen above in the Issue section). PEM files can include a header or footer that could help identify the certificate. The example above does not. The body has a beginning and ending to describe its contents. —–BEGIN CERTIFICATE REQUEST—– and —–END CERTIFICATE REQUEST—– show a CSR in PEM format. —–BEGIN RSA PRIVATE KEY—– and —–END RSA PRIVATE KEY—– show a private key in PEM format. —–BEGIN CERTIFICATE—– and —–END CERTIFICATE—– show a certificate file in PEM format. The format would look like this if the PEM file included the SSL certificate chain. —–BEGIN CERTIFICATE—– //end-user —–END CERTIFICATE—– —–BEGIN CERTIFICATE—– //intermediate —–END CERTIFICATE—– —–BEGIN CERTIFICATE—– //root —–END CERTIFICATE—– NOTE: There must be a blank line after the END is defined. Ensure there is only one certificate in the file to examine. You may have to copy the file multiple times, open each one, and retain only one per file. Open Command Prompt and find a copy of OpenSSL installed on the machine. OpenSSL installed with EBO Use the following command, where server.pem is the file and file type you are inspecting. openssl.exe x509 -in server.pem -text -noout​ Example output from sample above.  Certificate: Data: Version: 3 (0x2) Serial Number: e5:17:51:7b:1b:07:f2:e9:4b:45:53:42:cc:ff:1c:57 Signature Algorithm: sha256WithRSAEncryption Issuer: C = GB, ST = Greater Manchester, L = Salford, O = Sectigo Limited, CN = Sectigo RSA Domain Validation Secure Server CA Validity Not Before: Jan 17 00:00:00 2019 GMT Not After : Apr 17 23:59:59 2019 GMT Subject: OU = Domain Control Validated, OU = Free SSL, CN = web-security.cz Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:c3:42:e6:dc:14:cf:bf:18:ca:f5:bd:63:e6:af: a4:16:4b:66:31:85:2d:96:cd:64:dd:ed:ba:45:8b: ff:5c:2e:c0:b5:2b:86:e0:a3:bb:52:03:5d:69:c9: 6b:bb:ee:e0:81:40:fe:6f:df:80:3e:bc:63:e2:3a: 04:41:7f:b5:dc:3d:e1:31:9c:fd:7d:27:f9:0d:f6: e9:90:77:7d:ff:1e:e7:e1:85:da:8d:a8:5d:00:94: 11:7e:b4:c0:6b:f5:ef:32:31:f2:30:98:66:d6:8f: f6:b5:9e:91:4c:d6:9a:43:4f:6a:02:26:6e:85:9e: 61:22:d6:92:de:c6:bd:d2:42:53:b5:58:f2:4a:4a: 9b:b6:3f:24:5f:cf:42:ce:19:e7:e7:78:1c:cb:1f: 92:72:7e:3e:87:c8:ed:57:b7:c1:3d:1a:3c:4e:1a: 89:0d:fe:31:6a:f2:c5:c9:d9:63:31:fb:c4:da:5e: 07:b5:1b:91:f1:48:78:39:22:e1:7d:6f:91:51:4c: d8:3a:34:ec:89:18:f5:d3:bc:77:45:0d:23:79:43: 0c:90:e9:c4:20:96:e2:45:4e:97:cc:90:4d:1b:66: c8:f6:66:b5:79:39:ba:8c:85:70:21:21:28:fe:7f: 4f:68:31:36:bf:4a:37:32:28:ae:71:34:17:b2:d9: 7e:93 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Authority Key Identifier: keyid:8D:8C:5E:C4:54:AD:8A:E1:77:E9:9B:F9:9B:05:E1:B8:01:8D:61:E1 X509v3 Subject Key Identifier: 87:76:25:68:CF:BB:0C:A5:89:1D:16:C4:16:60:7A:0C:70:96:54:23 X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Basic Constraints: critical CA:FALSE X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 Certificate Policies: Policy: 1.3.6.1.4.1.6449.1.2.2.7 CPS: https://sectigo.com/CPS Policy: 2.23.140.1.2.1 Authority Information Access: CA Issuers - URI:http://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA.crt OCSP - URI:http://ocsp.sectigo.com X509v3 Subject Alternative Name: DNS:web-security.cz, DNS:www.web-security.cz CT Precertificate SCTs: Signed Certificate Timestamp: Version : v1 (0x0) Log ID : BB:D9:DF:BC:1F:8A:71:B5:93:94:23:97:AA:92:7B:47: 38:57:95:0A:AB:52:E8:1A:90:96:64:36:8E:1E:D1:85 Timestamp : Jan 17 09:06:16.765 2019 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:21:00:B5:9A:14:2E:09:83:C8:4A:69:60:AF: 67:98:35:8D:46:34:46:70:4F:81:06:8F:C3:2D:A6:A8: 69:85:A0:EC:2F:02:20:7F:B4:50:27:5A:E9:3C:5C:97: 4E:62:9C:0B:0C:A7:39:5E:3C:42:F2:67:78:5A:C2:01: 1D:98:CB:A0:2B:76:D7 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 74:7E:DA:83:31:AD:33:10:91:21:9C:CE:25:4F:42:70: C2:BF:FD:5E:42:20:08:C6:37:35:79:E6:10:7B:CC:56 Timestamp : Jan 17 09:06:16.843 2019 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:21:00:99:D1:1B:AA:5F:B5:A5:65:9F:1E:6A: 64:63:7E:09:CE:20:8E:43:36:83:94:55:6D:50:57:A7: F9:B9:60:21:6C:02:20:15:67:C0:30:F7:BE:7C:12:B2: B3:B6:4F:90:A5:A3:93:E3:A9:AF:B1:C5:4E:CE:B6:B2: E8:FD:94:46:90:80:81 Signature Algorithm: sha256WithRSAEncryption 33:38:cf:65:4b:74:52:53:ba:cb:cb:c4:f7:05:f8:b1:1e:fb: 9a:12:b6:7e:60:e1:c2:1e:96:21:94:27:92:b8:56:7a:ea:35: 47:b9:e6:16:be:07:c5:f0:0f:9e:9d:17:4c:33:49:34:cf:43: c2:f5:e9:d1:12:7b:a6:34:3a:b7:9a:c0:9f:59:88:52:2d:de: 65:0d:78:84:75:d8:36:18:2a:d7:93:08:4e:15:f3:a2:1b:4b: 72:c1:2e:42:0f:e8:4b:b1:3a:b5:2d:09:16:0d:08:3b:10:a9: 48:6f:a7:5d:85:a6:4e:21:81:10:f7:1c:04:ed:a7:a1:ca:74: 04:bc:08:ef:dd:4c:9e:bc:c6:1f:bf:0e:e0:95:8f:8c:5b:96: e4:31:fb:31:3e:77:43:0f:58:03:6e:76:2d:f2:4c:9e:9e:37: 2f:a1:d8:e7:92:f4:f0:e2:78:27:0b:2d:60:17:d9:95:5a:48: 10:b0:4d:63:df:81:44:47:56:d5:b5:1f:c5:96:ca:48:d0:50: 7e:a2:05:78:42:1b:28:d4:dd:b7:0f:0b:45:54:32:b1:1f:ca: 7e:75:d6:21:d4:b5:f8:6f:a3:b2:dd:d6:6a:ce:de:07:39:cb: a7:3c:ab:05:bf:7e:80:06:97:93:b3:c1:4f:3a:38:10:b9:e4: d6:7c:74:38 ​ Notable fields include, Issuer: CN = : This is the issuer's common name (CN), Sectigo RSA Domain Validation Secure Server CA, which is the name on the certificate that signed it. If it is the same as a Subject: CN =, then it is, in most cases, Self-Signed. CA Certificates are self-signed and added to a client system in a trust store to be trusted. Validity: Not After: This is the expiration date Subject: CN = : This is the server on which it should be installed common name (CN), in this case, web-security.cz Subject Alternative Name: This Subject Alternative Name (SAN) field can specify alternate server names, like local DNS or IP address. If this server is being used to server content from multiple domains and/or subdomains, all will be listed here. In this sample, two DNS names are listed: web-security-cz and www.web-security.cz. Compare the Common Name (CN) or Subject Alternative Name (SAN) to the address or IP address used to access the server; if it is not one of the included names, then certificate validation will fail. Reference this article to check validity: Verify certificates with OpenSSL
View full article
Picard David_Purser Picard
‎2024-02-20 05:43 AM

Labels:
  • EcoStruxure Building Operation
2759 Views

BACnet multi state object number of states and states label

Issue Can the user set the 'Number of States' and the 'State Text' in a multi state object? Product Line EcoStruxure Building Operation Environment BACnet b3 controllers Multi-state values Cause The b3 firmware does not allow the Number of States or State Text to be modified This is Function as designed. Resolution Continuum DOES NOT allow changes to the default number of states and state labels. The 'Number of States' field is read only. An attempt to change any of the label will result in the following error: An error code was returned from a BACnet operation, but the reason could not be determined. The same is seen in EBO if any attempt is made to edit the State Text, see below
View full article
Picard Product_Support
‎2018-09-06 03:54 PM

Last Updated: Dave_Shore Schneider Alumni (Retired) ‎2024-02-20 01:52 AM

Labels:
  • Andover Continuum
  • EcoStruxure Building Operation
1555 Views

Verify certificates with OpenSSL

Issue Check the host and intermediate certificates with a CA certificate to verify the authentication chain before importing them into EBO servers. Product Line EcoStruxure Building Operation Environment Enterprise Central Enterprise Server Automation Server Edge Server Cause Certificates are provided and can be assigned incorrectly or to the incorrect server; therefore, they do not function as expected. Resolution Verify you have the following: Host certificate in PEM file format Intermediate Certificates in one pem file, not including Certificate Authority (CA) cert CA Certificate where Issuer and Subject Name are the same, indicating it is self-signed. OpenSSL is installed on the computer with the files. Use OpenSSL installed with EBO or install as mentioned in Ensuring the SSL Host Certificate and key file are a matching pair Use this command:  openssl verify -CAfile ca.pem -untrusted intermediate.pem server.pem​ The explanation of the command is as follows: openssl verify: This initiates the certificate verification process. -CAfile ca.pem: Specifies the path to the PEM file containing the trusted CA (Certificate Authority) certificate. -untrusted intermediate.pem: Indicates the path to the PEM file containing the intermediate certificates. They are marked as untrusted because the system does not directly trust them, but their validity will be checked against the CA certificate. server.pem: Specifies the path to the PEM file containing the host server certificate you want to verify. The expected responses are:  server.pem: OK: Verification successful, indicating the server certificate is valid and its chain of trust is established. Error messages: If any errors occur during verification, they'll be displayed in the output. Common errors include certificate expiration, invalid signatures, or missing intermediate certificates Additional information: Ensure the file paths are correct and the certificates are in PEM format Ensure the host and intermediate certificates are installed on the server device and the CA Certificate on the client device. If you encounter issues, double-check the validity of the file permissions and certificates. For more detailed output, add the -verbose option to the command. To check expiration dates, use  openssl x509 -in server.pem -noout -dates
View full article
Picard David_Purser Picard
‎2024-02-19 01:32 PM

on ‎2024-02-19 01:32 PM

Labels:
  • EcoStruxure Building Operation
2262 Views

OpenSSL installed with EBO

Warning Potential for Data Loss: The steps detailed in the resolution of this article may result in a loss of critical data if not performed properly. Before beginning these steps, make sure all important data is backed up in the event of data loss. If you are unsure or unfamiliar with any complex steps detailed in this article, please contact Product Support for assistance. Issue Importing certificates into EBO may require OpenSSL to perform the tasks. Product Line EcoStruxure Building Operation Environment Building Operation Enterprise Server Building Operation Enterprise Central Building Operation Device Administrator Building Operation Automation Server Cause OpenSSL needs to be used to manipulate certificates so they are in the correct format for importing into EBO Servers. Resolution OpenSSL is installed with Enterprise Server, Enterprise Central, and Device Administrator, so use the following path to resolve your installation. In this example, EBO 2022 is installed on the C Drive, so a change in the path may be necessary for your installation. In EBO 2023, OpenSSL was upgraded to 3.x version (3.0.8 dated 7 Feb 2023). Enterprise Server Location: C:\Program Files (x86)\Schneider Electric EcoStruxure\Building Operation 4.0\Enterprise Server\bin\openssl.exe Device Administrator Location: C:\Program Files (x86)\Schneider Electric EcoStruxure\Building Operation 4.0\Device Administrator\OpenSSL\openssl.exe One can use the command openssl version to see the version installed. In this example with EBO 2022 OpenSSL version 1.1.1l (Letter L) dated 24 Aug 2021 is installed.   Enterprise Server  Device Administrator  Use Copy Path to use openssl.exe in the current directory In Windows Explorer, find openssl.exe Hold SHIFT, Right-Click on openssl.exe, and select Copy Path Paste into the command prompt, and you will see double quotes since the path can contain spaces. Continue to type your command and reference files by name in the current directory. 
View full article
Picard David_Purser Picard
‎2022-10-26 02:34 PM

Labels:
  • EcoStruxure Building Operation
3104 Views
  • « Previous
    • 1
    • …
    • 15
    • 16
    • 17
    • …
    • 507
  • Next »
To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2025 Schneider Electric

This is a heading

With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

of