Configuration
Operating Manual PITreader, PITreader Firmware V1.5.x
1004806-EN-08
| 37
Certificates and private keys are not part of the device configuration and cannot be down-
loaded to other devices using the function Save configuration/Restore configuration.
8.3.2 Incorporate certificate into a public key infrastructure (PKI)
To incorporate a PITreader into an existing public key infrastructure you can either upload a
separate server certificate to the device together with its private key or download a certific-
ate signing request (CSR) from the PITreader, import it into your existing PKI and upload
the signed certificate back to the device.
Certificates can be loaded on to the device in PEM (certificate or certificate + private key) or
DER format (certificate only).
The device supports certificates based on one of the following cryptographic processes:
} ECC (prime256v1, secp256r1 or NIST P-256), recommended
} RSA (2048 Bit)
8.4 Configure authentication mode
You can configure the authentication mode for the PITreader in the web application under
Configuration -> Settings. Select either "Transponder data" or "External" authentication
mode.
8.5 Configure authentication type
You can configure the authentication type for the PITreader in the web application under
Configuration -> Settings. Select one of the authentication types "Basic", "Single authen-
tication" or "2-person rule".
8.6 Location description
In the web application, under Configuration -> Settings -> Location description, you can
enter a description of the location of the PITreader. A maximum of 47 characters are per-
mitted.
8.7 Data logging with personal data
In the web application you can select whether personal data (security ID, user and IP ad-
dress) is to be logged in the diagnostic log under Configuration -> Settings -> Function.
This function is activated in the default configuration.
8.8 Set device group
In the web application, under Configuration -> Settings -> Function, you can assign a
device group to the PITreader (see also Device groups [ 15]). Under Configuration ->
Device groups you can enter a name for each of the device groups from 0 … 31. A max-
imum of 47 characters are permitted. If you have entered a name for a device group, when
you assign the device group under Configuration -> Settings -> Function, the corres-
ponding name is displayed in the selection list. If no name has been entered, the number of
the device group is displayed.