cancel
Showing results for 
Search instead for 
Did you mean: 

SSL certificate authentication failed, continue loading?

SSL certificate authentication failed, continue loading?

abene
Member

SSL certificate authentication failed, continue loading? -error message appears during the boot of the core with webiq server installed. Is there a solution where to set the ssl? Please advise.

15 REPLIES 15

Sgilk
Contributor

Hello,

What versions of ctrlX CORE firmware and WebIQ runtime are you using? SSL support in WebIQ was removed and replaced with TLS.

Documentation on WebIQ TLS: WebIQ TLS 

In newer versions of the WebIQ runtime application, an HTTPS connection to the WebIQ application can be made via the ctrlX OS reverse proxy. You can create and install the TLS certificate following this process: ctrlX OS HTTPS

@CodeShepherd This should probably be moved to WebIQ sub.

webiq-sk
Frequent Contributor

The message is not a WebIQ message, this seems to come from ctrlX itself maybe?
Also, the message states "SSL Certificate authentication failed" - "certificate authentication" rather than "certificate verification" which sounds more like some more internal thing? It also doesn't bring up a lot of results on Google.

The user also pointed out that it "appears during the boot of the core" - maybe this is something unrelated to WebIQ?

CodeShepherd
Community Moderator
Community Moderator

@abene please always add pictures of the complete screen so we can see what the problem is related to.

Which HMI are you using?
Which path do you try to open and how do try to do that?

Please check also the topic "WR21 in kiosc mode does not refresh ctrlX CORE´s IP" for some other information about booting topics of HMI.

Hi there, thanks for responding. Below is the current app config on CtrlX Core.

1.20.0
Automation Core
Basic automation functionalities

2.15.3
WebIQ Server App (Runtime App)

I am using the WR207W HMI. In Kiosk the following path is set:
https://111.111.111.111/webiq/webiq-ctrlx-template-v0

webiq-sk
Frequent Contributor

Are you intentionally using a public IP address on the internet associated with a company in Japan for running your ctrlX?

whois 111.111.111.111
% [whois.apnic.net]

inetnum: 111.96.0.0 - 111.111.255.255
netname: KDDI
descr: KDDI CORPORATION
descr: Garden Air Tower,3-10-10,Iidabashi,Chiyoda-ku,Tokyo,102-8460,Japan

I assume you rather want to use an internal IP address for your network - in this case you cannot use arbitrary IP addresses - there is only a certain number available: https://en.wikipedia.org/wiki/Private_network - the IP address 111.111.111.111 would be routed to the internet automatically, not to your network. You can use 10.*.*.* or 192.168.1.* for example.

I don't know if this could cause this issue, just wanted to point this out.

 

There is more detailed info I can provide after testing different options.


1. The "SSL certificate authentication failed, continue loading?" -error message only occurs when using the "Kiosk" as default android app after power-up.
When "Chromium" is set to the same destination start address (https://abc.def.ghi.jkl/webiq/webiq-ctrlx-template-v0) in this case, there is no issue with the error message, however the connection remains unsafe, http vs https.
2. Now the issue is how to run "Chromium" in full-screen, kiosk-like mode.


3. The problem with not synchronized startups between CtrlX-Core and HMI running android still remains, see my related post https://developer.community.boschrexroth.com/t5/Smart-HMI-WebIQ-Designer-and/WEBIQ-4008-ctrlX-WebIQ-...

(* Sorry, the IP in previous post was just an example I randomly put in the command. The actual address of course is the core static assigned permanent address.)

CodeShepherd
Community Moderator
Community Moderator

@abene On point number 2: Could you explain a bit more what you mean by "the connection remains unsafe, http vs https"?
The connection to a ctrlX CORE in general is encrypted and safe. What you could see is, that browser tells you the certificate serverd is self signed (as it is by the controller) and so connection is not trusted and could be unsecured. Please see "How to make an HTTPS connection with ctrlX OS Web Server" for how to create own certificates and import them into the ctrlX CORE and your browser to establish a trusted connection.

 

Hi there and thanks for the answer. Instead of "unsafe" I should put "unsecured or not trusted" as the browser clearly shows. I will try to configure the certificates as described in the guide.
The issue here really is
1. how can this configuration be done in case of Chromium browser or Kiosk running on the ctlX HMI
2. In case Chromium is used, how can it run in full-screen, kiosk-like mode

3. The startup time synchronization is solved using the recommended startup.html addition until a firmware update addresses the problem.
https://developer.community.boschrexroth.com/t5/Smart-HMI-WebIQ-Designer-and/WEBIQ-4008-ctrlX-WebIQ-...

bkautzman
Established Member

I believe this is the same issue that I posted about here. As I mentioned in my most recent reply, I don't believe this is related to WebIQ. Do you also see the same security message if you direct the WebStation to your ctrlX core web UI?

V_A
Long-established Member

Hello,
unfortunately I have the same problem: in kiosk mode the warning "SSL certification failed, continue loading?" appears immediately after restarting the system.
After confirming the warning with continue, the interface opens normally and I can operate the system.
However, it is unpleasant that the message always appears.
What exactly is the solution in this case?

HMI:
MNR: R11411947 FD: 22W33 (7260)
Android version 10
Kios App V1.0.6
WebIQ Server App 2.15.3
OPC UA Server 1.20.3

Hello,

I have the same problem with a customer. When he tries to connect to the HMI (based on webIQ) he gets the message "SSL certificate authentication failed". I would like to know if it is possible to delete this message.

davifas_1-1715340416047.png

I tried installing a certificate on the ctrlX HMI device and on the ctrlX Core. After a successful installation, the main page of the 192.168.4.183 ctrlX Core no longer asks to accept the certificate as usually happens. But the HMI page (based on the same address 192.168.4.183) still displays the SSL certificate popup.

ctrlX version 1.20
ctrlX HMI WR21

Hello @davifas ,

Which version of WebIQ runtime is installed on the ctrlX CORE? SSL support was dropped in WebIQ a number of versions back. See this note from the documentation. TLS is now used as standard.

 

Sgilk_1-1715342385838.png

 

Hello @Sgilk,

thanks for your reply. Customer has the following configuration: 

  • WebIQ Server App: 2.15.6
  • WebIQ Designer: 2.15.4
  • CtrlX Core 1.20

Should we update WebIQ Designer? 

@davifas ,

I think you are at a sufficient version that it is not the cause of the message. I think this might be a problem with the certificate manager in the panel and not with WebIQ configuration.

Icon--AD-black-48x48Icon--address-consumer-data-black-48x48Icon--appointment-black-48x48Icon--back-left-black-48x48Icon--calendar-black-48x48Icon--center-alignedIcon--Checkbox-checkIcon--clock-black-48x48Icon--close-black-48x48Icon--compare-black-48x48Icon--confirmation-black-48x48Icon--dealer-details-black-48x48Icon--delete-black-48x48Icon--delivery-black-48x48Icon--down-black-48x48Icon--download-black-48x48Ic-OverlayAlertIcon--externallink-black-48x48Icon-Filledforward-right_adjustedIcon--grid-view-black-48x48IC_gd_Check-Circle170821_Icons_Community170823_Bosch_Icons170823_Bosch_Icons170821_Icons_CommunityIC-logout170821_Icons_Community170825_Bosch_Icons170821_Icons_CommunityIC-shopping-cart2170821_Icons_CommunityIC-upIC_UserIcon--imageIcon--info-i-black-48x48Icon--left-alignedIcon--Less-minimize-black-48x48Icon-FilledIcon--List-Check-grennIcon--List-Check-blackIcon--List-Cross-blackIcon--list-view-mobile-black-48x48Icon--list-view-black-48x48Icon--More-Maximize-black-48x48Icon--my-product-black-48x48Icon--newsletter-black-48x48Icon--payment-black-48x48Icon--print-black-48x48Icon--promotion-black-48x48Icon--registration-black-48x48Icon--Reset-black-48x48Icon--right-alignedshare-circle1Icon--share-black-48x48Icon--shopping-bag-black-48x48Icon-shopping-cartIcon--start-play-black-48x48Icon--store-locator-black-48x48Ic-OverlayAlertIcon--summary-black-48x48tumblrIcon-FilledvineIc-OverlayAlertwhishlist