SKNS
v2.0
Skans Docs/How-tos/Trust or forget a device certificate
How-tos

Trust or forget a device certificate

Skans does not send a device password, an API secret, or an SSH password to a peer it has not pinned. The pin is the SHA-256 of that device’s web certificate or SSH host key. Until one of those is recorded, a job that would have used the password is refused.

A pin that is present but not a 64-character hex SHA-256 matches nothing. It is not treated as “no pin.”

HTTPS is not retried as HTTP. A driver that cannot speak HTTPS names the step that turns HTTPS on. It does not open a second connection, and it does not enable HTTPS itself.

On the device page #

Open the device and choose the Certificate tab. This tab is not shown for an agent. The panel is titled What Skans trusts this device to be.

Two rows: Web certificate and SSH host key. An armed row shows the SHA-256 and when it was recorded.

With device-manage permission:

  • Trust the certificate it presents now
  • Trust the SSH host key it presents now
  • Forget the recorded certificate or Forget the recorded SSH host key — shown when a pin is armed or malformed

The headline depends on why nothing is armed:

  • Never pinned: Not pinned — no certificate is recorded yet (or no SSH host key). That line does not say credentials are withheld. A first recording on the lanes below is still allowed.
  • Forgotten: Not pinned — Skans will not send credentials to this device.

First recording does not use the password #

Trusting the certificate opens a TLS handshake and hashes the leaf. No device password is sent. Trusting the SSH host key reads the key during key exchange and does not use the device password. This page does not claim a packet capture of that SSH handshake.

Storing the password in the vault is not the same as sending it. Some jobs record a pin themselves before they send the password: auto-onboard (the password is stored first, then the pin is recorded, then the device is provisioned), certificate deployment, controller SSH, config backup, and the device SSH tool. A job that only reads pins, and finds none on a device Skans already knows, refuses with pin this device first.

An automatic capture does not replace a pin that is already recorded. Trusting again from this tab, or with --pin-device, is how an operator records a new fingerprint after a legitimate change (reimage, factory reset).

Forget #

Forget writes a marker first, then removes the pin. Skans will not probe or record a replacement by itself. The next automatic job refuses until an operator trusts the device again, from this tab or with --pin-device.

Forget writes that marker before it removes the pin. A trust that was already in progress can still clear the marker. That race is still in the code.

From the appliance CLI #

Run these on the appliance. A missing device exits 1. Bad arguments exit 2.

POWERSHELL
# Read-only. Prints the TLS and SSH headlines. --ssh is a usage error.
Skans.ControlPlane.exe --show-pin <name|ip|publicId>

# Record the certificate on port 443, or the SSH host key with --ssh (port 22).
# A port argument overrides the default. This is an operator trust: it clears a forget marker.
Skans.ControlPlane.exe --pin-device <name|ip|publicId> [port] [--ssh]

# Write the forget marker. Exits 0 when the device resolves, even if nothing was recorded.
Skans.ControlPlane.exe --forget-pin <name|ip|publicId> [--ssh]

--pin-controller is a different verb. It records a network controller’s TLS certificate and SSH host key independently.

A device with no current address cannot be pinned: the command reports that and exits 1.

Firmware #

A firmware push uses https:// only. Any other URL, including an http:// override, is refused before a preflight and before the password is read: firmware is only pushed over https. A confirmed push also needs an armed web-certificate pin. A forgotten SSH host key refuses the push as well. A preflight does not check the pin. The image is hashed again against the repository’s recorded SHA-256 before it is sent.

Turn on HTTPS on the device #

Where a driver speaks HTTPS only, turn HTTPS on in the device’s own web UI, then trust the certificate Skans sees. These are the menus in the driver pack. A camera that only speaks HTTP is refused.

  • Honeywell current 30-Series, 35-Series, and current equIP: Setup > Network Setup > HTTPS, turn HTTPS on, Save. Legacy equIP and Performance Series: Setup > Network Setup, HTTPS Setting, Save.
  • Uniview and FS (FS uses the Uniview web UI): Setup > Security > Network Security > HTTPS, turn on, Save. The port is under Setup > Network > Port (443 unless you changed it).

Uniview and FS certificate deployment can send an enable call on that HTTPS API. That call is HTTPS. It is not a retry over HTTP, and it is not SSH.

This page does not claim that every driver in the pack has been checked for an HTTP fallback. The rule above is what the pin check, the HTTPS-only refusal, firmware push, and these three vendor menus do.

Next #