Support · Installation · License · Related Integrations
The Mobotix IP Camera Orchestrator extension remotely manages TLS certificates on Mobotix IP Network Cameras (x7 and x8 models).
This extension provides functionality to:
- Inventory the TLS certificate used by the camera's web server
- Enroll and install a new TLS certificate for use by the camera's web server
Since Mobotix cameras do not support on-device key generation, the extension performs certificate enrollment by:
- Generating a private key pair in memory on the orchestrator server
- Creating and submitting a CSR to Command
- Receiving the issued certificate
- Uploading the private key and certificate to the camera via REST API
- Rebooting the device to apply the new certificate
This job type is still referred to as ODKG (On Device Key Generation) in Keyfactor Command — the platform-wide name for a Reenrollment job — even though for Mobotix the key pair is generated on the orchestrator server rather than on the device itself.
This workflow is fully automated.
- Inventory of TLS certificate (web server only)
- Automated enrollment and installation of TLS certificates
- Upload of certificates outside the enrollment workflow
- Removal of certificates from the camera
- Management (add/remove) of CA certificates on the device
This integration is compatible with Keyfactor Universal Orchestrator version 25.1 and later.
The Mobotix IP Camera Universal Orchestrator extension is supported by Keyfactor. If you require support for any issues or have feature request, please open a support ticket by either contacting your Keyfactor representative or via the Keyfactor Support Portal at https://support.keyfactor.com.
If you want to contribute bug fixes or additional enhancements, use the Pull requests tab.
Before installing the Mobotix IP Camera Universal Orchestrator extension, we recommend that you install kfutil. Kfutil is a command-line tool that simplifies the process of creating store types, installing extensions, and instantiating certificate stores in Keyfactor Command.
- Out of the box, a Mobotix IP Network Camera will typically have configured an Administrator account. It is recommended to create a new account specifically for executing API calls. This account will need 'Administrator' privileges since the orchestrator extension is capable of making configuration changes, such as enrolling new certificates.
- Network connectivity from orchestrator to camera over HTTP/HTTPS
Supported on Mobotix x7 and x8 model cameras (per the Mobotix API).
- Tested model: Mobotix v71
- Tested software version: MX-V7.3.5.35
Has not been tested with any other model or software version.
The Mobotix IP Camera Orchestrator Extension uses .NET HttpClientHandler credential negotiation when connecting to Mobotix devices over HTTPS. This allows the orchestrator to automatically negotiate the authentication mechanism required by the camera. The orchestrator has been validated against Mobotix cameras configured with:
- Basic
- Digest
- Auto
As a result, customer-side changes to camera authentication policies are generally not required.
To use the Mobotix IP Camera Universal Orchestrator extension, you must create the MobotixIPCamera Certificate Store Type. This only needs to happen once per Keyfactor Command instance.
The Mobotix IP Camera certificate store type represents the TLS configuration of a Mobotix IP network camera, including the certificate and private key used by the camera's web server.
Only a single TLS certificate can be active on the camera at any time. Updating the certificate replaces the existing one. The default certificate installed on the camera is the factory device ID certificate.
- A user Account with 'Administrator' privileges
- Camera IP address (and possible port number)
| Operation | Is Supported |
|---|---|
| Add | 🔲 Unchecked |
| Remove | 🔲 Unchecked |
| Discovery | 🔲 Unchecked |
| Reenrollment | ✅ Checked |
| Create | 🔲 Unchecked |
kfutil is a custom CLI for the Keyfactor Command API and can be used to create certificate store types.
For more information on kfutil check out the docs
Click to expand MobotixIPCamera kfutil details
This will reach out to GitHub and pull the latest store-type definition
# Mobotix IP Camera
kfutil store-types create MobotixIPCameraIf required, it is possible to create store types from the integration-manifest.json included in this repo. You would first download the integration-manifest.json and then run the following command in your offline environment.
kfutil store-types create --from-file integration-manifest.jsonBelow are instructions on how to create the MobotixIPCamera store type manually in the Keyfactor Command Portal
Click to expand manual MobotixIPCamera details
Create a store type called MobotixIPCamera with the attributes in the tables below:
| Attribute | Value | Description |
|---|---|---|
| Name | Mobotix IP Camera | Display name for the store type (may be customized) |
| Short Name | MobotixIPCamera | Short display name for the store type |
| Capability | MobotixIPCamera | Store type name orchestrator will register with. Check the box to allow entry of value |
| Supports Add | 🔲 Unchecked | Indicates that the Store Type supports Management Add |
| Supports Remove | 🔲 Unchecked | Indicates that the Store Type supports Management Remove |
| Supports Discovery | 🔲 Unchecked | Indicates that the Store Type supports Discovery |
| Supports Reenrollment | ✅ Checked | Indicates that the Store Type supports Reenrollment |
| Supports Create | 🔲 Unchecked | Indicates that the Store Type supports store creation |
| Needs Server | ✅ Checked | Determines if a target server name is required when creating store |
| Blueprint Allowed | 🔲 Unchecked | Determines if store type may be included in an Orchestrator blueprint |
| Uses PowerShell | 🔲 Unchecked | Determines if underlying implementation is PowerShell |
| Requires Store Password | 🔲 Unchecked | Enables users to optionally specify a store password when defining a Certificate Store. |
| Supports Entry Password | 🔲 Unchecked | Determines if an individual entry within a store can have a password. |
The Basic tab should look like this:
| Attribute | Value | Description |
|---|---|---|
| Supports Custom Alias | Forbidden | Determines if an individual entry within a store can have a custom Alias. |
| Private Key Handling | Forbidden | This determines if Keyfactor can send the private key associated with a certificate to the store. |
| PFX Password Style | Default | 'Default' - PFX password is randomly generated, 'Custom' - PFX password may be specified when the enrollment job is created (Requires the Allow Custom Password application setting to be enabled.) |
The Advanced tab should look like this:
For Keyfactor Command versions 24.4 and later, a Certificate Format dropdown is available with PFX and PEM options. Ensure that PFX is selected, as this determines the format of new and renewed certificates sent to the Orchestrator during a Management job. Currently, all Keyfactor-supported Orchestrator extensions support only PFX.
Custom fields operate at the certificate store level and are used to control how the orchestrator connects to the remote target server containing the certificate store to be managed. The following custom fields should be added to the store type:
| Name | Display Name | Description | Type | Default Value/Options | Required |
|---|---|---|---|---|---|
| ServerUsername | Server Username | Enter the username of the configured "service" user on the camera | Secret | ✅ Checked | |
| ServerPassword | Server Password | Enter the password of the configured "service" user on the camera | Secret | ✅ Checked | |
| ServerUseSsl | Use SSL | Select True or False depending on if SSL (HTTPS) should be used to communicate with the camera. | Bool | true | ✅ Checked |
| BypassTlsValidation | Bypass TLS Validation | If true and 'Use SSL' is enabled, TLS certificate validation is skipped when connecting to the camera. Has no effect when 'Use SSL' is false. Only enable this when the camera's certificate cannot be trusted by the orchestrator server. | Bool | false | ✅ Checked |
The Custom Fields tab should look like this:
Enter the username of the configured "service" user on the camera
[!IMPORTANT] This field is created by the
Needs Serveron the Basic tab, do not create this field manually.
Enter the password of the configured "service" user on the camera
[!IMPORTANT] This field is created by the
Needs Serveron the Basic tab, do not create this field manually.
Select True or False depending on if SSL (HTTPS) should be used to communicate with the camera.
If true and 'Use SSL' is enabled, TLS certificate validation is skipped when connecting to the camera. Has no effect when 'Use SSL' is false. Only enable this when the camera's certificate cannot be trusted by the orchestrator server.
-
Download the latest Mobotix IP Camera Universal Orchestrator extension from GitHub.
Navigate to the Mobotix IP Camera Universal Orchestrator extension GitHub version page. Refer to the compatibility matrix below to determine which asset should be downloaded. Then, click the corresponding asset to download the zip archive.
Universal Orchestrator Version Latest .NET version installed on the Universal Orchestrator server rollForwardcondition inOrchestrator.runtimeconfig.jsonmobotix-ipcamera-orchestrator.NET version to downloadBetween 11.0.0and11.5.1(inclusive)net8.0LatestMajornet8.011.6and newernet8.0net8.025.5and newernet10.0net10.0Unzip the archive containing extension assemblies to a known location.
Note If you don't see an asset with a corresponding .NET version, you should always assume that it was compiled for
net10.0. -
Locate the Universal Orchestrator extensions directory.
- Default on Windows -
C:\Program Files\Keyfactor\Keyfactor Orchestrator\extensions - Default on Linux -
/opt/keyfactor/orchestrator/extensions
- Default on Windows -
-
Create a new directory for the Mobotix IP Camera Universal Orchestrator extension inside the extensions directory.
Create a new directory called
mobotix-ipcamera-orchestrator.The directory name does not need to match any names used elsewhere; it just has to be unique within the extensions directory.
-
Copy the contents of the downloaded and unzipped assemblies from step 2 to the
mobotix-ipcamera-orchestratordirectory. -
Restart the Universal Orchestrator service.
Refer to Starting/Restarting the Universal Orchestrator service.
-
(optional) PAM Integration
The Mobotix IP Camera Universal Orchestrator extension is compatible with all supported Keyfactor PAM extensions to resolve PAM-eligible secrets. PAM extensions running on Universal Orchestrators enable secure retrieval of secrets from a connected PAM provider.
To configure a PAM provider, reference the Keyfactor Integration Catalog to select an extension and follow the associated instructions to install it on the Universal Orchestrator (remote).
The above installation steps can be supplemented by the official Command documentation.
Click to expand details
-
Navigate to the Certificate Stores page in Keyfactor Command.
Log into Keyfactor Command, toggle the Locations dropdown, and click Certificate Stores.
-
Add a Certificate Store.
Click the Add button to add a new Certificate Store. Use the table below to populate the Attributes in the Add form.
Attribute Description Category Select "Mobotix IP Camera" or the customized certificate store name from the previous step. Container Optional container to associate certificate store with. Client Machine The IP address of the Camera. Sample is "192.167.231.174:44444". Include the port if necessary. Store Path Enter the camera's factory IP address, as shown in the camera's web UI at initial setup. Used to validate the camera's factory certificate. Orchestrator Select an approved orchestrator capable of managing MobotixIPCameracertificates. Specifically, one with theMobotixIPCameracapability.ServerUsername Enter the username of the configured "service" user on the camera ServerPassword Enter the password of the configured "service" user on the camera ServerUseSsl Select True or False depending on if SSL (HTTPS) should be used to communicate with the camera. BypassTlsValidation If true and 'Use SSL' is enabled, TLS certificate validation is skipped when connecting to the camera. Has no effect when 'Use SSL' is false. Only enable this when the camera's certificate cannot be trusted by the orchestrator server.
Click to expand details
-
Generate a CSV template for the MobotixIPCamera certificate store
kfutil stores import generate-template --store-type-name MobotixIPCamera --outpath MobotixIPCamera.csv
-
Populate the generated CSV file
Open the CSV file, and reference the table below to populate parameters for each Attribute.
Attribute Description Category Select "Mobotix IP Camera" or the customized certificate store name from the previous step. Container Optional container to associate certificate store with. Client Machine The IP address of the Camera. Sample is "192.167.231.174:44444". Include the port if necessary. Store Path Enter the camera's factory IP address, as shown in the camera's web UI at initial setup. Used to validate the camera's factory certificate. Orchestrator Select an approved orchestrator capable of managing MobotixIPCameracertificates. Specifically, one with theMobotixIPCameracapability.Properties.ServerUsername Enter the username of the configured "service" user on the camera Properties.ServerPassword Enter the password of the configured "service" user on the camera Properties.ServerUseSsl Select True or False depending on if SSL (HTTPS) should be used to communicate with the camera. Properties.BypassTlsValidation If true and 'Use SSL' is enabled, TLS certificate validation is skipped when connecting to the camera. Has no effect when 'Use SSL' is false. Only enable this when the camera's certificate cannot be trusted by the orchestrator server. -
Import the CSV file to create the certificate stores
kfutil stores import csv --store-type-name MobotixIPCamera --file MobotixIPCamera.csv
Attributes eligible for retrieval by a PAM Provider on the Universal Orchestrator
If a PAM provider was installed on the Universal Orchestrator in the Installation section, the following parameters can be configured for retrieval on the Universal Orchestrator.
| Attribute | Description |
|---|---|
| ServerUsername | Enter the username of the configured "service" user on the camera |
| ServerPassword | Enter the password of the configured "service" user on the camera |
Please refer to the Universal Orchestrator (remote) usage section (PAM providers on the Keyfactor Integration Catalog) for your selected PAM provider for instructions on how to load attributes orchestrator-side.
Any secret can be rendered by a PAM provider installed on the Keyfactor Command server. The above parameters are specific to attributes that can be fetched by an installed PAM provider running on the Universal Orchestrator server itself.
The content in this section can be supplemented by the official Command documentation.
Cameras are typically provisioned with a self-signed or otherwise untrusted device identity certificate. The Use SSL and Bypass TLS Validation certificate store properties together determine what's required to connect successfully:
| Use SSL | Bypass TLS Validation | Behavior |
|---|---|---|
False |
(any) | Connects over plain HTTP. There is no TLS handshake, so certificate trust does not apply, and Bypass TLS Validation has no effect either way. |
True |
True |
Connects over HTTPS but skips certificate validation entirely - any certificate is accepted, including the camera's untrusted factory certificate. |
True |
False |
Connects over HTTPS and validates the certificate like any other TLS connection - see below for what's required to pass. |
Warning
It is highly recommended to keep Use SSL enabled. Plain HTTP sends credentials and certificate data to the camera unencrypted, and is only intended as a fallback for cameras or networks that cannot support HTTPS.
When Use SSL is True and Bypass TLS Validation is False, install the certificate's issuing
intermediate and root CAs into the orchestrator server's local trust store so that standard TLS validation
succeeds. This applies both to the camera's initial factory certificate and, later, to whatever certificate is
enrolled from the customer's own PKI - each requires its own issuing intermediate and root CAs to be trusted,
since they're typically different CAs.
This only applies when Use SSL is True and Bypass TLS Validation is False.
While the camera still has its factory certificate, its SAN reflects the camera's IP address at the time of manufacture, not wherever it's actually deployed. This causes a name mismatch even when the issuing CAs are trusted. To resolve this:
- Enter the camera's factory IP address (shown in the camera's web UI at initial setup) as the certificate store's Store Path value.
- When the certificate's SAN contains that value, and the certificate is otherwise trusted (its issuing intermediate and root CAs are installed on the orchestrator server), the connection succeeds despite not matching the camera's current network address.
- This doesn't change anything about trust itself: a certificate that doesn't chain to a trusted CA still fails, regardless of Store Path.
Note
This check only compares the certificate's SAN against the recorded Store Path value - it does not verify which CA issued the certificate. It is not intended to distinguish the camera's factory certificate from a customer-issued certificate that happens to carry the same value, for example due to a misconfigured enrollment.
Note
This only applies while the camera presents its factory certificate. Once a customer-PKI certificate is enrolled via ODKG, its SAN should match the address actually used to connect to the camera (the store's Client Machine value), and this factory-IP exception no longer comes into play.
Important
Inventory and Reenrollment (ODKG) jobs both connect to the camera using the same HTTP/HTTPS connection, so Bypass TLS Validation affects both job types.
The following enrollment behaviors are specific to Mobotix cameras and should be considered when designing certificate automation workflows.
Mobotix devices support only a single TLS server certificate for the camera's web server, and the integration manages only that certificate — no others on the device are in scope. Every ODKG job replaces it at the same fixed location and reboots the device to apply the change.
A typical ODKG job configuration for a Mobotix certificate store:
- Store Path: the camera's factory IP address (see Device Onboarding)
- Overwrite:
trueorfalse(has no effect) - Alias: (only shown if Overwrite is checked; has no effect)
In this configuration:
- The ODKG job generates a new certificate and private key
- They are uploaded to the camera's fixed certificate location (
httpd_cert.pem), replacing the previous certificate - The device reboots, after which the new certificate becomes active and is the certificate presented in subsequent TLS sessions with the camera's web server
Operational behavior:
- The Overwrite and Alias fields have no effect — there is only one certificate slot on the device, and every job always replaces it, regardless of these settings
- Store Path is used only for the factory-certificate TLS validation described under Device Onboarding; it does not identify or affect which certificate file is managed on the camera
- Inventory always reports this certificate to Command with a fixed Alias of
HTTPS, regardless of Store Path or the job-configuration Alias field above
Important
The camera may take several minutes to reboot and become reachable again. During this time, API calls (such as Inventory jobs) will fail because the device is temporarily unavailable.
Tip
Wait for the camera to fully come back online before initiating additional jobs, such as Inventory or ODKG.
As of Keyfactor Command v25.4, Subject Alternative Names (SANs) can be specified for ODKG jobs. Support for passing SANs to the orchestrator also requires, at minimum, Keyfactor Universal Orchestrator v25.1.
This integration supports DNS, IP, and URI SAN types. Any other SAN type included in the ODKG job stops the job before a certificate is requested, rather than being silently dropped from the enrolled certificate. SANs are not automatically added if none are supplied.
No known troubleshooting guidance available at this time.
Only the end-entity (leaf) certificate is inventoried and enrolled by this integration - intermediate and root certificates in the issuing chain are not automatically retrieved or bundled. If the leaf's issuing intermediate and root certificates are separately present in Command (for example, imported independently), Command can still build and display the complete chain for that certificate. This applies to both Inventory and Reenrollment (ODKG) jobs.
1.0.0
- Initial Public Version.
- Improved HTTP communication diagnostics to improve troubleshooting of camera connectivity and communication issues.
- Updated ODKG job initialization to align with the other jobs.
- Removed an unnecessary dependency path that could prevent the ODKG job loading in certain environments.
- Added support for PAM credential retrieval.
- Added
Use SSLandBypass TLS Validationcertificate store properties, including support for validating a factory-fresh camera's certificate and reporting specific TLS validation failure reasons. - Added support for URI Subject Alternative Names, in addition to DNS and IP; unsupported SAN types now stop the enrollment job with a clear error instead of being silently dropped.
- Fixed issues where Inventory could report zero certificates without failing, and where enabling Bypass TLS Validation could cause an unexpected error retrieving the camera's certificate.
Apache License 2.0, see LICENSE.