<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CameraStack Tools on CameraStack</title><link>https://camerastack.io/tools/</link><description>Recent content in CameraStack Tools on CameraStack</description><generator>Hugo</generator><language>en-gb</language><atom:link href="https://camerastack.io/tools/index.xml" rel="self" type="application/rss+xml"/><item><title>TLS Manager manual</title><link>https://camerastack.io/tools/tls-manager/manual/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://camerastack.io/tools/tls-manager/manual/</guid><description>&lt;p&gt;CameraStack TLS Manager configures and checks HTTPS on ONVIF cameras.
It can manage a simple self-signed certificate, enrol a camera-held key
with your certificate authority, verify secure media transports, and
clean up unused objects created by CameraStack TLS tools.&lt;/p&gt;
&lt;p&gt;The application never exports a camera private key. It keeps HTTP
enabled while setting up or rotating a certificate. Disabling HTTP is a
separate action with its own confirmation and recovery checks.&lt;/p&gt;</description></item><item><title>CameraStack TLS Manager</title><link>https://camerastack.io/tools/tls-manager/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://camerastack.io/tools/tls-manager/</guid><description>&lt;p&gt;CameraStack TLS Manager is a desktop application for giving network
cameras a proper TLS identity, and for keeping that identity healthy.
It speaks the standard ONVIF Advanced Security service and the
&lt;a href="https://www.onvif.org/add-on/tls-configuration-add-on/"&gt;TLS Configuration Add-on&lt;/a&gt;,
so it works with CameraStack Server and with other cameras that
implement the same operations. It discovers local ONVIF cameras and
keeps the connection panel and long-running operation progress visible.&lt;/p&gt;
&lt;figure class="arch-figure"&gt;
 &lt;img src="https://camerastack.io/images/camerastack-tls-manager.png"
 alt="CameraStack TLS Manager managing a self-signed camera identity"
 loading="lazy" decoding="async"&gt;
&lt;/figure&gt;
&lt;h2 id="what-it-does"&gt;What it does&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Inspect keys, certificates, certification paths, TLS server
assignments and live HTTPS state.&lt;/li&gt;
&lt;li&gt;Create, verify and renew self-signed identities.&lt;/li&gt;
&lt;li&gt;Adopt an existing certificate without changing the camera.&lt;/li&gt;
&lt;li&gt;Create a camera-held key and CSR for your private Certificate
Authority, then validate and atomically activate the certificate the
CA returns. The private key never leaves the camera.&lt;/li&gt;
&lt;li&gt;Diagnose every advertised secure transport: HTTPS, snapshots, RTSP
over HTTPS, secure WebSocket and native &lt;code&gt;rtsps://&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Store passwords and accepted certificate pins in the
operating-system vault.&lt;/li&gt;
&lt;li&gt;Preview dependency-aware cleanup before deleting anything.&lt;/li&gt;
&lt;li&gt;Export a sanitized support bundle.&lt;/li&gt;
&lt;li&gt;Disable plain HTTP only after repeating the secure-management checks.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;TLS Manager does not contain a production Certificate Authority. It
exports the CSR for the CA software your organisation already runs,
then resumes from a non-secret journal when the issued certificate is
ready.&lt;/p&gt;</description></item></channel></rss>