Categories
Technical Advisory Bulletins Knowledge Support exacqVision EDGE exacqVision Enterprise Support exacqVision Client Other exacqVision Server exacqVision Mobile exacqVision Webservice exacqVision Hardware Products exacqVision Integrations

Support procedure for reporting newly discovered cyber security vulnerabilities in Exacq Software 

This document will outline the procedures expected from Exacq Support staff in the event of discovering a previously unreported security vulnerability in an exacqVision product.

Product 

Any exacqVision product

Procedure:

  1. Verify the vulnerability has not already been properly reported at: https://www.johnsoncontrols.com/cyber-solutions/security-advisories
  2. Email the GPS (Global Product Security) team at: productsecurity@jci.com
    • Provide vulnerability analysis in this email and any relevant links
    • Provide customer details and contact information in this email
    • Provide software product and software versions in this email
    • CC the customer on the email
  3. Inform the customer you have notified the appropriate team (GPS) and will be closing the Support ticket.

Our Global Product Security team will then be responsible for following up with this customer and resolving vulnerability.

<br>

Categories
exacqVision Enterprise Windows exacqVision Enterprise Linux exacqVision Enterprise 23.03 exacqVision Enterprise 22.12 Software Categories Knowledge Support Support exacqVision Enterprise

Enterprise Manager fails to save edits to Custom User Roles

Description 

Support has identified an issue affecting Customer User Roles in some Enterprise Manager public release versions.

This issue prevents camera permissions such as video inputs and edits from being saved, and these permission checkboxes may “uncheck” themselves after a period of short time. This issue has been resolved in later versions.

Product 

ExacqVision Enterprise Manager Versions:
22.12.0.0
23.03.0.0

Steps to Reproduce 

  • Create a Custom User Role
  • Attach valid User/Users to this Custom User Role
  • edit permissions such as video inputs
  • Save the configuration changes
  • Wait a few minutes
  • Edit the Custom User Role you created and observe the previously saved edits

Expected Results 

The edits made to the Custom User Role should be saved.

Actual Results 

The edits made to the Custom User Role are not saved, and the checkboxes have “unchecked” themselves.

Solution

Upgrade Enterprise Manager software version to 23.06.2.0.
AES-347 , AES-530

Categories
exacqVision Server 22.12 exacqVision Client Other exacqVision Server 22.09 exacqVision Enterprise Windows exacqVision Server 22.06 exacqVision Enterprise 23.03 exacqVision Server 22.03 exacqVision Enterprise 22.12 exacqVision Server Other exacqVision Enterprise 22.09 exacqVision Client Windows exacqVision Enterprise 22.06 exacqVision Client 23.03 exacqVision Enterprise 22.03 exacqVision Client 22.12 exacqVision Enterprise Other exacqVision Server Windows exacqVision Client 22.09 exacqVision Server Windows x64 exacqVision Client 22.06 exacqVision Server 23.03 exacqVision Client 22.03 Knowledge Support Support exacqVision Client exacqVision Server exacqVision Hardware

Recording Not Possible – Windows DST Issue

Description 

If the exacqVision Server data drives are full and are displaying “Recording Not Possible” on the storage page then it is possible an invalid hour folder was created during the switch to Daylight Savings Times (DST).  Use the following instructions to verify and resolve the issue. 

Product 

  • exacqVision Server

Solution

These instruction are based on Windows OS and North America DST.

  • Check DST Rules for your area here.
  • Make note of the Date and Time of the change to DST and determine if an invalid folder exist.
  • For this example most of North America changed to DST on March 12th, 2023 at 02:00 AM
  • Therefore any .ps or .psi files stored in the folder D:\2023\03\12\02 are in the wrong folder.
  • The folder either needs to be removed or the files need to be moved to D:\2023\03\12\03
  • Note: D: is the disk letter which will vary across systems with more than one disk.
    i.e. – E:\2023\03\12, F:\2023\03\12, etc.

Use File Explorer to Edit Directory

  • Log into the Exacq server OS using your Admin credentials
  • Open “File Explorer”
  • When File Explorer opens navigate to data drive
    D: > 2023 > 03 > 12
  • NOTE: If your system has more than 1 data drive, you will also need to look in each mount point/disk letter and repeat this process listed below.
    i.e. – look in E: > 2023 > 03 > 12, F: > 2023 > 03 > 12, etc. 
  • If you find a folder named “02” within
    D:\2023\03\12 you will need to copy the contents to
    D:\2023\03\12\03 then delete this 02 folder.
  • Repeat this process for all data drives attached. Optionally, you can delete this 02 folder altogether, but only with permission from the system administrator.
  • Restart the ExacqVision server service from the services.msc console:

Note:
Depending on the amount of data retention the system has it may be necessary to go back to previous years to make the same edits for Daylight Savings Time changes.

In Example:
DST change was March 13th in 2022. You would find the 03/13/2022 directory, and make the same edits removing the 02 hour folder or moving the contents of the 02 hour folder to the 03 folder in this directory.

Categories
Knowledge Support Support exacqVision Enterprise Categories Products

How to use the Camera Inspection tool

Enterprise Manager (EM), formerly known as Enterprise System Manager (ESM), includes a feature called Camera Inspection which allows EM users to notate cameras which need attention for a later date.

This handy feature means you can easily create a punch list of cameras which need attention for integrator/installer work orders to do things such as:

  • Clean camera domes/lenses
  • Maintain camera focus on subjects
  • Trim foliage or remove debris blocking camera views
  • Re-orient camera field of view if a camera has been tampered with or nudged
  • Investigate network issues<br><br>

  1. Log into Enterprise Manager (EM) with an account that has live viewing privileges.
    See Configuring live video streams in Enterprise Manager<br><br>
  2. Beneath the Cameras header on the navigation menu, click on Inspection.<br><br>
  3. A paginated view of available cameras is displayed. Each camera listed will display the Server Group name / Server name / Camera name at the top of its box.
    • Orange border = Has not been checked
    • Green border = Marked Good
    • Red border = Marked Bad
  1. To work effectively a reference image would have been set when the camera was added/installed. This image appears on the left and can be set using the Use current image as camera image link on the camera details page.<br><br>
  2. Use the Camera Inspection page by comparing the current snapshot on the right with the one on the left. <br><br>
    • Mark Good if you are pleased that the current snapshot indicates no action is needed.
    • Mark Bad if further action is needed.
    • Clicking the View Details link allows the user to enter additional comments, such as “Camera is out of focus”, or, “Camera dome needs cleaned”. Comments could also include notes about the person or date/time an issue was resolved. The bottom corner allows navigating through all cameras one by one while in the details/comments view.
  1. After marking each camera, you may export a report to provide your integrator/installer.
    <br><br>
  2. After issues have been fixed, use the Camera Inspection tool to Mark Fixed.<br><br>

<br>

Categories
Exclude from Global Search Plugin Log Level Verbose exacqVision Enterprise Products Logs Other

psycopg2.errors.ForeignKeyViolation: update or delete on table “organization_enterpriseuser” violates foreign key constraint “auditlogger_auditlog_user_id_*****_fk_organizat” on table “auditlogger_auditlog”

psycopg2.errors.ForeignKeyViolation: update or delete on table “organization_enterpriseuser” violates foreign key constraint “auditlogger_auditlog_user_id_%1_fk_organizat” on table “auditlogger_auditlog”

Description

Reviewing

Notes

%1 suggest the user id number.%BR%
See KB 15724 for resolution.

Categories
Knowledge Support Support exacqVision Enterprise exacqVision Client exacqVision Server Products

Downgrading Enterprise Manager software from 23.06 to lower versions


Downgrading ExacqVision Enterprise Manager from 23.06.0.0 to any version lower will prevent users from accessing the ExacqVision Client software due to the migration to AES-128 from ARC4 Encryption methods used on earlier ExacqVision Enterprise Manager versions. 

Downgrading or “Rolling Back” Enterprise Manager software from versions 23.06.0.0 and up to a lower version is not recommended due to this encryption migration.

Note: It is advised to take an Enterprise Manager backup of your system prior to attempting any upgrades/downgrades. Best Practices would include taking a database back up of PostgreSQL or Microsoft SQL.

Product 

ExacqVision Enterprise Manager versions 23.06.0.0 and higher subsequently released versions.

Steps to Reproduce 

  • Downgrade ExacqVision Enterprise Manager software to any prior version from 23.06.0.0

Expected Results 

This downgrade should complete reflecting the new version, and all functionality should remain intact.

Actual Results 

ExacqVision Client users will receive the error: “Invalid Username/Password account locked or disabled” upon trying to log in after the downgrade has been performed.

Solution

Do not downgrade from ExacqVision Enterprise Manager versions 23.06.0.0 to a lower version. If you find this needs to happen for an unforeseen reason it is recommended to uninstall the current version of Enterprise Manager 23.06.0.0 or higher, followed by installing the desired legacy version which will require rebuilding the configuration.

Categories
Knowledge Support exacqVision Enterprise Support Products

EM Displaying Red Banner and DataRoll Off with high Resource Consumption

Description 

EM experiencing High resources and data roll off banner.

Product 

Enterprise Manager 23.03
Windows 10

Steps to Reproduce 

  • Log into EM and if you see a Red Roll Off Banner.
  • Check system resources for high CPU and Memory.
  • Check Data Roll off logs for the following error.

psycopg2.errors.ForeignKeyViolation: update or delete on table "organization_enterpriseuser" violates foreign key constraint "auditlogger_auditlog_user_id_fbf03342_fk_organizat" on table "auditlogger_auditlog"

DETAIL: Key (id)=(2) is still referenced from table "auditlogger_auditlog"

Expected Results 

We should not see high Resources and Data Roll Off Banner.

Actual Results 

High Memory, CPU, and Red Banner Data Roll Off.

Solution

Update to exacqVisionEnterpriseManager_23.06.101.0_x64.exe or official EM release 23.06.

AESW-4786

Categories
Knowledge Support Video Library Demo Release Notes Support exacqVision Enterprise Other exacqVision Client exacqVision Server exacqVision Webservice Categories Products

2023-06 June Quarterly Release Training

ExacqVision Server

Bug Fix – Fixed excessive Archiving status messages (AESW-4989)

Bug Fix – Debian installer no longer enabled eventpi by default

Bug Fix – Fixed issue capturing all metadata when multiple events are sent as one alarm

Bug Fix – Ensure eventpi database is purged after server reboot

Bug Fix – Fixed connection status problem from Axis cameras with older firmware

Bug Fix – Prevent needing to restart client after adding Axis body worn camera system, caused by receiving cert before configuration (AESW-3445)

Bug Fix – Fixed potential streaming issue from Exacq’s RTSP Server resulting in gaps (AESW-5251)

Bug Fix – Fixed problem where time triggers were not firing on some days (AESW-4573)

Bug Fix – Fixed socket crash from Bosch intrusion plugin (AESW-5105)

Bug Fix – Fixed a problem with stale metadata for Illustra3 and Illustramulti plugins

Bug Fix – Restart the SSL session and restart metadata on error 94 from Illustra3 and Illustramulti plugins (AESW-4574)

Bug Fix – Corrected issue with missing codecs from Panasonic camera plugin causing them to default to JPEG (AESW-631)

Bug Fix – Fixed issue with motion issues on some Panasonic cameras (AESW-4794)

Bug Fix – Fixed problem with issue making settings changes to Panasonic multisensor (AESW-4562)

Enhancement – Improvements made to search results returned for audio/video events

Enhancement – Improved loading time of eventpi

Enhancement – Cameras previous detected as Samsung are now detected as Hanwha Vision
(AESW-5539, AESW-5538)

Enhancement – Added Hanwha Vision option (AESW-5189)

Enhancement – Integration of WiseAI analytics from Hanwha

Enhancement – Enhanced camera discovery for new Illustra Flex Dual Sensor camera (AESW-5541)

Enhancement – Server installer no longer checks Illustrapi or Illustraflexpi for install by default

Enhancement – Changed the reported name to “Illustra Multisensor”

Enhancement – Added legacy tag to Illustrapi and Illustraflexpi

Enhancement – Added support for Axis “Optics Control” autofocus (AESW-2649)

Enhancement – Added support for Bosch “RuleEngine” analytics (AESW-1326)

ExacqVision Client

Bug Fix – wxWidgets version upgrade
New installs, not upgrades, automatically select dark or light theme based on the OS theme and prevent user changes
(AESW-5146)

Enhancement – Copy selected camera information when adding a new camera
If camera is highlighted in IP Cameras List on the Add Cameras page when the New button is clicked, the Device Type field will automatically populate with the same as that which was highlighted saving time from selecting from Device Type list.
(AESW-5855)

ExacqVision Web Service

Bug Fix – Updated nvrg version to fix group type retrieval, fixes issue with group items (AESW-3340)

Bug Fix – Updated nvrg version to fix a soft trigger bottleneck, fixes issue where triggers from web or mobile client resulted in status flickering between ‘Alarm’ and ‘Normal’ in Desktop Client. (AESW-3816)

ExacqVision Enterprise Manager

Bug Fix – Improved logging for DynamicDNS files for Integrator Service Portal (AESW-5897)

<br>

Categories
Configuration Knowledge Support Documentation Support exacqVision Enterprise exacqVision Client exacqVision Server Products Uncategorized exacqVision Integrations

Enterprise Manager supports LDAP authentication with Azure Active Directory 

Azure Active Directory supports the LDAP interface when properly configured, and therefor LDAP can be used to sync the ExacqVision Enterprise Manager software with the Azure AD instance.

Background Information: Lightweight Directory Access Protocol (LDAP) is an application protocol for working with various directory services. Directory services, such as Active Directory, store user and account information, and security information like passwords. The service then allows the information to be shared with other devices on the network. Enterprise applications such as email, customer relationship managers (CRMs), Video Management Software (VMS – ExacqVision), and Human Resources (HR) software can use LDAP to authenticate, access, and find information.

Azure Active Directory ( sometimes referred to as Azure AD) supports this pattern via Azure AD Domain Services (sometimes referred to as AD DS). This allows organizations that are adopting a cloud-first strategy to modernize their environment by moving off their on-premises LDAP resources to the cloud. ExacqVision has supported the use of LDAP authentication since early versions, and now has been enhanced to support the use of LDAP authentication when integrated with Azure Active Directory as a modern solution to cloud based computing.

When a network hosting Enterprise Manager on-premise has been properly configured for communication with an Azure Active Directory instance by verifying no port restrictions or other environmental variables inhibit communication – ExacqVision Enterprise Manager has the ability to support the use of LDAP authentication with Azure Active Directory as of December 15th, 2022 – and subsequent releases thereafter.  

Products 

  • ExacqVision Enterprise Manager version 22.12.0.0 and up

Minimum Requirements for ExacqVision Enterprise Manager Software: 

  • Enterprise Manager version must be 22.12.0.0 or later
  • Your network configuration must be properly configured to communicate with your Azure AD instance
  • you must have Azure Active Directory credentials with access to the following Active Directory parameters – as supplied by your Local IT Department or Network Administrator: objectClass (specifically “group” & “user”), userPrincipalName , sAMAccountName , inetOrgPerson , krbPrincipalName

Configuration Steps for Enterprise Manager: 

  • Properly configure the network to communicate with Azure Active Directory instance without restriction.
  • Verify you possess the minimum credential requirements needed to complete the integration as listed above (supplied by your Local IT Department or Network Administrator) and login to Enterprise Manager user interface with administrative privileges
  • Navigate to the Domain settings page
  • Under “Add Domain” enter the address of the Azure Active Directory instance in the “Hostname or IP” field and enter the above mentioned credential criteria with the proper port number, security protocol, Search Criteria information, and Attribute names information in their corresponding fields – as supplied by your Local IT Department or Network Administrator
  • Apply the changes.

Expected Results 

The above steps when executed properly will sync with the Azure AD Instance, allowing LDAP authentication in ExacqVision Enterprise Manager.

For more information on how to configure ExacqVision Enterprise Manager for use with LDAP authentication please see the ExacqVision Enterprise Manager user manual.

Categories
Knowledge Support Support exacqVision Enterprise exacqVision Webservice

EM server can’t update the web service and showing “Remote Restriction”

Description

When connecting the web service to the EM server, The EM server can connect to the web service. However, it can’t push an update to it or remotely administrate the web service and keeps going back and force between “Remote Restriction” and “Running

Solution

This issue has been fixed on Enterprise Manager Version 23.03.103 or above

The EM ver 23.03.103 can be downloaded Here