RM ServiceInterface 202002 en
RM ServiceInterface 202002 en
RM ServiceInterface 202002 en
Reference Manual
04045682 - 02/2020
EN
dormakaba EAD GmbH
Albertistraße 3
78056 Villingen-Schwenningen
Germany
T: +49 7720 603-0
www.dormakaba.com
Company headquarters: Villingen-Schwenningen
No part of this document may be reproduced or used in any form or by any means without prior written permis-
sion of dormakaba Schweiz AG.
All names and logos of third-party products and services are the property of their respective owners.
04045682 - 02/2020
Reference Manual Table of contents
Table of contents
1 About this document 5
1.1 Validity 5
1.2 Target group 5
1.3 Contents and purpose 5
1.4 Additional documentation 5
1.5 Orientation in the document 6
1.6 Notes 6
2 Service interface 7
2.1 Purpose and function 7
2.2 Use of the service interface 7
4 Service functions 11
4.1 Overview of the service functions 11
4.1.1 ‘System’ menu group 11
4.1.2 ‘Settings’ menu group 11
4.1.3 'Firmware' menu group 12
4.2 Basic operation 12
5 System functions 13
5.1 Information/System Information 13
5.2 Information/Statistics 13
5.3 Licence 14
5.3.1 Extension of the licence 16
5.3.2 Adjustment of the licence when service is required 16
5.4 Licence/Test Licence 16
5.5 Diagnosis 17
5.6 Administration 17
5.6.1 Terminal restart 17
5.6.2 Resetting SSH key 17
5.7 Reboot 17
6 Settings 18
6.1 Network settings 18
6.1.1 Requesting an IP address from the DHCP server 18
6.1.2 Requesting an IP address from the DHCP server on the basis of
the terminal name 19
6.1.3 Assigning a permanent IP address 19
6.2 WLAN Settings 20
6.3 Host settings 21
6.3.1 Communication via Ethernet/UDP 21
6.3.2 Encryption 22
6.3.3 Host registration 22
6.3.4 Communication via Ethernet/XML 22
6.3.5 Basic Authentication 23
6.3.6 Group identification and device identification 23
Index 33
This documentation describes the functions of the service interface from the following ver-
sions:
The descriptions are intended for already trained personnel. They cannot replace product
training.
Additional documentation is available on the Internet at the dormakaba website. The tech-
nical manuals are located in a protected area. They can be accessed via the user account of
trained professionals. However, you can also create a temporary account.
https://www.dormakaba.com/extranet-emea-en
• The table of contents at the beginning of the document offers an overview of all topics.
• The header contains the associated main section.
• Cross references indicate the number of the section containing additional information.
Example [ 5.7].
• An index in alphabetical order is given at the end of the document.
1.6 Notes
Notes marked with symbols must be observed in particular.
NOTICE
Important information on the correct use of the product.
Failure to comply with these instructions could lead to malfunctions. It is possible to damage
the product.
2 Service interface
2.1 Purpose and function
The service interface provides the functions that are required for start-up, maintenance, and
diagnostics of the device.
The service interface is provided by the web server integrated into the device. Access takes
place via the network connection of the device, either directly or via the network. For direct
connection, an Ethernet cross-over cable (crossed RJ45 cable) or an Ethernet patch cable 1:1
can be used (Auto MDIX).
The service interface can be accessed from a service PC via a web browser by typing the
device IP address into the address box.
The service interface is part of the BaseApp. It is used in the following android-based termin-
als.
• Terminal 96 00
• Terminal 97 00
The Web server service on the terminal can be be enabled- disabled by settings of the ter-
minal software (TA command record). Access to the service interface is only possible if the
Web server is active.
The SFTP server (SSH server service) on the terminal can be enabled- disabled by settings of
the terminal software (TA command record).
• Access manager 92 00
• Access manager 92 30
• Access manager 92 90
The device must already have a valid network configuration, and it must be possible to access
it via the network.
If the IP address of the device is unknown, the following measures can be taken.
Option 2: Display the settings of the terminal software by pressing the menu key. The IP ad-
dress will be shown on the display, for example.
Option 2: Determine or assign IP address using the Device Discovery Tool. This is only possible
if the device is waiting for host registration, indicated by red/green flashing LEDs.
The Device Discovery Tool is available for download at the dormakaba site in the secured
area.
Format Example
The browser may report that the certificate is not trustworthy after the first call. In this case,
confirm that the page is trustworthy and can be displayed.
3.5 Login
After loading the service interface, your are prompted for your user name and password.
admin admin
root root
After login as user ‘root’, both passwords can be changed using the ‘User management’ func-
tion.
4 Service functions
4.1 Overview of the service functions
4.1.1 ‘System’ menu group
Chapter Function/Description
Chapter Function/Description
5 System functions
5.1 Information/System Information
In this function, important system information, such as device type, versions of the software
used, MAC address and IP address of the device, is displayed.
Example:
5.2 Information/Statistics
Displays the runtime since last system start and the usage of the internal memory.
Example:
Explanations:
5.3 Licence
Display of the current terminal software licence
Example:
The usable range of functions of the device is given by the options activated in the sop.ini li-
cence file by means of the corresponding licence key.
The licence file is only valid on the device having the entered MAC address. Any manual
change to the contents of the file will render the licence void.
From the parameters, you can determine which functions are enabled.
Depending on the device, the licence file can contain the following entries:
Sections
Section Meaning
Entry Meaning
Entry Meaning
Entry Meaning
Other parameters
Entry Meaning
Licence-related parameters
Entry Meaning
Test-licence-related parameters
Entry Meaning
The adjusted licence file can be generated online in the dormakaba Extranet.
.
After entering the old and new MAC addresses, the adjusted licence file can be downloaded.
The range of functions is taken from the old licence, only the licence key is adjusted to the new
MAC address.
Condition:
The replaced component must be received by the dormakaba Repair Department for repair
within 4 weeks, otherwise you will be invoiced for the new licence file.
The licence key will be valid for 7 days. After the validity has expired, the terminal software
can no longer be started.
A total of five time-limited licence keys can be generated. By using an unlimited licence file,
this counter will be reset.
This function is only available for access managers equipped with B-Client AC30 terminal
software. If no licence file is available, android-based terminals will automatically generate a
test licence that is valid for 20 days.
5.5 Diagnosis
The diagnosis functions allow access to system logfiles.
For problem solution, logfiles must in many cases be evaluated by the dormakaba Support.
When service is required, logfiles must be made available to the dormakaba Support upon re-
quest.
Logs overview
Overview of the logfiles generated by the terminal software
Current logs
Logfiles generated by the operating system
Support information
Generates a zip file containing all logfiles and configuration files.
This support information is usually requested by the dormakaba Support for problem solution.
5.6 Administration
Android-based devices only.
The default SSH key (SFTP security file) can be downloaded from the dormakaba Extranet.
5.7 Reboot
Devices with B-Client AC30 terminal software only
This function can be used to perform a restart or cold start of the device.
6 Settings
6.1 Network settings
6.1.2 Requesting an IP address from the DHCP server on the basis of the
terminal name
6.3.2 Encryption
This function is used to activate or deactivate data encryption via Ethernet.
These settings are required if the terminal is logged on to the host using Basic Authentication
in accordance with RFC 2617.
User and password for Basic Authentication. Leave fields empty if Basic Authentication is not
used.
In connection with the B-COMM communication software, the following must be observed
when assigning the device identification GID:
For devices with connected subterminals, the device identifications must be assigned in steps.
The device identifications in-between are reserved for subterminals.
These settings are required if subterminals with biometric reader have been connected (ac-
cess manager) or if the device has an internal biometric reader.
The FTCS service can be made available by the host server defined under’Host Set-
tings’ [} 6.3] or by a separate host server. The settings are required in both cases.
1. Enter IP address of the computer on which you want the FTCS service to run (B-COMM
server). If a DNS has been configured, it is also possible to enter the FTCS host name in
this field.
2. Select the UDP port to be used for communication in the ‘Port’ field. Hexadecimal values
must be prefixed by ‘0x’. Default=0x7800.
The settings are required if a separate host server is used for distributing the CardLink-spe-
cific parameters and registration records. The settings are not required if the host server
defined under ‘Host Settings’ [} 6.3] is also used for distributing the CardLink-specific para-
meters and registration records.
1. Enter IP address of the host providing the CardLink data. If a DNS has been configured, it
is also possible to enter the CardLink host name in this field.
2. Select the UDP port to be used for communication in the ‘Port’ field. Hexadecimal values
must be prefixed by ‘0x’. Default=0x7700, possible values: 0x7700-0x77EF.
Encryption
The function UDP encryption is optional. Using this function requires the presence of a suit-
able licence.
The ‘Enable Encryption’ check box can be used to enable or disable encryption via Ethernet
UDP.
These reader settings correspond to the device configuration at the time of delivery. The func-
tion is usually only required if an external reader is connected at a later stage or if LEGIC is
switched over to MIFARE in connection with an MRD reader.
For LEGIC media, the ‘LEGIC’ reader type has been factory-preset.
For processing MIFARE media, the reader type must be changed to ‘MIFARE’.
LEGIC media are configured via the files ‘mediaact.ini’ and ‘mediadef.ini’.
When using older B-COMM versions < 4.1.0, the reader types LEGIC_4200 (deprecated) or
MIFARE_4200 (deprecated) must be used.
6.6.2 Interface
To set the interface the reader is connected to.
Terminal 96 00
Internal COM interface = COM3
Terminal 97 00
The device supports up to three readers. Depending on options, the reader assignment of the
COM ports is as follows:
6.7 Add-On
This function is used to enable the external inputs/outputs.
Type Meaning
Preset Enroll is a preset value for supporting the entry of the template ID during the Enroll
and Unenroll procedures.
The preset value defines a character string displayed in the ‘Template ID’ field. When entering
the template ID, the character string is overwritten from the right. This makes it unnecessary
to enter leading zeros or leading constants, so that the template ID has a constant length in
all templates.
When entering the template ID manually, the entry of leading zeros is omitted. The presetting
generates a LEGIC-compliant booking record.
Allowed values are the characters ‘1’ to ‘9’, ‘A’ to ‘F’ and the special characters ‘:’, ‘;’, ‘<’, ‘=’, ‘>’
and ‘?’. There is no limit to the length of the preset value.
Example:
[Reader1CBM]
PresetBooking = 0000000002000000000000
Result:
Template ID 12345
1 Identification
2 Verification
3 Verification by ID comparison
4 Combination of modes 1 and 2
5 Combination of modes 2 and 3
The authentication mode cannot be changed during operation.
This setting can also be made under the menu item Sensors [} 6.11.2]. For a description, see
Sensors/Biometric Proximity Sensor [} 6.11.2].
Alternatively, operation without biometric software is also possible. In this ‘Standalone mode’,
all fingerprints of persons must be registered by the reader of the terminal. In this case, the
finger templates are only saved in the reader’s internal database. If they get lost, all persons
have to be registered again at the terminal.
This is why the Standalone mode without biometric software is only recommended for very
small solutions (max. 20 persons).
The ‘Standalone mode’ check box defines whether a standalone mode without FTCS is pos-
sible (activate) or not (deactivate).
If operation in standalone mode once enabled is reset, all locally enrolled fingerprints will be
deleted.
The Standalone parameter is stored in the system.ini configuration file, section [Reader-
1CBM]. Possible values 0 (not active) or 1 (active).
The finger templates of the reader-internal database cannot be read for security reasons.
If an NTP server is available in the network, ‘NTP’ (Network Time Protocol) can be selected un-
der ‘Use Network Time’.
Enter the IP address of the NTP server in the NTP Server field.
If no NTP server is available, ‘Disabled’ must be selected. In this case, date and time can be set
manually.
The users ‘admin’ and ‘root’ are permanently stored. The user names cannot be changed, and
no further users can be added.
Brightness (in %)
To set the display brightness in the range from 30% to 100%.
Presetting = 70%
Reduced brightness
After a defined time without user activity, the display brightness can be automatically re-
duced.
The function is enabled or disabled via the ‘Timeout use reduced brightness’ check box.
The time until this energy-saving mode is initiated can be set in a range between 30 and 3600
seconds. Presetting = 120 seconds.
Standby
After a defined time without user activity, the terminal can be switched to the Standby mode.
In Standby mode, the display is completely dark.
To signal that the terminal is in the Standby mode ready-to-operate, the reader lighting can
be activated in a pulsed manner
The function is enabled or disabled via the ‘Use Standby’ check box.
The time until the Standby mode is initiated can be set in a range between 60 and 14,400
seconds. Presetting = 0 seconds (disabled).
By activating the ‘Pulse Lighting’ check box, the reader lighting (RFID light ring) is activated in
a pulsed manner.
The lighting duration can be set in a range between 1000 ms and 5000 ms.
Presetting = 1500 ms.
Between the individual lighting signals, a pause twice the lighting duration takes place. At a
presetting of 1500 ms, the reader lighting will be lit every 3 seconds for 1.5 seconds each.
Sensitivity of the proximity sensor in the biometric fingerprint reader. Possible settings:
• Disabled
• Low sensitivity
• Medium sensitivity
• High sensitivity
The proximity sensor enables the biometric reader. If the proximity sensor is disabled, the
reader must be enabled by touching a function key.
In most cases, the presetting ‘Medium Sensitivity’ ensures an optimum function of the sensor.
However, certain environmental conditions can make it necessary to adjust the sensitivity.
The setting ‘High Sensitivity’ takes up a high percentage of the system resources and may
lengthen the time of execution of background activities (e.g. downloads).
6.12 HR-Client
For android-based terminals, the following functions are available.
Following the system start, ‘Waiting for registration” appears on the display.
Index
B I
Basic Authentication 23 IP address 19
Biometric mode 28
Biometric proximity sensor 31 L
Biometrics 27 Licence 14
Brightness 30 Licence extension 16
Logfiles 17
C Login 10
CardLink host settings 24
Change password 29 M
Communication via Ethernet/UDP 21 MRD reader 25
Communication via Ethernet/XML 22
N
D Network settings 18
Data encryption 22
Date and time 29
P
DHCP server 18, 19
Password 10
Diagnosis functions 17
Password for Basic Authentication 23
DID 23
Preset Booking 27
Display brightness 30
PresetEnroll 27
DNS server 19
Proximity Scale 28
Proximity sensor 30
E Proxy server 23
Enabling Add-On 26
Enabling inputs/outputs 26
R
Encryption 22
Reader settings 25
Extension of the licence 16
Reader type 25
Reboot 17
F Resetting SSH key 17
FTCS host settings 24
S
G Selecting the language 10
GID 23 Sensors 30
Globe icon 10 Software licence 14
Group identification and device identification 23 sop.ini 14
Guard time 26 SSID 20
Standalone mode 28
H Support information 17
Host registration 22 Supported browsers 8
Host settings 21
HTTP/HTTPS 22 T
Terminal restart 17
Terminal software licence 14
Test licence 16
U
User for Basic Authentication 23
User management 29
User name 10
W
WLAN Settings 20