AK-SM 800A Series

  • Overview
  • Product security
  • Downloads
  • Documents
  • Related products
  • Disclaimer

AK-SM 800A Series

The AK-SM 800A offers secure system control and monitoring whilst including energy saving functions that contribute to continuous and autonomous energy savings for your stores.

SM800A_0187_SMG09.000.141_SVB501.000.141.spk

AK-SM 800A series software package

System Manager AK-SM 800A software package v4.0x and above enhances your product's security features to meet internationally recognized regulations. Danfoss is now defaulting to a strong security posture and is following secure by design principles.

This new feature is called Strict Session Control and when combined with HTTPS improves overall security of your product 

Product security

Danfoss takes security seriously and as part of our continued improvements, new measures are being implemented. Please review below important security updates included in the latest AK-SM 800A software update that may impact your upgrade experience

System Manager AK-SM 800A software package v4.0x and above enhances your product's security features to meet internationally recognized regulations such as the NIS2 and CRA Directives. Also following the global standard IEC 62443-4-1 Standard regarding IT security by design principles

In compliance, Danfoss is now defaulting to a strong security posture on the System Manager Ak-SM 800A, via software package 4.0.x and above. This feature is called Session Control and when combined with HTTPS improves overall security of your product.

What is Session Control?

Sesson control in the AK-SM 800A is an authentication rules engine/module and is intended to improve the overall security posture of your system. Session control offers different configuration settings (Backward compatibility, Permissive and Strict). Depending on how these settings are configured, the remote interface will need to comply accordingly.

What is a remote Interface?

The term remote interface refers to StoreView Browser 5 (SvB5), StoreView Web (SvW), Alsense™ (Danfoss Digital services) and 3rd party XML1.0. SvB5, SvW and Alsense™ already support Session control. 3rd party XML1.0 users will need to update requests if Strict mode remains selected (see below).

What are these Session Control settings?
The important aspect to note is that immediately after installing System Manager AK-SM 800A software package 4.0.x and above, Strict mode is set by default. These settings can always be managed via the System Manager Configuration>Security menu (Supervisor permission level required).

Session Control setting

Description
Backward Compatible Not recommended but when selected, http is available, and no session tokens needed
Permissive (used as a transition to strict level) Set this level to view any error responses so that adjustments can be made in preparation for strict mode. Permissive is allowing both the old authentication and the new authentication scheme at the same time.

Strict

(defaulted immediately after s/w package R4.0.x install)
Require HTTPS connection XML requests cannot contain usernames and passwords.  Must provide session token in the AKSM-auth header. HTTPS becomes mandatory and authentication moves from plain-text to session-based authentication.  Strict mode will sanitize all strings in the Northbound connection of XML, rejecting any commands that conflict with the sanitization.

 

After AK-SM 800A software package 4.0.x is installed, Strict mode is default, what does this mean?

  • Your AK-SM 800A now requires secure Internet standard of HTTPS (encrypts all data in transit)
  • In Strict mode, 3rd Party XML communications to the AK-SM 800A cannot contain usernames/passwords and must provide the session token in the AKSM-auth header
  • For AK-SM 800A systems that have 3rd party XML interfaces, Danfoss has supporting documentation, please contact Danfoss Technical Support
  • Depending on your method of upgrade a pop-up message will be presented, informing of Strict mode but also allowing fall back to Backward compatible
  • Depending on your method of upgrade your remote browser session my be lost. In this event you may need to manually type https in front of your system managers IP / DNS name
  • After the software installation you may revert back to (weaker configuration) by selecting ‘Backward Compatible’ mode – Danfoss recommends Strict mode.

Important installation notes for System Manager Release 4.0.x

Before upgrading to Release4.0, take a moment to review your current implementation. For instance: check how your AK-SM 800A network is configured, are any 3rd Party XML entities involved?

After installation of System Manager software package 4.0x the unit will reboot and will Immediately default to Strict enforce level.

If you are uncertain about your AK-SM800A's current configuration for web communications, we strongly recommend performing on-site update only or having personnel on-site or contact Danfoss Technical support for further guidance

If your AK-SM 800A application is already configured for HTTPS, the remote update will not require any additional manual steps apart from confirming Strict mode.

If your AK-SM 800A application is configured for HTTP, there will be a workaround to support a remote update dependent on network setting (detailed guidelines will follow), but in case of any doubt an on-site update is always recommended.

Documents

Documents
Type Name Language Valid for Updated Download File type
Application guide AK-SC 255 / SM 800 to AK-SM 800A conversion English Multiple 17 Apr, 2024 1.8 MB .pdf
Operating guide AK-SM 800A R4.0 Change Log English Multiple 10 Jul, 2024 179.3 KB .pdf
Application guide AK-SM 800A Series: Security Guidance and Session Control English Multiple 28 Jun, 2024 652.9 KB .pdf
User guide AK-System Manager, AK-SM 800A series English Multiple 09 Jul, 2024 11.8 MB .pdf
User guide AK-System Manager, AK-SM 800A series Chinese (CN) Multiple 11 Apr, 2023 12.1 MB .pdf
User guide AK-System Manager, AK-SM 800A series Italian Multiple 11 Apr, 2023 11.9 MB .pdf
User guide AK-System Manager, AK-SM 800A series Polish Multiple 28 Apr, 2023 11.9 MB .pdf
User guide AK-System Manager, AK-SM 800A series Portuguese Brazil 11 Apr, 2023 39.6 MB .pdf
User guide AK-System Manager, AK-SM 800A series Spanish, Castilian Multiple 11 Apr, 2023 11.9 MB .pdf
User guide AK-System Manager, AK-SM 800A series French Multiple 11 Apr, 2023 11.9 MB .pdf
User guide AK-System Manager, AK-SM 800A series German Multiple 11 Apr, 2023 11.9 MB .pdf
Installation guide System Manager, AK-SM 800A series Portuguese Brazil 03 Nov, 2021 892.2 KB .pdf
Installation guide System Manager, AK-SM 800A series - Installation Guide French Multiple 20 Dec, 2021 1.2 MB .pdf
Installation guide System Manager, AK-SM 800A series - Installation Guide Russian Multiple 20 Dec, 2021 1.3 MB .pdf
Installation guide System Manager, AK-SM 800A series - Installation Guide English Multiple 18 Jun, 2020 885.1 KB .pdf
Data sheet System manager, type AK-SM 800A series English Multiple 28 Jun, 2024 729.6 KB .pdf
Data sheet System manager, type AK-SM 800A series Spanish, Castilian Multiple 07 Dec, 2022 891.8 KB .pdf
Data sheet System manager, type AK-SM 800A series Polish Multiple 07 Dec, 2022 933.5 KB .pdf
Data sheet System manager, type AK-SM 800A series Portuguese Brazil 07 Dec, 2022 894.1 KB .pdf
Data sheet System manager, type AK-SM 800A series German Multiple 07 Dec, 2022 898.9 KB .pdf
Data sheet System manager, type AK-SM 800A series Chinese (CN) Multiple 07 Dec, 2022 918.0 KB .pdf
Data sheet System manager, type AK-SM 800A series Italian Multiple 07 Dec, 2022 874.6 KB .pdf
Data sheet System manager, type AK-SM 800A series French Multiple 07 Dec, 2022 894.1 KB .pdf

Related products

Disclaimer

** DISCLAIMER: Professional Use Only **

This product is not subject to the UK PSTI regulation, as it is for supply to and use only by professionals with the necessary expertise and qualifications. Any misuse or improper handling may result in unintended consequences. By purchasing or using this product, you acknowledge and accept the professional-use-only nature of its application. Danfoss does not assume any liability for damages, injuries, or adverse consequences (“damage”) resulting from the incorrect or improper use of the product and you agree to indemnify Danfoss for any such damage resulting from your incorrect or improper use of the product.