Deploying Vocera Devices with Unique Certificates

The BCU provides benefits beyond loading badge firmware and updates to the badge properties file.

Although not necessarily recommended, you can use the BCU to accept PFX (PCKS12) format client certificate files and convert them to a PEM format which is supported by Vocera device. This is achieved by using the MAC address referenced on the certificate file name, so that certificates are pushed to the provisioned device.

  1. From the Windows Start menu on the configuration computer, choose Programs > Vocera > Badge Utilities > Badge Configuration Utility. The Badge Configuration Utility opens in a command window.
  2. Once command prompt window appears, press any key to continue.
  3. For each certificate located in the certs\files folder, enter the PFX import password when prompted.
    Note: If the wrong import password is entered, the script will continue to run but the certificate will not be converted. If this occurs, restart the process by running the Badge Configuration Utility again.

    Result: After all the passwords are entered, the Badge Configuration Utility runs automatically were device are provisioned with the needed firmware and properties, and each badge with a unique EAP-TLS certificate.

    In addition, the PFX converted certificates can be removed from the certs/files folder since the converted certificates are loaded automatically when the BCU is restarted.
    Note: These converted badge certificates are located in their own mac address folder %vocera_drive%\vocera\config\certs\badges