The cart is empty

ITVDesk Pro IP Camera 10.8: Security Enhancements and exacqVision Integration

ITVDesk 10.8 adds exacqVision VMS support and security enhancements for hardened deployments, including secure-only connections, Windows-protected storage, shared certificate management, and expanded access controls and security auditing.

Release highlights

  • exacqVision integration supports ONVIF HTTP and HTTPS connections with RTSP-over-HTTPS tunneling.
  • Optional HTTPS-only and RTSPS-only operation gives administrators more control over allowed connections.
  • Windows-protected storage and certificate management strengthen protection of configuration, secrets, and imported TLS private keys.
  • Expanded security controls include password policies, independent account lockouts, snapshot access control, and Windows Event Log forwarding.

Improvements

  • Improved ONVIF compatibility, HTTP/HTTPS tunneling, certificate handling, and connection diagnostics.
  • Strengthened Local UI password protection, network account validation, and security audit persistence.
  • Improved authentication, account lockout, Web Management, and Windows license-history reliability.

ITVDesk 10.8 update overview

Version 10.8.0 (Build 7.7.11.2) - Released on September 24, 2026

This release adds security controls to support applicable DISA Application Security and Development STIG requirements and secure deployment configurations. Deployment-specific assessment and configuration are still required.

New Features

  • exacqVision Video Management System support. See the exacqVision integration guide for HTTP and HTTPS setup.
  • Optional HTTPS-only and RTSPS-only operation. Administrators can disable plain HTTP per camera and plain RTSP for the streaming service. SRTP remains a separate option for encrypted audio/video.
  • Windows-protected storage for configuration, UI accounts, security settings, audit records and imported TLS private keys. Windows DPAPI adds protection tied to the Windows installation while supporting the existing application and SYSTEM Broker workflow.
  • Shared certificate management for RTSPS and camera HTTPS services. Administrators can validate and save a certificate pair, apply it to all cameras, or select individual camera certificates under Advanced. Apply to All Cameras reloads the saved pair by restarting the relevant active services; clients may briefly disconnect.
  • Administrator-controlled certificate recovery policy. When the entire protected certificate store is missing, the optional fallback can use the bundled default certificate with a visible warning. Damaged or unreadable stores do not trigger fallback.
  • Optional forwarding of Security Audit events to the Windows Application Event Log. Events use the ITVDesk Security source and can be collected through Windows Event Forwarding or existing monitoring tools. Collection and retention are configured by the administrator.
  • Change Password in UI Protect, including protection against reuse of the current and previous five passwords. Changes require the current password and TOTP code when enabled. Password history is retained if the same username is removed and added again.
  • Optional 15-character minimum-password policy for new or changed UI and supported network account passwords. Existing passwords remain valid until changed.
  • Independent Local UI and Network Account Lockout controls. Both are disabled by default, with initial values of three failed attempts within 15 minutes and a 10-minute lock duration.
  • Per-stream snapshot access control. Administrators can disable snapshot generation and retrieval, including access to previously cached images.
  • Automatic Web Management sign-out after 10 minutes of inactivity. The panel is Administrator-only. Background image and status refreshes do not extend the session; sign-out is audited and does not stop separate ONVIF or VMS/NVR streams.

Improvements

  • Enabled RTSP-over-HTTP and RTSP-over-HTTPS tunneling by default.
  • Added a compact, high-DPI HTTPS padlock indicator to the camera service status panel. Tunneling uses each camera's enabled ONVIF HTTP/HTTPS services. Saved transport choices remain unchanged.
  • Allowed optional HTTPS tunneling in RTSPS-only mode for compatible VMS/NVR clients. Plain RTSP and HTTP tunneling remain disabled in this mode; HTTPS tunneling still requires the camera's HTTPS service and a valid TLS certificate.
  • Strengthened Local UI password protection with salted PBKDF2-HMAC-SHA256 hashing. New or changed UI passwords require at least eight characters, including uppercase and lowercase letters, a number and a special character. Existing accounts remain usable.
  • Improved network account setup by removing the predefined Add Camera password and validating new or changed camera passwords. The basic camera password policy requires at least eight characters with letters and numbers when the optional 15-character policy is disabled.
  • Added clearer ONVIF Administrator, Operator and User permissions and an Operator option in Login Management. Operator supports media configuration and PTZ; User supports viewing, events and playback/search. System, network and account administration require Administrator.
  • Protected direct HTTP/HTTPS snapshot access with Digest authentication when camera ONVIF authentication is enabled. Snapshot requests use the existing audit and optional network lockout policy, and responses instruct browsers and proxies not to cache images.
  • Expanded Security Audit with application and Broker startup/shutdown, UI authentication, supported UI configuration changes and Web profile/account saves. Administrative records identify the verified user, target, action and result without recording passwords or private keys.
  • Improved audit persistence with periodic and orderly-exit saving and coordinated application/Broker updates. With Windows Event Log forwarding enabled, local audit-save failures also generate a rate-limited error event.
  • Strengthened RTSP session-ID and SRTP key generation with a cryptographically secure random source. Active RTSP session IDs are checked for duplicates. Existing ID formats and SRTP key lengths remain unchanged.
  • Simplified HTTPS, RTSPS, SRTP and Certificate Management settings with clearer labels, status messages and aligned controls.
  • Added quick access to temporary Account Lockouts from the camera menu and automatic list refresh when opening the Account Lockout tab. Manually blocked IP addresses remain separate under Blocked Clients.
  • Updated the bundled default TLS certificate to RSA-2048 / SHA-256 and improved certificate validation messages.
  • Reduced internal Release log noise and improved encrypted configuration saving with atomic file replacement.

Fixes

  • Fixed missing LIVE/client status for RTSP-over-HTTP/HTTPS sessions by retaining the tunnel client's IP address in the RTSP session.
  • Fixed ONVIF Media1/Media2 HTTPS tunneling advertising the plain HTTP port for saved RTSP stream paths.
  • Corrected HTTPS handshake result handling and improved failed-connection diagnostics without changing TLS settings.
  • Fixed ONVIF discovery rejecting standard RFC3986/RFC2396 MatchBy rules sent by some clients. Standard scope matching now respects URI path segments; existing discovery requests without MatchBy retain their behavior.
  • Fixed pending Security Audit records being lost after reopening the application and incorrect success reporting when clearing the audit fails.
  • Fixed normal Digest authentication challenges being counted as failed logins and already-blocked requests extending account lockout.
  • Corrected Burst Protection escalation and cleanup of expired counters.
  • Fixed RTSPS-only setup rejecting certificate pairs already saved in Windows-protected storage.
  • Fixed Web Management signing out prematurely after a temporary connection or status-check error.
  • Improved ONVIF XML depth validation to prevent parser stack overflow without changing the accepted nesting limit.
  • Fixed Windows license-history saving failures and Qt 6 compatibility for UI password-length validation.

Upgrade Notes

  • Back up before upgrading. Windows configuration gains DPAPI protection on its next successful save. macOS and Linux storage behavior is unchanged. Older builds cannot read protected files, and moving to another Windows installation requires planned recovery. Updates and in-place reinstalls retain access when configuration and the Windows installation are preserved. Windows file permissions remain necessary.
  • Use a deployment-specific certificate for production and configure client trust. Keep a secure backup of the original certificate and private key. Clients using the previous bundled certificate may require a trust update. Strict installations can disable default-certificate fallback.
  • VMS/NVR accounts that change media settings or use PTZ require Operator or Administrator; system and account changes require Administrator. Web Management supports browser Digest login over HTTP and HTTPS. HTTPS is recommended; Sign in may reuse credentials already cached by the browser.
  • UI password history applies to local UI accounts, not network accounts. Secure-only modes and Windows Event Log forwarding remain optional and disabled by default.