KNX Secure:

Hi everyone,

I have switched the KNX communication for my MDT 6-inch panel in Home Assistant to KNX Secure, using the tunnel of a Gira S1. The panel itself is rather “dumb”, but with Home Assistant automations it becomes quite useful.

The migration to KNX Secure via the S1 tunnel was basically straightforward: In ETS, all approximately 1,750 group addresses used by the panel are configured as secure, and in Home Assistant I imported the current project including the key file.

The problem is that for a few group addresses, Home Assistant regularly reports that the telegrams cannot be decrypted (see screenshot). This still happens even after I:

  • reloaded the application program of the MDT panel in ETS, and
  • exported the KNX Secure key file again and updated it in Home Assistant.

Does anyone have an idea what could be causing this, or where I should look next?

Any hints or experience would be greatly appreciated.

This forum is English only.
Please edit your post and translate it.

Hi :waving_hand:!
Is only HA and the one knx device using those addresses?
Did you assign the addresses to the used tunnel interface? (See knx integration docs)?
Try to only export the keyring for the used interface instead of the whole project keyring file.

When the issue occurs, have a look at HAs group monitor and filter for the GA. You'll see if it was received secure with an unknown key, or sent plain while expected secure.