
Be sure to import into the “Own Certificates” folder.
1.
Change to the
“Security Screen”
.
2.
Select tab
“Devices”
, the folder
“Own Certificates”
and press the import button.
3.
Select the certificate (
[1_IoDrvFTPServer.cer]
) to be imported in the opening file manager.
4.
Press the
“Open”
button.
ð
The new certificate will be shown as
“IoDrvFTPServer”
in the information column. The
previous self-signed certificate will lose its name and is therefore not valid anymore.
DON’T delete any of the installed certificates.
5.
Check the validation and
“Issued by”
of the new certificate by activating the top PLC
branch.
6.
Download and reboot the PLC (repower or use
“PLC Shell”
and command
[reboot]
.)
We recommend changing the communication policy accordingly so that only
encrypted connections are allowed.
An application can be encrypted and signed in order to protect a running application in an
AC500 V3 PLC and to protect a configured project. How to set-up the user management, the
communication and the boot application in order to prevent unauthorized access is explained in
the application note
AC500 V3 - Encrypt and sign your application
.
As of Automation Builder 2.6.0 there is also the possibility to activate the
“Enforced signing”
mode in the
“Change Runtime Security Policy”
. Then the controller accepts ONLY signed
downloads.
“Tab Communication Settings
è
Device
è
Change Runtime Security Policy...
è
Code Signing
è
New policy
è
Enforced signing”
Encrypted and
signed applica-
tions
Enforced
signing
Configuration and programming
Cyber security > Certificates factory default - no encryption
2023/03/03
3ADR011074, 1, en_US
82