Communications services
3.6 Secure Communication
Communication
54
Function Manual, 05/2021, A5E03735815-AJ
4.
In the drop-down list for selecting a certificate click the "Add" button.
The "Create Certificate" dialog opens.
5.
Leave the default settings in this dialog. They are tailored to the usage of Secure Open User
Communication (usage: TLS).
Tip: Supplement the default name of the certificate subject, in this case the CPU name. In
order to differentiate you better leave the default CPU name in case you have to manage a
large number of device certificates.
Example: PLC_1/TLS becomes PLC_1-SecOUC-Chassis17FactoryState.
6.
Compile the configuration.
The device certificate and the CA certificate are part of the configuration.
7.
Repeat the steps described above for PLC_2.
In the next step you have to create the user programs for the data exchange and load the
configurations together with the program.
Using self-signed certificates instead of CA certificates
When creating device certificates you can select the "Self-signed" option. You can create self-
signed certificates without being logged in for the global security settings. This procedure is
not recommended because the resulting certificates do not exist in the global certificate
memory and can therefore not be assigned directly to a partner CPU.
As described above, you should select the name of the certificate subject with care so that
the right certificate can be assigned to a device without any doubt.
Verification with the CA certificates of the STEP 7 project is not possible for self-signed
certificates. To ensure that self-signed certificates can be verified you have to include the self-
signed certificates of the communication partner into the list of trusted partner devices for
each CPU. To this purpose you must have activated the "Use global security settings for
certificate manager" option and be logged in as a user in the global security settings.
Proceed as follows to add the self-signed certificate of the communication partner of the CPU:
1.
Mark PLC_1 and navigate to the "Certificates of partner devices" table in the "Protection &
Security" section.
2.
Click in an empty line in the "Certificate subject" column in the "Device certificates" table to
add a new certificate.
3.
Select the self-signed certificate of the communication partner from the drop-down list and
confirm the selection.
In the next step you have to create the user programs for the data exchange and load the
configurations together with the program.
Summary of Contents for SIMATIC ET 200AL
Page 2: ......
Page 143: ......
Page 218: ......
Page 250: ......
Page 296: ......
Page 337: ......
Page 365: ......
Page 392: ......
Page 419: ......
Page 451: ......
Page 483: ......
Page 597: ......
Page 648: ......
Page 702: ......
Page 739: ......
Page 781: ......
Page 804: ......
Page 828: ......
Page 853: ......
Page 880: ......
Page 906: ......
Page 996: ...Diagnostics ...
Page 1121: ......
Page 1565: ......