Communications services
3.6 Secure Communication
Communication
Function Manual, 05/2021, A5E03735815-AJ
97
Requirement for the initial establishment of connection to load the CPU
•
No password for confidential PLC configuration data available in the CPU.
If the CPU has already been loaded and therefore already has a password for confidential
PLC configuration data, this password must then match the project that is to be loaded.
•
Project with CPU configuration (including password for confidential PLC configuration
data) and user program is available.
•
The CPU is in STOP mode.
•
Programming device and CPU are directly connected to each other and are located in a
protected environment; i.e. you can identify the CPU to be loaded and control the
connection between CPU and programming device.
Initial establishment of connetion to the CPU - provisioning phase
The first connection establishment for loading the CPU is secured by the TLS procedure in
terms of Secure PG/HMI Communication.
However, the CPU uses its manufacturer device certificate (if available) or a self-signed
certificate to establish this connection. The CPU can only be used to a limited extent in this
phase. In this phase, the CPU waits for the provision of the password-based key information -
or more simply stated, it is expecting the password for confidential PLC configuration data. In
the following, this phase is also called the provisioning phase. A message in the diagnostic
buffer indicates that the CPU is in the provisioning phase.
Summary of Contents for SIMATIC ET 200AL
Page 2: ......
Page 143: ......
Page 218: ......
Page 250: ......
Page 296: ......
Page 337: ......
Page 365: ......
Page 392: ......
Page 419: ......
Page 451: ......
Page 483: ......
Page 597: ......
Page 648: ......
Page 702: ......
Page 739: ......
Page 781: ......
Page 804: ......
Page 828: ......
Page 853: ......
Page 880: ......
Page 906: ......
Page 996: ...Diagnostics ...
Page 1121: ......
Page 1565: ......