Certificates and keys
• As of firmware version V5.2.5, we converted from RSA certificates to certificates for elliptic
curves cryptography ("ECDSA certificates"). Only use ECDSA certificates in PEM format that
were generated with the following curves:
– secp256r1 (NIST P-256)
– secp384r1 (NIST P-384)
– secp521r1 (NIST P-521)
RSA certificates are no longer supported as of this firmware version. The existing RSA
certificates on the device are automatically replaced with self-signed ECDSA certificates.
• On the device there is a preset SSL certificate with the key length 256 bits for the elliptic-
curves cryptography. Replace this certificate with a self-made certificate with key. We
recommend that you use a certificate signed either by a reliable external or by an internal
certification authority.
• Use a certification authority including key revocation and management to sign certificates.
• Make sure that user-defined private keys are protected and inaccessible to unauthorized
persons.
• Verify certificates and fingerprints on the server and client to prevent "man in the middle"
attacks.
• Change certificates and keys immediately if there is a suspicion of compromise.
Recommendations on network security
SCALANCE X-200
Operating Instructions, 11/2021, C79000-G8976-C284-15
15