
Configuration
4.16 Security
CP 1243-8 IRC
Operating Instructions, 02/2018, C79000-G8976-C385-03
107
●
SHA-1 interlock
Setting to select whether the CP may use the secure hash algorithm SHA-1 if "SHA-256"
was configured as the Secure hash algorithm and the master does not support SHA-256.
Range of values:
–
SHA-1 mode not allowed
The CP may not use SHA-1. If the master does not support SHA-256, no connection
will be established.
–
SHA-1 mode allowed
The CP can use SHA-1 if the master does not support SHA-256.
Default setting: SHA-1 mode not allowed
●
Secure hash algorithm (SHA)
Selection of the Secure Hash Algorithm (SHA)
Range of values:
–
SHA-1
–
SHA-256
Default setting: 256
●
Key wrap algorithm
Selection of the Advanced Encryption Standard (AES)
Range of values:
–
AES-128
–
AES-256
Default setting: AES-128
●
Key length
Specifies the length of the pre-shared key in bytes.
The following lengths are used depending on the key wrap algorithm.
–
For AES-128: 16 bytes
–
For AES-256: 32 bytes
●
Max. number of statistics queries
If the configured number of statistics queries of the master is exceeded within the key
exchange interval, the CP enters a message in the diagnostics buffer of the CPU.
Range of values: 2...255 Default setting: 5
●
Authentication requests before key exchange
Maximum number of authentication requests of the CP with the master. When this
number is reached, the session key is renewed.
Range of values: 1...10000 Default setting: 1000
Recommendation: Set the number for the CP twice as high as for the master.