3. Run the tool with the following options: "cert -c -s -p".
Example: "cert -c 169.254.11.5 -s -p"
A Certification Authority is created. A private server key and server certificate will then be
created. The certificate is signed.
The following files will be stored in the folder you have just created.
"c:\MySSL\CA\ITDiagRootCA.crt"
"c:\MySSL\CA\ITDiagRootCA.key"
"c:\MySSL\out\<IP-Address>\<IP-Addr>.SSL.crt"
"c:\MySSL\out\<IP-Address>\<IP-Addr>.SSL.key"
Note
Help when calling is available with option -h: "cert -h".
4. Copy the server certificate (e.g. MWSSLCert.pem) and the private server key (e.g. SSL.key)
to your converter's memory card under the directory "\OEM\SINAMICS\HMICFG
\CERTSTORE". Assign an appropriate name to the server certificate.
Note
If you want to generate the server certificates automatically from the web server, only copy
the root certificate and the private root key (e.g. ITDiagRootCA.key) to the memory card.
5. Make a backup copy of your certificate and rename the copy, e.g. as "SINAMICS.crt".
6. Import the renamed server certificate to the browser on your PC. Instructions for importing
the certificate can be found in your browser's help options.
7. Open an HTTPS web server connection to your drive in the browser.
– If the certificate has been imported correctly, the required connection is established.
– If the certificate is not imported, a message indicating that the signed Certification
Authority is unknown is displayed when you open the browser.
5.6.9.3
Generating your own certificates
You can either generate your own certificates for the secured data connection or purchase
them from a certification authority. The software required for generating your own certificates
is not included in the scope of delivery of the converter. In these cases, a server certificate
and a private server key are supplied.
Table 5-1
Example:
Name of the server certificate
<IP-Addr>.SSL.crt (z. B. 192.168.2.90.SSL.crt)
Name of the private server key
<IP-Addr>.SSL.key (z. B. 192.168.2.90.SSL.key)
Proceed as follows:
1. Copy the server certificate (e.g. 192.168.2.90.SSL.crt) and the private server key (e.g.
192.168.2.90.SSL.key) to your converter's memory card under the directory "\OEM
\SINAMICS\HMICFG\CERT\". Assign an appropriate name to the certificate.
2. Make a backup copy of your certificate and rename the copy, e.g. as "SINAMICS.crt".
Security measures for SINAMICS
5.6 Web server
Industrial Security
76
Configuration Manual, 08/2017, A5E36912609A