14
© Softing Industrial Automation GmbH
dataFEED Gateway - User Manual
4.2.4 Manage Client Certificates
The
Manage Client Certificates
view supports the the management of existing certificates, the upload of new
certificates and the display of certificate properties in a table.
For a certificate of an OPC UA Client to become trusted (from view of the OPC UA Server in the dataFEED
Gateway) the following conditions need to be fulfilled:
1.
The certificate is digitally signed and the whole chain of certificates used for signing is available to the
dataFEED Gateway. It is either stored in the
CA
(Certificate Authority) folder or in the
Trusted certificates
folder (see below).
2.
The certificate is stored in the dataFEED Gateway. Self-signed certificates need to be stored in the
Trusted
certificates
folder to become trusted. This classification stays valid unless a certificate is declared not
trusted.
3.
In addition, it is checked for user authentication that the certificate is not stored in the
Rejected certificates
folder in the dataFEED Gateway.
Upload new certificate
To ease certificate management, the OPC UA Server in the dataFEED Gateway stores each new client certificate
in the
New certificates
folder using the binary
DER
format. Additional
DER
format certificates can be uploaded in
the dataFEED Gateway using the
Browse...
button.
Declare a certificate trusted
To declare a certificate trusted, move it into the
Trusted certificates
folder. To do so, select the certificate and
click the
Move to trusted folder
(
) button.
Note
Check the certificate's fingerprint to make sure you declare the correct certificate trusted.
Declare a certificate not trusted
To exclude a certificate from being trusted, remove it from the
Trusted certificates
folder. To do so, select the
certificate and delete it by clicking the
Delete certificate
( ) button or move it to the
Rejected
folder by clicking
the
Move to rejected folder
(
) button.
Note
If the certificate is deleted, it may reappear in the
New certificates
folder, if the certificate owner
tries to re-connect.
Manage certificate authorities certificates
The certificates of certificate authorities (CA) are certificates that are required to verify that (not self-signed)
certificates in the
Trusted Certificates
folder are valid. These certificates are uploaded in the dataFEED
Gateway as follows:
1.
Upload the
DER
format certificate into the
New certificates
folder (see above).
2.
Select the uploaded certificate and click the
Move to certificate authority (CA)
(
) button to move it to the
CA
folder.