Additional Settings For The Secure Pg/Hmi Communication - Siemens SIMATIC ET 200AL System Manual

Distributed i/o system
Hide thumbs Also See for SIMATIC ET 200AL:
Table of Contents

Advertisement

Communications services
3.6 Secure Communication
3.6.4.2

Additional settings for the secure PG/HMI communication

In addition to the assignment of a password to protect confidential PLC configuration data,
you have further setting options for the behavior of the CPU during operation.
PG/PC and HMI communication mode
You can set how the CPU can communicate with programming devices and HMI devices:
• Only via secure PG/HMI communication
• Both via Secure PG/HMI communication and via the previously used PG/HMI
communication, "Legacy PG/HMI communication" for short.
Procedure
1. In the CPU properties, navigate to the area "Protection & Security > Connection
mechanisms".
2. Select the option you want to use.
Select certificate or generate a new certificate
If you select the connection mechanism for PG/HMI communication, you can select a PLC
communication certificate for the protection of the connection in the same context or have it
generated by the TIA Portal. If you have assigned a password or if you have deactivated the
option to protect confidential PLC configuration data (i.e. no password has been set), then a
certificate with suitable settings and a valid default name is already preset in the "Protection
& Security> Connection mechanisms" area.
Procedure
If you want to have a new certificate generated by the TIA Portal or if you want to select
another existing certificate:
1. In the "PLC communication certificate" field, click the three points to expand the field.
2. Select the certificate you want or click the "Add" button.
3. When adding a certificate, a dialog appears with setting options for the certificate.
The purpose is set to "TLS server", you can change other parameters (such as name, hash
algorithm).
The general rules for certificate management apply. For example, if you want to generate a
CA certificate, the option "Global settings for the certificate manager" must be selected. You
also have the option of generating a self-signed PLC certificate.
See also
Managing certificates with STEP 7 (Page 49)
94
Function Manual, 05/2021, A5E03735815-AJ
Communication

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents