Certificate Manager; Handling Certificates - Siemens CP 1243-7 LTE Operating Instructions Manual

Simatic net
Table of Contents

Advertisement

Configuration
4.11 Security
4.11.7

Certificate manager

Assignment of certificates
If you use communication with authentication for the module, for example SSL/TLS for
secure transfer of e-mails, certificates are required. You need to import certificates of non-
Siemens communications partners into the STEP 7 project and download them to the
module with the configuration data:
1. Import the certificates of the communications partners using the certificate manager in the
global security settings.
2. Then assign the imported certificates to the module in the table below the local security
settings of the module.
For a description of the procedure, refer to the section Handling certificates (Page 74).
You will find further information in the STEP 7 information system.
4.11.8

Handling certificates

Certificate for authentication
If you have configured secure communication with authentication for the CP, own certificates
and certificates of the communications partner will be required for communication to take
place.
All nodes of a STEP 7 project with enabled security functions are supplied with certificates.
The STEP 7 project is the certification authority.
Note
No certificate with security functions disabled.
If the security functions of the CP are disabled in the STEP 7 project, no certificate will be
generated for the CP.
For the secure transfer of e-mails via SSL/TLS and SSL certificate is created for the CP. It is
visible in STEP 7 in "Global security settings > Certificate manager > Device certificates".
The table "Device certificates" shows the issuer, validity, use of a certificate
(service/application) and the use of a key. You can call up further information about a
certificate by selecting the certificate in the table and selecting the shortcut menu "Show".
The table also shows all other certificates generated by STEP 7 and all imported certificates.
So that the CP can communicate with non-Siemens partners when the security functions are
enabled, the relevant certificates of the partners must be exchanged during communication.
To supply the CP with third-party certificates, follow the steps below:
1. Importing third-party certificates from communications partners
⇒ Global security settings of the project (certificate manager)
2. Assigning certificates locally
⇒ Local security settings of the CP ("Certificate manager" table)
These two steps are described in the next two sections.
74
Operating Instructions, 04/2017, C79000-G8976-C381-03
CP 1243-7 LTE

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

S7-1200 telecontrolCp 1243-7 lte-euCp 1243-7 lte-us

Table of Contents