Siemens SINUMERIK 840D Installation Manual page 70

Manage myresources, optimize myprogramming/nx-cam editor, software sinumerik integrate, version 5.0.3.0
Hide thumbs Also See for SINUMERIK 840D:
Table of Contents

Advertisement

Installing/configuring Windows services
3.6 Setting up encrypted communication
Prepare yourself against DoS (Denial of Service) attacks, for example, by setting up
appropriate firewall rules, implementing an IPS (Intrusion Prevention System) and/or a WAF
(Web Application Firewall).
Protect your system against code injection by applying state-of-the-art technologies and the
appropriate knowledge.
Store certificates securely so they cannot be exported by unauthorized entities. In such cases,
you must follow the hardening guidelines when setting up.
These are just a few examples of how you can make your system more secure. It is your task
and you are responsible for configuring the hardened system.
TLS implementation
The system is prepared for use of the TLS 1.2 protocol. All modules and services must
communicate via encrypted channels that meet the current security requirements.
Consequently, the system is prepared to use the TLS 1.2 protocol. The server requires a digital
certificate that confirms the identity of the server. You can purchase these items from CAs
(Certificate Authorities). The certificate must be digitally signed. The clients must trust these
certificates. If you use your own generated self-signed certificate, then the root certificates must
be deployed on the controls on both Linux and Windows machines - and they must also be
deployed on SSL proxies if they are being used. You are completely responsibility for correctly
implementing and checking your system.
If you are using an obsolete client (such as a Windows NT machine) that does not support the
required TLS protocols, then you should use a hardware proxy to resolve this problem. Such
hardware can provide an additional encryption layer for the communication channel.
You must also ensure that the hardware proxy is appropriate and correctly encrypted. The
hardware proxy is not part of the product.
Finally, you must also have the knowledge and the experience to configure the IIS server. You
must always be prepared to address the actual hardening requirements. You are responsible
for making the correct system security settings in the client environment.
70
Manage MyResources, Optimize MyProgramming /NX-Cam Editor
Installation Manual, 12/2019, A5E44672080B AE

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sinumerik 840d slSinumerik 840de slSinumerik 828d

Table of Contents