Protection Of Confidential Configuration Data; Local User Management; Useful Information On The Local User Administration And Access Control - Siemens SIMATIC S7-1500 System Manual

Drive controller
Hide thumbs Also See for SIMATIC S7-1500:
Table of Contents

Advertisement

11.2

Protection of confidential configuration data

As of STEP 7 V17, you have the option of assigning a password for protecting confidential
configuration data of the respective CPU. This refers to data such as private keys that are
required for the proper functioning of certificate-based protocols.
You can find detailed information on protecting confidential configuration data in the
Communication function manual
(https://support.industry.siemens.com/cs/ww/en/view/59192925).
11.3

Local user management

11.3.1

Useful information on the local user administration and access control

As of TIA Portal version V19 and CPU firmware version V3.1, SIMATIC Drive Controller feature
improved management of users, roles and CPU function rights (User Management & Access
Control, UMAC).
From the versions mentioned above onwards, you manage all project users along with their
rights (for example, access rights) for all CPUs in the project in the editor for users and roles
of the project in the TIA Portal:
• Navigate to the "Security Settings > Users and roles" area in the project tree to manage
users with their rights, for example, to control access rights.
The TIA Portal saves the assignment of the function rights of a CPU to user-defined roles and
the assignment of these roles to users for each CPU. There are no system-defined roles with
predefined function rights for CPUs.
After loading the configuration, the user management becomes effective in the respective
CPUs. After loading, every CPU "knows" who may access which service and execute certain
functions.
This new feature is also called "local user management and access control" below.
Note
No global user support for CPU function rights
Another option for user management in the TIA Portal is the central user management UMC
(User Management Component). With this component you manage global users on
connected servers, e.g. also via the connection of an MS Active Directory. The authentication
is then implemented via UMC. A global user management for CPU-specific function rights via
UMC is currently not supported.
SIMATIC Drive Controller
System Manual, 11/2023, A5E46600094-AD
11.2 Protection of confidential configuration data
Protection
237

Advertisement

Table of Contents
loading

Table of Contents