Web certificate with FQDN and external CA

If a fully qualified domain name (FQDN) is used, for example, AS01.siemens.com , the settings are different than DHCP settings.

Example of a FQDN domain name:

The following is important when handling certificates:

 

1. Set the domain name for FQDN

  1. Go to Settings.
  2. Open the Address defaults task.
  3. Select the IP tab.
  4. In the Domain name field, enter the domain name, for example, Siemens.com.

 

2. Set the properties for each device

  1. Go to Building.
  2. Open the Certificates management task.
  3. Select a device.
  4. Select the Web Interface tab.
  5. Do the following for the device version ≤ 1.5:
    • Select the IPv4 tab.
    • In the Host name field, verify the host name, for example, AS01. This name must be unique within the project.
    • Select the Use DHCP check box.
  6. Do the following for the device version ≥ 1.6:
    • Select the Ports / network > LAN > IPv4 tab.
    • In the Host name field, verify the host name, for example, AS01. This name must be unique within the project.
    • In the Web access drop-down list, select the desired connection type.
    • Activate the Use DHCP check box.
  7. Repeat these steps for each device.

 

3. Export certificates for signing by the external certification authority.

  1. The column Serial number is not empty.
  2. The certificate type is Internal, if the project settings are set to Internal.
  1. Go to Building.
  2. Open the Certificates management task.
  3. Select all or specific devices.
  4. Select the Web Interface tab.
  5. Right-click and select Change certificate authority to External.
  6. Click Export CSR.
    Note: If the certificate is exported a second time, a message appears. Cancel the process if you are not aware of the consequences (see explanation above).
  7. Click Open folder.
  8. A multiple export creates a zip file named as [Project-name_Date_Time].zip. Use the 7-zip File Manager to check the content.
    Note: The Windows explorer does not recognize the zip format and creates an error message.
  9. A single export creates two files named as [Project-name_Cert_Host-name_Serial-number_Date_Time].csr and [Project-name_Cert_Host-name_Serial-number _date_time].txt.
    Note: Those two files contain the same information, in slightly different formats. Depending on your certification authority, you may want to use one or the other, but typically you will not need both.
  10. The external CSR private key is stored in ABT Site project data and the serial number of the device is stored in the CSR to link the certificate to the serial number of the device.
  11. Send the file to the signing authority.
info

The time period between the certificate export and the signed certificate import should be very short, to avoid inconsistencies of data and keep the device accessible.

 

4. Import the signed certificates

  1. The file from the signing authority is available in one of the supported formats (*.p12, *.pfx, *.cer, *.crt).
  1. Go to Building.
  2. Open the Certificates management task.
  3. Select a device.
  4. Select the Web Interface tab.
  5. Click Import external.
  6. Select the certificate file type Certificate container (*.p12, *.pfx) or Certificate (*.cer, *.crt).
  7. Select the corresponding signed certificate for this device.
  8. Click Open.
  9. The signed certificate is imported into ABT Site.
  10. Repeat these steps for all required devices.

 

5. Load the certificates to the device

  1. An online connection to the device is established.
  2. A full download with an operational certificate is already performed.
  1. Go to Startup.
  2. Open the Configure and download task.
  3. Select the Engineered devices tab.
  4. Select the device.
  5. Right-click and select Only updated certificates or perform a full download.
    Downloading an updated certificate to a device
  6. The signed certificate is stored in the device.
  7. Repeat these steps for all required devices.