Working with web certificates
There are 6 scenarios that require renewing operational certificates:
- Operational certificate is expired.
- Root certificate is expired or must be renewed by an IT request.
- Routine periodic renewal of the operational certificate.
- Changes in the project PKI settings.
- Device name, ID or IP address has changed.
- Operational certificate has been compromised.
Working with web root certificates
Base workflow for intermediate web certificates with external CA
ABT Site exports a certificate signing request for its project root signing key. it must be signed by an external CA and deemed trustworthy by the authentication server. The signed certificate is imported back to ABT Site. ABT Site creates an individual device certificate for each device, signed with its project key. It is no longer a trusted root, but part of a longer trust chain.

You can transition from ABT Site as CA to an intermediate solution with an external CA at a later date as needed. The ABT Site root certificate then trusts the external signed certificate to complete the trust chain. Devices need not be reloaded in this case.

| Siemens tasks | Customer tasks |
|---|---|---|
1 |
| |
2 |
| |
3 | Defining the web project properties for the root certificate. |
|
4 | Setting the certificate authority to Internal. |
|
5 | Exporting the certificate signing request for the intermitted root certificate. |
|
6 |
| Signing the intermitted root certificate by external signing certification authority. |
7 |
| Sending the signed intermitted root certificate back to Siemens. |
8 | Importing the intermitted certificate signing request for the root certificate. |
|
9 | Downloading the control program with a full download to each device. |
|
10 | Testing the web certificate management together with the customer’s IT department. | |
Further information
- Defining the web project properties for the root certificate
- Exporting the web root certificate
- Renewing web internal operational certificate
- Exporting a web operational certificate signing request
- Importing a web operational certificate from an external CA
- Importing an external web certificate
- Creating a web certificate report
- Web certificate with FQDN and external CA