Working with IEEE 802.1X certificates

There are 6 scenarios that require renewing operational certificates. Follow the procedure for renewing operational certificates for any of the cases listed below.

info

IEEE 802.1X certificates are only supported as of device version V1.6 (check the device version in the Details pane > System folder > Device version).

 

IEEE 802.1X certificates must be applied in different ways depending on customer requirements. Each of the scenarios has its advantages/disadvantages in terms of trustworthiness or effort involved in certifying the certificates.

 

Trustworthy

Certification effort

Effort to renew an operational certificate

Effort to replace a damaged device

IEEE 802.1X certificates with ABT Site as root CA (internal certificates)

Less (1)

Low

Low

Low

IEEE 802.1X certificates with external CA

Good

High

High (2)

High (2)

IEEE 802.1X certificates with external CA and ABT Site as Intermediate CA

Medium

Low

Low

Low

(1) Less does not mean that connections with this type of certification are unsafe. There are customers who have their own certification authority and therefore do not trust this ABT Site as a certification authority.

(2) The customer's IT department must be involved and available to sign certificates.

 

IEEE 802.1X certificates with ABT Site as root CA (internal certificates)

ABT Site creates an individual device certificate for each device, signed by the internal ABT Site project root certificate. The project root certificate must be exported to the customer’s IT department, and deemed trustworthy by the authentication server.

 

 

Siemens tasks

Customer tasks

1

Downloading a control program to a device

 

2

Adding the serial number

 

3

Defining the IEEE 802.1X project properties for the root certificate

 

4

Setting the certificate authority to Internal.

 

5

Exporting the IEEE 802.1X root certificate

 

6

Sending the root certificate to the customer.

 

7

 

Importing the ABT Site root certificate to its authentication server environment.

8

 

Informs Siemens to be ready with the authentication server.

9

Downloading the control program with a full download to each device.

 

10

Testing the IEEE 802.1X certificate management together with the customer’s IT department.

 

IEEE 802.1X certificates with external CA

ABT Site creates an individual device certificate signing request for each device. It must be signed by some external CA and deemed trustworthy by the authentication server. Signed certificates are imported back into ABT Site, and loaded to each device afterwards.

info

This solution has higher engineering effort, but may be deemed more trustworthy by a customer’s IT department.

 

 

 

Siemens tasks

Customer tasks

1

Downloading a control program to a device

 

2

Adding the serial number

 

3

Defining the IEEE 802.1X project properties for the root certificate

 

4

Setting the certificate authority to External.

 

5

Exporting an IEEE 802.1X operational certificate signing request for each device.

 

6

 

Signing each operational certificate by external signing certification authority.

7

 

Sending the signed operational certificate back to Siemens.

8

Importing an IEEE 802.1X operational certificate from an external CA for each device.

 

9

Downloading the control program with a full download to each device.

 

10

Testing the IEEE 802.1X certificate management together with the customer’s IT department.

 

IEEE 802.1X certificates with external CA and ABT Site as Intermediate CA

ABT Site exports a certificate signing request for its project root signing key. it must be signed by an external CA and deemed trustworthy by the authentication server. The signed certificate is imported back to ABT Site. ABT Site creates an individual device certificate for each device, signed with its project key. That project signing certificate is now no longer a trusted root, but part of a longer trust chain.

info

You can transition from ABT Site as CA to an intermediate solution with an external CA at a later date as needed. The ABT Site root certificate then trusts the external signed certificate to complete the trust chain. Devices need not be reloaded in this case.

 

 

Siemens tasks

Customer tasks

1

Downloading a control program to a device

 

2

Adding the serial number

 

3

Defining the IEEE 802.1X project properties for the root certificate

 

4

Setting the certificate authority to Internal.

 

5

Exporting the certificate signing request for the intermitted root certificate.

 

6

 

Signing the intermitted root certificate by external signing certification authority.

7

 

Sending the signed intermitted root certificate back to Siemens.

8

Importing the intermitted certificate signing request for the root certificate.

 

9

Downloading the control program with a full download to each device.

 

10

Testing the IEEE 802.1X certificate management together with the customer’s IT department.