Working with IEEE 802.1X certificates
There are 6 scenarios that require renewing operational certificates. Follow the procedure for renewing operational certificates for any of the cases listed below.
- Operational certificate is expired.
- Root certificate is expired or must be renewed by a IT request.
- Routine periodic renewal of the operational certificate.
- Changes in the PKI settings of a project.
- Device name, ID or IP address has changed.
- Operational certificate has been compromised.

IEEE 802.1X certificates are only supported as of device version V1.6 (check the device version in the Details pane > System folder > Device version).
IEEE 802.1X certificates must be applied in different ways depending on customer requirements. Each of the scenarios has its advantages/disadvantages in terms of trustworthiness or effort involved in certifying the certificates.
| Trustworthy | Certification effort | Effort to renew an operational certificate | Effort to replace a damaged device |
|---|---|---|---|---|
IEEE 802.1X certificates with ABT Site as root CA (internal certificates) | Less (1) | Low | Low | Low |
IEEE 802.1X certificates with external CA | Good | High | High (2) | High (2) |
IEEE 802.1X certificates with external CA and ABT Site as Intermediate CA | Medium | Low | Low | Low |
(1) Less does not mean that connections with this type of certification are unsafe. There are customers who have their own certification authority and therefore do not trust this ABT Site as a certification authority.
(2) The customer's IT department must be involved and available to sign certificates.
IEEE 802.1X certificates with ABT Site as root CA (internal certificates)
ABT Site creates an individual device certificate for each device, signed by the internal ABT Site project root certificate. The project root certificate must be exported to the customer’s IT department, and deemed trustworthy by the authentication server.

| Siemens tasks | Customer tasks |
|---|---|---|
1 |
| |
2 |
| |
3 | Defining the IEEE 802.1X project properties for the root certificate |
|
4 | Setting the certificate authority to Internal. |
|
5 |
| |
6 | Sending the root certificate to the customer. |
|
7 |
| Importing the ABT Site root certificate to its authentication server environment. |
8 |
| Informs Siemens to be ready with the authentication server. |
9 | Downloading the control program with a full download to each device. |
|
10 | Testing the IEEE 802.1X certificate management together with the customer’s IT department. | |
IEEE 802.1X certificates with external CA
ABT Site creates an individual device certificate signing request for each device. It must be signed by some external CA and deemed trustworthy by the authentication server. Signed certificates are imported back into ABT Site, and loaded to each device afterwards.

This solution has higher engineering effort, but may be deemed more trustworthy by a customer’s IT department.

| Siemens tasks | Customer tasks |
|---|---|---|
1 |
| |
2 |
| |
3 | Defining the IEEE 802.1X project properties for the root certificate |
|
4 | Setting the certificate authority to External. |
|
5 | Exporting an IEEE 802.1X operational certificate signing request for each device. |
|
6 |
| Signing each operational certificate by external signing certification authority. |
7 |
| Sending the signed operational certificate back to Siemens. |
8 | Importing an IEEE 802.1X operational certificate from an external CA for each device. |
|
9 | Downloading the control program with a full download to each device. |
|
10 | Testing the IEEE 802.1X certificate management together with the customer’s IT department. | |
IEEE 802.1X certificates with external CA and ABT Site as Intermediate CA
ABT Site exports a certificate signing request for its project root signing key. it must be signed by an external CA and deemed trustworthy by the authentication server. The signed certificate is imported back to ABT Site. ABT Site creates an individual device certificate for each device, signed with its project key. That project signing certificate is now no longer a trusted root, but part of a longer trust chain.

You can transition from ABT Site as CA to an intermediate solution with an external CA at a later date as needed. The ABT Site root certificate then trusts the external signed certificate to complete the trust chain. Devices need not be reloaded in this case.

| Siemens tasks | Customer tasks |
|---|---|---|
1 |
| |
2 |
| |
3 | Defining the IEEE 802.1X project properties for the root certificate |
|
4 | Setting the certificate authority to Internal. |
|
5 | Exporting the certificate signing request for the intermitted root certificate. |
|
6 |
| Signing the intermitted root certificate by external signing certification authority. |
7 |
| Sending the signed intermitted root certificate back to Siemens. |
8 | Importing the intermitted certificate signing request for the root certificate. |
|
9 | Downloading the control program with a full download to each device. |
|
10 | Testing the IEEE 802.1X certificate management together with the customer’s IT department. | |
Further information
- Defining the IEEE 802.1X project properties for the root certificate
- Exporting the IEEE 802.1X root certificate
- Renewing the IEEE 802.1X internal operational certificate
- Exporting an IEEE 802.1X operational certificate signing request
- Importing an IEEE 802.1X operational certificate from an external CA
- Creating an IEEE 802.1X certificate report
- IEEE 802.1X certificate with FQDN and external CA