Certificates for secure communication can be configured during the installation of ibaCMC. A special dialog box allows you to select a certificate.
For installation information, see Installation and program start.
Selecting the certificate
The selected certificate is then applied to both the web server and device communication when encrypted or TLS communication is enabled. In both cases, the same certificate is used.
The following certificate options are available:
-
Self-signed certificate (default)A self-signed certificate is created and used. You can set the validity period. The default value is 5 years, but you can also select 2 years or enter a duration in days using the Custom setting.
-
Certificate file (PFX file)Select this option if you want to use your own certificate. If you want to use your own certificate, you must provide the PFX file and enter the path to the certificate and the password here. iba AG recommends storing the certificate in the folder
…\ProgramData\iba\ibaCMC\Server\ca. -
Windows Certificate Store:In this setting, you can reference an existing certificate in the Windows Certificate Store to use it for the web server. You can still choose which certificate store to use (personal/public) and where the storage path is located.
Device communication (MQTT)
You can configure the port and communication mode for communication between ibaPDA devices and ibaCMC. Encrypted communication is provided by default. If the systems involved are on an isolated network without an Internet connection, you can also use unencrypted communication.
Note |
|
|---|---|
|
In unencrypted communication, the transmitted data is not protected and could be read by attackers. The plant operator should be explicitly informed of this risk! |
|
Notification about expired certificates
Usually, certificates have a limited validity period. If the validity of a certificate expires and a communication is no longer possible, related error messages will be posted in the system diagnostics (overview and System tab).