Public Key Infrastructure
230/258
16.5 Working with server certificates for inbound connections
For inbound connections, certificates can be stored within the PKI of the
Edge Gateway as described in
Use case 2: Server certificates for Edge
page 224] . There is a 1:1-Relation between client and
server (this means, exactly one certificate and one private key are required
per client).
The following actions can be performed:
1. Uploading the server certificate from a file into the Edge Gateway
2. Downloading the server certificate from the Edge Gateway into a file
3. Removing a server certificate from the Edge Gateway
4. Newly creating a server certificate on the Edge Gateway
5. Uploading a key file for a server certificate into the Edge Gateway
6. Removing a key file for a server certificate on the Edge Gateway
7. Newly creating a key file for a server certificate on the Edge Gateway
Note:
The certificate (containing the public key) and the private key are
stored in two separated files and uploaded individually into the Edge
Gateway. You as the user are solely responsible that the file with
the certificate and the file with the private key fit together, which you
have uploaded into the Edge gateway.. for logical connection
between certificate and private key, i.e. that the public key
contained in thespecified certificate fits to the specified private key.
16.5.1
Working with certificates for HTTP and OPC UA Server
16.5.1.1
Uploading the server certificate from a file into the Edge Gateway
Note:
If at one point in time, you intend to upload both a server certificate
and the related private key file, always upload the key file
key.pem
first and then upload the certificate file
cert.pem
into the Edge
Gateway. Do not try to reverse this order!
To upload a server certificate for the communication with the HTTP server,
Node-RED, the Edge Server or the REST API from a file into the Edge
Gateway, proceed as follows.
Ø
Select option
Service certificates
in selection list (Selection list Root/
Service Certificates).
Ê
In window
Certificates
, a tree structure is displayed instead of the
former display of the contents of the Linux trust store.
If the server certificate applies to the communication with the HTTP server,
Node-RED, the Edge Server or the REST API:
Ø
Within window
Certificates
, select the entry
cert.pem
below
nginx
.
Alternatively: If the server certificate applies to the communication with the
OPC UA-Server or mosquitto:
Edge Gateway | NIOT-E-TPI51-EN-RE (Connect)
DOC170502UM04EN | Revision 4 | English | 2018-08 | Released | Public
© Hilscher 2017 – 2018