Public Key Infrastructure
235/258
16.6 Working with client authentication certificates for outbound
connections
For outbound connections, client authentication certificates can be stored
within the PKI of the Edge Gateway, as described in
certificates for specific servers
page 226]. Here, a 1:n relation between
server and client applies (i.e. one certificate and one key per client and per
server).
The following actions can be performed for a specific server:
1. Uploading the certificate for client authentication from a file into the
Edge Gateway
2. Downoading a certificate for client authorization for a specific server
from the Edge Gateway
3. Removing a certificate for client authorization for a specific server on
the Edge Gateway
4. Newly creating a certificate for client authorization for a specific server
on the Edge Gateway
5. Copying the path to a certificate for client authorization for a specific
server on the Edge Gateway
Note:
The certificate (containing the public key) and the private key are
stored in two separated files and uploaded individually into the Edge
Gateway. You as the user are solely responsible that the file with
the certificate and the file with the private key fit together, which you
have uploaded into the Edge gateway.. for logical connection
between certificate and private key, i.e. that the public key
contained in thespecified certificate fits to the specified private key.
16.6.1
Working with certificates for client authentication
16.6.1.1
Uploading a certificate for client authorization for a specific server into the
Edge Gateway
Note:
If at one point in time, you intend to upload both a client
authentication certificate and the related private key file, always
upload the key file
key.pem
first and then upload the certificate file
cert.pem
into the Edge Gateway.
To upload a server certificate for client authorization for a specific server
from a file into the Edge Gateway, proceed as follows.:
Ø
Select option
Service certificates
in selection list (Selection list Root/
Service Certificates).
Ê
In window
Certificates
, a tree structure is displayed.
Ø
In window
Certificates
, select the entry
node-
opcuaclient_cert.pem
below
node-red
.
Edge Gateway | NIOT-E-TPI51-EN-RE (Connect)
DOC170502UM04EN | Revision 4 | English | 2018-08 | Released | Public
© Hilscher 2017 – 2018