3 Detailed checklist
Checklist
Article ID: 109745536, V2.0, 05/2022
13
©
S
iem
e
n
s A
G
2
0
2
2
A
ll r
igh
ts
re
se
rv
e
d
3.8
HTTPS certificates and SSH keys
Menu path
You can find this information in the following paths:
•
With MSPS: "System > Load & Save"
•
With X-200 and X-300: "System > Save & Load"
Recommendation
By default, the devices generate and use a self-signed certificate/key pair for
HTTPS and SSH.
A consequence of this are warning messages in the browser when you open the
WBM over HTTPS.
You can load your own certificates into the devices via HTTPSCert,
SSHPrivateKeyECDSA, SSHPrivateKeyRSA as an alternative. If the container is
password-protected, enter the passwords under "Passwords" before loading.
In combination with a certificate authority (CA), it is possible to check in the
browser whether it is connecting with the correct device or the correct IP address.
For this to be possible, the public key of the CA must be distributed among all
participating browsers/operating systems of the clients.
The CA and certificates are generated in TIA Portal, SINEC NMS or other software
tools.