Features that use Certificates

In the server-side authentication (SSA) for managers the managers use SSL certificates to authenticate themselves. They authenticate to the running manager, e.g. the Data Manager is started and runs. In this case VALARCH must have a certificate and be started with the right user. The WinCC OA Multiplexing Proxy , WinCC OA HTTP server, webView.ewo as well as the Reporting Manager use SSL for the secure communication. The Multiplexing Proxy uses SSL in the communication between managers and the Multiplexing Proxy and the HTTP server in the communication between the server and the client such as webbrowser or the Desktop UI. The Reporting Manager uses the SSL communication when querying values from WinCC OA. For a more secure OPC UA Client-Server communication certificates are required by the OPC UA Server and the OPC UA Client.

Table 1. WinCC OA Features
Feature Type of Certificate

Multiplexing Proxy

Filebased certificate

WindowsCertificateStore certificate

Server-side Authentication for Managers (SSA )

Filebased certificate

WindowsCertificateStore certificate

HTTP Server (Web Server)

Mobile UI Application, ULC UX, NodeRED, Dashboard und Desktop UI use the HTTP Server

Filebased certificate

Mobile UI Application Filebased certificate
ULC UX Filebased certificate
NodeRED Filebased certificate
Dashboard Filebased certificate
Desktop UI Filebased certificate

Reporting Manager

Filebased certificate

WebView.ewo

Filebased certificate

OPC UA

Filebased certificate

Mobile UI Application Filebased certificate
Video Feature Filebased certificate
S7 Driver Filebased certificate