hit counter script

Introduction - Siemens SR640XA User Manual

Generating ssh keys and ssl certificates using windows
Table of Contents

Advertisement

RUGGEDCOM
Application Note

Introduction

ROS (beginning with ROS v3.12.1 and onwards) and ROX can accept SSL certificates and SSH keys created
externally. This document, along with some useful scripts developed by Siemens, is intended to help users
working with Microsoft Windows® to generate their own keys and certificates for their ROS and/or ROX devices.
The Microsoft Windows Operating System has a Certificates Management console. However, the nature of key
creation and export is not particularly suitable for ROS/ROX purposes. A separate key and certificate generation
application is required.
There are many free, open source applications, such as OpenSSH and PuTTygen, that can create keys and
certificates. The instructions in this document utilize OpenSSL, a free cryptography toolkit, to generate both SSH
and SSL keys, as well as SSL certificates.
ROS and ROX will accept self-signed certificates or certificates signed by a Certificate Authority (CA). This
document will make the Windows machine a Certificate Authority (CA) and sign certificates.
IMPORTANT!
Normally, the steps involved in creating the private key and creating the Certificate Signing Request
(CSR) are the ones that will be performed if a Certificate Chain of Trust is implemented in the
organization. The CSR files are then submitted to the appropriate department for it to be signed by
a CA. Once the certificate is issued, it is then uploaded to the device in the required format. When
certificates are self-signed, the trust (identity establishment) part of SSL cannot work because each
server is essentially its own CA. For the purpose of security, it is recommended that a proper Chain of
Trust is implemented for SSL.
This document describes:
• How to generate SSL certificates and SSH keys for ROS using Siemens scripts
• How to generate SSL keys and certificates for ROX using Siemens scripts
• How to import certificates on Windows machines so the SSL certificates provided by these devices can be
verified properly
Chapter 1
Introduction
1

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sr650xaSr660xaRosRox

Table of Contents