Kkula
Browse Questions » Industrial Edge: Self signed certificates

About User

Questions Asked: 29.3K

Answers Given: 0

0
  • Open

Industrial Edge: Self signed certificates

For the self-signed certificate chain. Is there a TTL set in them? Does the whole system go down in a year? I can't tell if there is certificate management built in but it looks like not. Should I be putting it under management of a certificate management system? Do you have OCSP hooks in your control plane?

0 Likes 0 Favourites 0 Followers 0 Comments
Answers(1)

Self-Signed Certificates & TTL in Siemens Systems

Self-signed certificates used by Siemens systems do have a Time To Live (TTL), typically one year. After this period, the system will likely experience connectivity issues as clients will no longer trust the expired certificate.

Currently, our systems do not have automated certificate management built-in. Implementing a robust certificate management system (CMS) like Microsoft Certificate Services, OpenSSL, or a cloud-based solution is highly recommended to avoid service disruptions. A CMS automates renewal and distribution.

Regarding Online Certificate Status Protocol (OCSP), our control plane does not currently have direct OCSP hooks. Reliance on OCSP stapling by the clients is the expected behavior. Using a CMS allows for OCSP responses to be managed efficiently.

For detailed guidance on certificate replacement and best practices, please refer to the SiePortal knowledge base: SiePortal. Search for relevant articles using keywords like "certificate renewal", "self-signed certificate", or the specific Siemens product you are using.

0
Add a comment