Configuring Certificates

Certificates is where you securely manage the secure sockets layer/ transport layer security (SSLClosed Secure Sockets Layer (SSL) - A cryptographic protocol designed to secure data transmitted over a network. SSL provided encryption, server (and sometimes client) authentication, and data integrity between two communicating applications (e.g., a browser and a web server)./TLSClosed Transport Layer Security (TLS) - A cryptographic protocol used to protect data in transit over networks (including the internet) by providing confidentiality (encryption), integrity (tamper protection), and authentication between endpoints.) certificate used by the EPM Data Management web server and related services. It controls which certificate is presented over HTTPS, how it is updated, and how changes are audited.

Note - You can only access this function if you have the Can access Settings permission. To update settings you need the Can edit Settings permission. If you need to access these functions and do not have permission, please contact your system administrator.
Note - The Generate New Certificate button is available only on the integrated human machine interface (HMI). When a new certificate is generated from the HMI, the certificate is automatically applied and updated on the device.

To set up your certificates remotely:

  1. From the EPM Data User Interface screen, select Options - Settings and Users - Settings:

  2. The Settings screen displays, select Certificates which then displays on the right-hand side of the screen:

  3. If you are not already in Configuration lock, the Configuration lock screen displays:

    Enter a reason if required and then select Confirm . The system configuration is now locked pending the submission of your update and the Configuration Locked icon displays on the status bar.

    Note - Configuration lock does not affect the operation of the EPM device.
    See Configuration Lock for details.
  4. Select Generate New Certificate from the HMI and the Session termination screen displays:

    Once you select Ok, you see Connection lost screen. Login to your account using your Username and Password.

    Tip - You might see Your connection is not private message, proceed with your IP address and reload to see the Login to your account screen.
  5. To add the newly generated certificate select Not secure - Certificate details:

    Note - The steps to install certificates are different for each web browser.
  6. The Certificate Viewer screen opens, select Details - Export:

    Tip - If you have not already saved your recently downloaded certificate save now.
  7. Locate the downloaded Certificate, right click and select Install Certificate:

  8. The Certificate Import Wizard Screen displays, select Local Machine - Next:

  9. Select Place all certificates in the following store:

  10. Select Browse - Trusted Root Certification Authorities - Ok:

     

  11. Select Next - Finish:

    Tip - Refresh the page or close the browser and reopen for the certificate to load.