Tools -> Transfer -> Certificate Settings

Certificate settings for LOGO! 9.0 and later versions devices

You can configure certificates for LOGO! 9 and later version devices in both Device settings and Online settings in LOGO!Soft Comfort. When you configure certificates in Online settings, LSC requires that you confirm the connection interface for each communication attempt. See "Tools ‑> Transfer" for complete information.

For different communication scenarios, LOGO!Soft Comfort provides you different certificate strategies to ensure secure communication.

Communication

Applicable certificate strategy

  • LSC & TDE access

  • LOGO! communication

  • Build-in certificate (default setting)

  • PSK certificate

  • External certificate

Web access with HTTPS mode

  • PSK certificate (default setting)

  • External certificate

Select the certificate strategy from the drop-down list for each communication scenario, then click the Apply button.

To learn more about LOGO! certificate strategy, refer to the "Security" section in LOGO! System Manual.

Note

LOGO! web server access

To access the LOGO! web server, you need to enable the web server access first. Refer to Tools -> Transfer -> Access control (LOGO! 9 and later versions only) for detailed information.

Besides, you need to install the PSK or external certificate on the supported web browser. To learn how to install the PSK certificate on the web browser, refer to LOGO! System Manual.

Build-in Certificate

LOGO! build-in certificate includes LOGO! root certificate, LOGO! issuing certificate and LOGO! device certificate. You can view the brief information of each build-in certificate in LOGO!Soft Comfort. To download these certificates, click Save button to save the certificate in your PC. Or you can find the LOGO! build-in certificates in LOGO!Soft Comfort USB stick.

PSK Certificate

To generate a PSK (Pre-shared Key) certificate, you need to enter a password, then click the Generate button. LOGO! Soft Comfort will display the brief information of the generated PSK issuing certificate and PSK device certificate. Click the Save button to download and save the certificates to your PC.

Note

The PSK certificate password rule is as follows:

  • ASCII characters are supported.

  • The maximum length of password is 12.

External Certificate

Enter the CSR (Certificate Signing Request) subject, then click Generate button to generate the .CSR file. You need to save the .CSR file to your PC and use the third-party certificate authority to generate the external certificate.

Click ... button to import the generated external certificate. LOGO!Soft Comfort displays the brief information of the imported certificate.

Note

You can only generate the .CSR file in LOGO!Soft Comfort Online settings.

Note

CSR information input limits

Note the following input limits for CSR information:

  • Common Name is mandatory to input.

  • When the Common Name is set as a domain name, you must input it as the domain name format: example.com or *.example.com.

  • ASCII characters are supported.

  • Except the "Others" field, the length limit for all input field is 64 bytes.

  • Country Name must be two upper case letters, for example, US, DE.

  • Email Address must be in the email address format: user@example.com.

  • For the "Others" field, the input format is, key=xxx. Use a comma to separate each pair when there are multiple pairs. "xxx" stands for the value you want to input. The key can only be: serialNumber, postalAddress, postalCode, title.

Note

Certificates validity period

For PSK certificates and external certificates, the device certificate's validity period is 47 days, while the issuing certificate's validity period is longer.

Verification of the certificate chain fails if the issuing certificate's validity period falls outside the device certificate's validity period.

To ensure that the PSK and external certificates work properly, it's recommended that you regularly check the their validity periods and regenerate them when necessary.

To set up the communication between devices, you need to import and trust the certificate from the communication server/client in one of the following cases:

To learn how to manage the trusted external certificates, refer to LOGO! settings -> Online settings -> Trust CA settings (LOGO! 9 and later versions only).

Certificate settings for LOGO! 8.4 and 8.3 devices

This menu command allows you to check the status of all LOGO! certificates. You can also download and save each LOGO! certificate to your local file system.

You can check the valid period of all LOGO! certificates.

To save certain LOGO! certificate, click the Save button below corresponding certificate, then you can choose the path to store the certificate file.

0BA8:

For LOGO! 8.4 and 8.3 devices, certificate settings are available only in online settings.