Install the SSL Certificate

The SSL (Secure Sockets Layer) certificate is a file stored on the PCMM2G that enables encrypted connections (HTTPS).

  • The SSL certificate is only applicable to PCMM2G.
  • By default, the PCMM2G contains a certificate generated by Kollmorgen.
  • The web browser shows a warning message when the connection is not secure.
    • To prevent this warning, the default certificate should be replaced by creating a new certificate in the Security tab.
    • This certificate must be downloaded and installed onto the PC connected to the PCMM2G.
    • This user-created certificate is assigned to the PCMM2G's IP address.
      • The certificate becomes invalid if this IP address is modified.

Certificate Expiration Period

  • The certificate expiration period is set by the user.
    • Kollmorgen recommends 365 days.
  • When the expiration period is over, the certificate becomes invalid.
  • The user must create and install a new certificate to prevent security warnings.

Installation Procedure

Assumptions

The PCMM2G is connected to the router or laptop.
See the PCMM2G Installation Manual.


  • The images in this procedure are from the Microsoft® Edge browser.
    Other browsers have different options.
    It's recommended to have only one instance of the web browser open for this procedure.
  1. Open a web browser.
  2. Enter the URL for the PCMM2G.
    The default IP address is 192.168.0.101.
    A connection message appears. (Connection message)
  3. Connection message

  4. Click the Advanced button.
    Additional information about the connection appears. (Connection message - Advanced information)
  5. Connection message - Advanced information

  6. Click the Continue to (IP address) (unsafe) link.
    The Web server opens for the PCMM2G. (Not Secure PCMM2G)
  7. Not Secure PCMM2G

  8. Login to the PCMM2G.
    See User Authentication.
  9. Click the Settings tab.
  10. Click the Security tab. (Security tab)
  11. Security tab

  12. In the Create SSL Certificate area:
    1. Enter the Organization Name.
    2. Enter the Expiration Period (days). (Create SSL Certificate area with content)

      • Kollmorgen recommends 365 days.

      Create SSL Certificate area with content

    3. Click the Create SSL Certificate button.
      A confirmation message appears. (Confirmation message)
    4. Confirmation message

  13. Click OK to continue.
    The SSL certificate successfully created message appears. (SSL certificate successfully created message)
  14. SSL certificate successfully created message

  15. Click OK to reboot the controller.
    A rebooting message appears. (Rebooting message)
  16. Rebooting message

  17. Wait for the Disconnected message to appear. (Disconnected message)
  18. Disconnected message

  19. Refresh the browser.
    The connection message reappears. (Connection message)
  20. Connection message

  21. Click the Advanced button again.
    Additional information about the connection reappears. (Connection message - Advanced information)
  22. Connection message - Advanced information

  23. Click the Continue to (IP address) (unsafe) link.
    The Web server opens for the PCMM2G.
  24. The PCMM2G shows it is Not secure. (Not secured PCMM2G)

    Not secured PCMM2G

  25. Click the Not secure button and click the Your connection to this site isn't secure option. (Your connection to this site isn't secure option)
  26. Your connection to this site isn't secure option

    The certificate for this site is not valid message appears.

  27. In the message header, click the Show certificate button. (Show certificate button)
  28. Show certificate button

    The Certificate Viewer dialog opens.
    The General tab is active. (Certificate Viewer dialog - General tab)

    Certificate Viewer dialog - General tab

  29. Click the Details tab. (Details tab with Export button.)
  30. Details tab with Export button.

  31. Click the Export button.
    The Save As dialog opens. (Save As dialog)
  32. Save As dialog

  33. Select a folder to save the .crt file.
    This example procedure uses the Downloads folder. (Save As dialog with saved .crt file)
  34. Save As dialog with saved .crt file

  35. Click the Save button.
    The Save As dialog closes and the Details tab returns.
  36. Use Windows® Explorer to locate and select the .crt file.
    • The .crt file name is the PCMM2G's IP address.
      Example: 192.168.0.101.crt.
  37. Right-click the file and click the Install Certificate option. (Selected .crt file and the Install Certificate option)
  38. Selected .crt file and the Install Certificate option

    The Certificate Import Wizard opens. (Certificate Import Wizard - Welcome page)

    Certificate Import Wizard - Welcome page

  39. Accept the default on the Welcome page and click Next.
    The Certificate Store page opens.
  40. Select the Place all certificates in the following store option. (Certificate Import Wizard - Certificate Store page with selection)
  41. Certificate Import Wizard - Certificate Store page with selection

  42. Click the Browse... button.
    The Select Certificate Store dialog opens.
  43. Select the Trusted Root Certification Authorities certificate store. (Selected Certificate Store dialog - Trusted Root Certification Authorities)
  44. Selected Certificate Store dialog - Trusted Root Certification Authorities

  45. Click OK to save the changes or selections and close the dialog.
    The Certificate Store page returns and shows the selected Certificate store. (Certificate Import Wizard - Certificate Store page with selected Certificate store)
  46. Certificate Import Wizard - Certificate Store page with selected Certificate store

  47. Click Next.
    The Completing the Certificate Import Wizard page opens. (Certificate Import Wizard - Completing the Certificate Import Wizard page)
  48. Certificate Import Wizard - Completing the Certificate Import Wizard page

  49. Click Finish.
    A Security Warning dialog opens. (Security Warning dialog)
  50. Security Warning dialog

  51. Click Yes to install this certificate.
    The Certificate Import Wizard - The import was successful message appears. (Certificate Import Wizard - The import was successful message)
  52. Certificate Import Wizard - The import was successful message

  53. Click OK to continue.
    The Certificate Import Wizard - Details tab returns.
  54. Close the wizard.
    The connected PCMM2G Web server page returns.
  55. Close the web browser.
  56. Verify ALL web browser windows are closed.
  57. Open a new web browser instance and use the URL to connect to the Web server.
    The PCMM2G shows it is secure.
  58. Click the Secure button. (Secure PCMM2G)
  59. Secure PCMM2G

  60. Click the Connection is secure option. (Connection is secure option)
  61. Connection is secure option

    The Certificate is secure message appears. (Certificate is secure message)

    Certificate is secure message

  62. Click the Settings tab.
  63. Click the Security tab.
    The SSL Certificate Details area shows the Certificate Status and expiration date. (SSL Certificate Details area with certificate information)
  64. SSL Certificate Details area with certificate information

Troubleshooting

The webpage displays a warning:

  • KAS IDE warning: The identity of this web site or the integrity of this connection cannot be verified.
  • Microsoft Edge / Google Chrome warning: Your connection isn’t private.
  • Mozilla Firefox warning: Warning: Potential Security Risk Ahead.

Remedies

  • Verify the current certificate:
    • has been downloaded and installed onto the machine.
    • matches the IP address of the controller.
    • has not expired yet

The IP address of the PCMM2G does not match the IP address listed on the SSL certificate.

Remedies

  • Create, download, and install a new certificate with the new IP address.
  • Configure the IP address with a static IP address matching the certificate’s IP address using the rotary switch.
  • Reserve the certificate’s IP address for the PCMM2G using a router or server.

The KAS IDE continually prompts a Security Alert dialog box.

Remedies

  • Click Yes to all the dialog boxes to continue to the Web server.
  • Restart KAS-IDE.
  • This situation can be avoided in the future by closing the Web server in KAS-IDE and creating the certificate using a web browser.