Install the SSL Server Certificate (Self-Signed)

IMPORTANT: This procedure is only for PCMM2G controllers.

The Secure Sockets Layer (SSL) certificate is a file stored on the PCMM2G that enables encrypted connections (HTTPS).

  • The SSL certificate is only applicable to PCMM2G.
  • By default, the PCMM2G contains a certificate generated by Kollmorgen.
  • The web browser shows a warning message when the connection is not secure.
    • To prevent this warning, the default certificate should be replaced by creating a new certificate in the Security tab.
    • This certificate must be downloaded and installed onto the PC connected to the PCMM2G.
    • This user-created certificate is assigned to the PCMM2G's IP address.
      • The certificate becomes invalid if this IP address is modified.

Certificate Expiration Period

  • The certificate expiration period is set by the user.
    • Kollmorgen recommends 365 days.
  • When the expiration period is over, the certificate becomes invalid.
  • The user must create and install a new certificate to prevent security warnings.

Installation Procedure

Assumptions

The PCMM2G is connected to the router or laptop.
See the PCMM2G Installation Manual.

Note

  • The self-signed SSL Certificate generated from this procedure can be used by the OPC UA Server to enable encrypted and authenticated data exchange between OPC UA clients and the PCMM2G controller.
  • See OPC UA - Create New Driver Configuration for setup instructions.

Procedure

  1. Open a web browser.
  2. Enter the controller's IP address for the URL.
    The default IP address for the PCMM2G is 192.168.0.101.
    A connection message appears.
  3. Click the Advanced button.
    Additional information about the connection appears.
  4. Click the Continue to (IP address) (unsafe) link.
    The Web server opens for the PCMM2G.
  5. Login to the PCMM2G.
    See User Authentication.
  6. Click the Settings tab.
  7. Click the Certificates tab.
  8. In the Create SSL Server Certificate (Self-Signed) area:
    1. Enter the Organization Name.
    2. Enter the Expiration Period (days).
      Kollmorgen recommends 365 days.
    3. Click the Create Certificate button.
      A confirmation message appears.
  9. Click OK to continue.
    The SSL certificate successfully created message appears.
  10. Click OK to reboot the controller.
    A rebooting message appears.
  11. Wait for the Disconnected message to appear.
  12. Refresh the browser.
    The connection message reappears.
  13. Click the Advanced button again.
    Additional information about the connection reappears.
  14. Click the Continue to (IP address) (unsafe) link.
    The Web server opens for the PCMM2G.
    The PCMM2G shows it is Not secure.
  15. Click the Not secure button and click the Your connection to this site isn't secure option.
  16. The certificate for this site is not valid message appears.

  17. In the message header, click the Show certificate button.
  18. The Certificate Viewer dialog opens.
    The General tab is active.

  19. Click the Details tab.
  20. Click the Export button.
    The Save As dialog opens.
  21. Select a folder to save the .crt file.
    This example procedure uses the Downloads folder.
  22. Click the Save button.
    The Save As dialog closes and the Details tab returns.
  23. Use Windows Explorer to locate and select the .crt file.
    • The .crt file name is the PCMM2G's IP address.
      Example: 192.168.0.101.crt.
  24. Right-click the file and click the Install Certificate option.
  25. The Certificate Import Wizard opens.

  26. Accept the default on the Welcome page and click Next.
    The Certificate Store page opens.
  27. Select the Place all certificates in the following store option.
  28. Click the Browse... button.
    The Select Certificate Store dialog opens.
  29. Select the Trusted Root Certification Authorities certificate store.
  30. Click OK to save the changes or selections and close the dialog box.
    The Certificate Store page returns and shows the selected Certificate store.
  31. Click Next.
    The Completing the Certificate Import Wizard page opens.
  32. Click Finish.
    A Security Warning dialog opens.
  33. Click Yes to install this certificate.
    The Certificate Import Wizard - The import was successful message appears.
  34. Click OK to continue.
    The Certificate Import Wizard - Details tab returns.
  35. Close the wizard.
    The connected PCMM2G Web server page returns.
  36. Close the web browser.
  37. Verify ALL web browser windows are closed.
  38. Open a new web browser instance and use the URL to connect to the Web server.
    The PCMM2G shows it is secure.
  39. Click the Secure button.
  40. Click the Connection is secure option.
  41. The Certificate is secure message appears.

  42. Click the Settings tab.
  43. Click the Certificates tab.
    The SSL Server Certificate Details area shows the Status and expiration date.

Troubleshooting

The webpage displays a warning:

  • KAS IDE warning: The identity of this web site or the integrity of this connection cannot be verified.
  • Microsoft Edge / Google Chrome warning: Your connection isn’t private.
  • Mozilla Firefox warning: Warning: Potential Security Risk Ahead.

Remedies

  • Verify the current certificate:
    • has been downloaded and installed onto the machine.
    • matches the IP address of the controller.
    • has not expired yet

The IP address of the PCMM2G does not match the IP address listed on the SSL certificate.

Remedies

  • Create, download, and install a new certificate with the new IP address.
  • Configure the IP address with a static IP address matching the certificate’s IP address using the rotary switch.
  • Reserve the certificate’s IP address for the PCMM2G using a router or server.