Regenerate zone CA certificates

Regenerate zone Certificate Authority (CA) certificates. Deploy the security policy model to apply the regenerated zone CA certificates to devices in these zones.
Prerequisites
Log on to
FactoryTalk Policy Manager
as an administrator. See Log on to FactoryTalk Policy Manager.
  1. To regenerate CA certificates
  2. From the main menu, select
    Settings
    and then select
    CA Certificate Management
    .
  3. To regenerate zone CA certificates for
    CIP Security
    capable devices, in
    Regenerated CA certificates for CIP Security capable devices
    , select
    Regenerate CA certificates
    .
    Under
    Certificate regeneration Time of Zone CA
    , CA certificate regeneration time displays. The CA certificate regeneration time also displays in port property panes of impacted devices. For more information, see Policies.
    IMPORTANT: The certificate regeneration time is not the time of certificate deployment to devices.
  4. To regenerate zone CA certificates for
    OPC UA
    devices, in
    Regenerated CA certificates for OPC UA capable devices
    , select
    Regenerate CA certificates
    .
    Under
    Certificate regeneration Time of Zone CA
    , CA certificate regeneration time displays. The CA certificate regeneration time also displays in port property panes of impacted devices. For more information, see Policies.
    IMPORTANT: The certificate regeneration time is not the time of certificate deployment to devices.
  5. To apply the regenerated zone CA certificates to devices in these zones, deploy the policy model. See Deploy a policy model.
    TIP: If you regenerated CA certificates for
    OPC UA
    devices, you may need to update the certificate for client-server communication. For more information about
    OPC UA
    , see OPC UA security policy.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal