System

These release notes apply to
FactoryTalk Policy Manager
version
6.60.00
and
FactoryTalk System Services
version
6.60.00
.

FactoryTalk Policy Manager

FactoryTalk Policy Manager
divides the system security policy to different component areas of control. Use these component areas to design policy models that control the permissions and usage of devices within the system.
Zones
Groups of devices.
Devices
Computers, controllers, modules, HMI panels, CIP Proxy devices,
OPC UA
clients,
OPC UA
servers, and drives.
Conduits
Communication routes between components.
FactoryTalk Policy Manager
enables you to use
ODVA
CIP Security
and
OPC UA
standards to design the security policy model for your system.

FactoryTalk System Services

FactoryTalk System Services
provide the policy authority, certificate authority, identity services, and deployment services required to enforce security policies.
FactoryTalk Policy Manager
uses these
FactoryTalk System Services
:
Authentication Service
Authenticates users and validates user resource requests. Validates user credentials against
FactoryTalk® Directory
and
FactoryTalk
security policy settings to obtain privileges associated with the user.
Certificate Service
Issues and manages X.509v3 certificates for use within the
FactoryTalk
system.
Deployment Service
Translates the security policy model defined using
FactoryTalk Policy Manager
to
CIP
and
OPC UA
configurations that are delivered to endpoints. Protocols configurations are deployed independently.
Diagnostics Service
Makes
FactoryTalk
audit and diagnostic logs available as a web service.
Policy Service
Builds and manages network trust models and define security policy for
CIP
and
OPC UA
endpoints.
Differential deployment
Enables deployment of changes in the security policy model only to the affected devices, instead of deploying the model to all devices.
Support for
CIP Security
Proxy devices
Uses proxy devices to secure communications to and from devices that do not have
CIP Security
capabilities.
Backup and restore
Preserves and restores the security policy models if there is a system failure.
Syslog routing
Sends eventing configuration to devices and stores events from
FactoryTalk Policy Manager
and
FactoryTalk System Services
as Syslog messages.
DTLS timeout
Configures the devices to close their DTLS sessions after a specified period of inactivity.
EST service
The Automatic Policy Deployment feature uses Enrollment over Secure Transport (EST) to leverage the
ODVA
CIP Security
pull model. This enables EtherNet/IP endpoints to start the deployment of policies defined on a system server.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal