System
These release notes apply to
FactoryTalk Policy Manager
version 6.60.00
and FactoryTalk System Services
version 6.60.00
.FactoryTalk Policy Manager
FactoryTalk Policy Manager
divides the system security policy to different component areas of control. Use these component areas to design policy models that control the permissions and usage of devices within the system.
- Zones
- Groups of devices.
- Devices
- Computers, controllers, modules, HMI panels, CIP Proxy devices,OPC UAclients,OPC UAservers, and drives.
- Conduits
- Communication routes between components.
FactoryTalk Policy Manager
enables you to use ODVA™
CIP Security™
and OPC UA
standards to design the security policy model for your system.FactoryTalk System Services
FactoryTalk System Services
provide the policy authority, certificate authority, identity
services, and deployment services required to enforce security policies.FactoryTalk Policy Manager
uses these FactoryTalk System Services
:
- Authentication Service
- Authenticates users and validates user resource requests. Validates user credentials againstFactoryTalk® DirectoryandFactoryTalksecurity policy settings to obtain privileges associated with the user.
- Certificate Service
- Issues and manages X.509v3 certificates for use within theFactoryTalksystem.
- Deployment Service
- Translates the security policy model defined usingFactoryTalk Policy ManagertoCIP™andOPC UAconfigurations that are delivered to endpoints. Protocols configurations are deployed independently.
- Diagnostics Service
- MakesFactoryTalkaudit and diagnostic logs available as a web service.
- Policy Service
- Builds and manages network trust models and define security policy forCIPandOPC UAendpoints.
- Differential deployment
- Enables deployment of changes in the security policy model only to the affected devices, instead of deploying the model to all devices.
- Support forCIP SecurityProxy devices
- Uses proxy devices to secure communications to and from devices that do not haveCIP Securitycapabilities.
- Backup and restore
- Preserves and restores the security policy models if there is a system failure.
- Syslog routing
- Sends eventing configuration to devices and stores events fromFactoryTalk Policy ManagerandFactoryTalk System Servicesas Syslog messages.
- DTLS timeout
- Configures the devices to close their DTLS sessions after a specified period of inactivity.
- EST service
- The Automatic Policy Deployment feature uses Enrollment over Secure Transport (EST) to leverage theODVACIP Securitypull model. This enables EtherNet/IP endpoints to start the deployment of policies defined on a system server.
Provide Feedback