Functional changes
WebSocket Service (WSS) requires a .CER file
In this release of
FactoryTalk Activation Manager
, the WebSocket Service has been enhanced to
use Base-64 encoded X.509 .CER certificate files instead of PKCS #12 .PFX files. You must
provide a .CER format certificate for the WebSocket Service to function.To create a new self-signed certificate using IIS:
- StartIIS Manager.
- SelectServer Certificates.
- UnderActions, selectCreate Self-Signed Certificate.
- InCreate Self-Signed Certificate, enter a name for the certificate.
- InSelect a certificate store for the new certificate, selectPersonal.
- SelectOK.
To export an existing certificate using Windows Settings:
- OpenWindowsSettings.
- In theSearchbar, entercertificate, then pressEnter.
- SelectManage computer certificates.
- ExpandPersonal > Certificates, right-click the certificate to export, then selectAll Tasks > Export.
- SelectNext.
- SelectNo, do not export the private key, then selectNext.
- SelectBase-64 encoded X.509 (.CER), then selectNext.
- Enter or browse for a path and filename for the certificate, then selectNext.NOTE: The path must be accessible by the Local Service user. recommends a subfolder within C:\ProgramData.
- Verify the settings, then selectFinish.
(optional) To create and export a self-signed certificate using OpenSSL, see
FactoryTalk Activation Manager
Help.To configure
FactoryTalk Activation Manager
to use an exported .CER certificate:- InFactoryTalk Activation Manager, select theAdvancedtab.
- SelectConfigure Websocket Server.
- Select the ellipsis (…) next to Certificate file to use forWebsocket Service.
- InOpen File, browse to the .CER file to use, then selectOK.
- SelectApply.
To import the certificate into the Trusted Root Certification Authorities local computer
store:
- Use the MMC.exe snap-in and administrator permissions to add the certificate to the Trusted Root Certification Authorities local computer store. For detailed instructions, see Import the certificate into the local computer store.IMPORTANT: In order for communications to operate correctly, the certificate from the WebSocket Service must be added to the Trusted Root Authority of the operating system of each client. Then, a certificate from each of the clients must be added to the Trusted Root Authority of the operating system of theFactoryTalk Activation Managerserver.
Provide Feedback