Functional changes

WebSocket Service (WSS) requires a .CER file

In this release of
FactoryTalk Activation Manager
, the WebSocket Service has been enhanced to use Base-64 encoded X.509 .CER certificate files instead of PKCS #12 .PFX files. You must provide a .CER format certificate for the WebSocket Service to function.
To create a new self-signed certificate using IIS:
  1. Start
    IIS Manager
    .
  2. Select
    Server Certificates
    .
  3. Under
    Actions
    , select
    Create Self-Signed Certificate
    .
  4. In
    Create Self-Signed Certificate
    , enter a name for the certificate.
  5. In
    Select a certificate store for the new certificate
    , select
    Personal
    .
  6. Select
    OK
    .
To export an existing certificate using Windows Settings:
  1. Open
    Windows
    Settings
    .
  2. In the
    Search
    bar, enter
    certificate
    , then press
    Enter
    .
  3. Select
    Manage computer certificates
    .
  4. Expand
    Personal > Certificates
    , right-click the certificate to export, then select
    All Tasks > Export
    .
  5. Select
    Next
    .
  6. Select
    No, do not export the private key
    , then select
    Next
    .
  7. Select
    Base-64 encoded X.509 (.CER)
    , then select
    Next
    .
  8. Enter or browse for a path and filename for the certificate, then select
    Next
    .
    NOTE: The path must be accessible by the Local Service user.
    recommends a subfolder within C:\ProgramData.
  9. Verify the settings, then select
    Finish
    .
(optional) To create and export a self-signed certificate using OpenSSL, see
FactoryTalk Activation Manager
Help.
To configure
FactoryTalk Activation Manager
to use an exported .CER certificate:
  1. In
    FactoryTalk Activation Manager
    , select the
    Advanced
    tab.
  2. Select
    Configure Websocket Server
    .
  3. Select the ellipsis (
    …
    ) next to Certificate file to use for
    Websocket Service
    .
  4. In
    Open File
    , browse to the .CER file to use, then select
    OK
    .
  5. Select
    Apply
    .
To import the certificate into the Trusted Root Certification Authorities local computer store:
  • Use the MMC.exe snap-in and administrator permissions to add the certificate to the Trusted Root Certification Authorities local computer store. For detailed instructions, see Import the certificate into the local computer store.
    IMPORTANT: In order for communications to operate correctly, the certificate from the WebSocket Service must be added to the Trusted Root Authority of the operating system of each client. Then, a certificate from each of the clients must be added to the Trusted Root Authority of the operating system of the
    FactoryTalk Activation Manager
    server.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal