Verifying the certificates

After running the Certificate Wizard or manually setting up certificates it is important to confirm that communication within your system is secure.
Prerequisites: You ran the Certificate Wizard or created and imported your own certificates.
 NOTE: The platform and the station share the same trust store, while the Workbench application has its own trust store. 
Perform the following steps:
  1. From the local platform, double-click on Certificate Management and verify that the certificates were installed:
    • The server certificate appears in the User Key Store.
    • The new root CA certificate appears in the User Trust Store. This is a copy of the root CA certificate exported with the public key.
      Image
  2. From the Workbench, click Tools > Certificate Management.
  3. Confirm that the new root CA certificate created by this instance of the Workbench (for use by the wizard) is in the Workbench User Key Store alongside the self-signed Tridium server certificate.
    Image
    Workbench is a client when connecting to platforms and stations, so it is worth pointing out that this is not a Server Certificate. The root CA certificate is available to Workbench for use in signing Server Certificates.

    Notice that the root CA certificate was not imported into the Workbench User Trust Store by the Certificate Wizard. You need to import the root CA certificate into this location to ensure that this instance of the Workbench can validate server certificates while handshaking with platforms and stations on the network.

  4. To import the root CA certificate into the Workbench User Trust Store, Click Import, locate and select the new root CA certificate in ~certManagement, and click OK.
    Image
  5. Verify that the TLS level for each of the following is set to TLSv1.2:
    • Platform TLS Settings — Using the Platform Administration tool, view the Change TLS Settings option and verify the Protocol value.
    • Station Web Service — In a station connection open a Property Sheet view on the Web Service and verify the Https Min Protocol property value.
    • Station Fox Service — Open a Property Sheet view on the Fox Service and verify the Foxs Min Protocol property value.
  6. Select the appropriate server certificate for use in secure platform and station connections.
    • Set the new server certificate to be used for secure platform (niagarad) communications.
    • Set the new server certificate to be used for secure station communications via Fox and Web services.

    For details, refer to the Niagara Station Security Guide