Root and intermediate certificate checklist

This checklist assumes that you are serving as you own CA (Certificate Authority). It summarizes the steps for setting up digital certificates using the Workbench User Key Store of a physically and electronically secure computer.

Use the check list to make sure you perform all necessary configuration tasks.

c Computer and device network disconnected from the company LAN and global Internet. Refer to Secure communication.

c Needed certificates identified: one root CA certificate, two or more intermediate certificates (optional) and one server certificate per controller. You need a code-signing certificate if you will be customizing the system by adding program objects. Refer to Certificates.

c Logical certificate naming convention established (a naming convention is not required, but it will help you differentiate among your certificates). Refer to Naming convention.

c CSR folder structure under the certManagement folder in the niagara_user_home created. Refer to Creating a CSR folder structure.

c Root CA certificate and any intermediate certificates created. Refer to Creating a root CA certificate.

c CSR for each intermediate and code-signing certificate created. Refer to Creating a CSR.

c Any intermediate and code-signing certificates signed using the root CA certificate. Refer to Signing a certificate.

c Any signed intermediate certificates imported back into the Workbench User Key Store where they were originally created. Refer to Importing the signed certificate back into the User Key Store.

c Backup of the root CA certificate and the signed intermediate certificates created. Refer to Exporting a certificate.

c Root CA certificate with only its public key exported in preparation to import it into the platform/station Trust Stores. Refer to Exporting a certificate