SICAM Gridpass 3
Total Page:16
File Type:pdf, Size:1020Kb
Open Source Software Table of Contents Overview 1 SICAM Enrollment over Secure Transport (EST) 2 GridPass SICAM GridPass 3 V1.50 Workflow Step-by-Step 4 User Management 5 Manual Certificate Management 6 Managing EST 7 Other Features 8 Glossary A E50417-H8940-C598-A6 NOTE i For your own safety, observe the warnings and safety instructions contained in this document, if available. Disclaimer of Liability Copyright Subject to changes and errors. The information given in Copyright © Siemens 2018 – 2020. All rights reserved. this document only contains general descriptions and/or The disclosure, duplication, distribution and editing of this performance features which may not always specifically document, or utilization and communication of the content reflect those described, or which may undergo modifica- are not permitted, unless authorized in writing. All rights, tion in the course of further development of the products. including rights created by patent grant or registration of a The requested performance features are binding only when utility model or a design, are reserved. they are expressly agreed upon in the concluded contract. Document version: E50417-H8940-C598-A6.01 Trademarks Edition: 05.2020 SIPROTEC, DIGSI, SIGRA, SIGUARD, SIMEAS SAFIR, SICAM, Version of the product described: V1.50 and MindSphere are trademarks of Siemens. Any unauthor- ized use is prohibited. Open Source Software The product contains, among other things, Open Source Software developed by third parties. The Open Source Software used in the product and the license agreements concerning this software can be found in the Readme_OSS. These Open Source Software files are protected by copyright. Your compliance with those license conditions will entitle you to use the Open Source Software as foreseen in the relevant license. In the event of conflicts between Siemens license conditions and the Open Source Software license conditions, the Open Source Software conditions shall prevail with respect to the Open Source Software portions of the soft- ware. The Open Source Software is licensed royalty-free. Insofar as the applicable Open Source Software License Conditions provide for it you can order the source code of the Open Source Software from your Siemens sales contact – against payment of the shipping and handling charges – for a period of at least 3 years after purchase of the product. We are liable for the product including the Open Source Software contained in it pursuant to the license conditions applicable to the product. Any liability for the Open Source Software beyond the program flow intended for the product is explicitly excluded. Furthermore any liability for defects resulting from modifications to the Open Source Software by you or third parties is excluded. We do not provide any technical support for the product if it has been modified. SICAM, GridPass, Manual 3 E50417-H8940-C598-A6, Edition 05.2020 Table of Contents Open Source Software..................................................................................................................................3 1 Overview...................................................................................................................................................... 6 1.1 General...............................................................................................................................7 1.2 Public Key Infrastructure (PKI)............................................................................................. 7 1.3 Certification Authority (CA)................................................................................................. 7 1.4 PKI Workflow...................................................................................................................... 8 2 Enrollment over Secure Transport (EST).................................................................................................... 10 2.1 Function........................................................................................................................... 11 2.2 Authentication..................................................................................................................11 2.3 CRL................................................................................................................................... 12 3 SICAM GridPass...........................................................................................................................................13 3.1 Overview.......................................................................................................................... 14 3.2 Workflow.......................................................................................................................... 14 3.3 Integration........................................................................................................................15 3.4 Operating Overview.......................................................................................................... 16 4 Workflow Step-by-Step...............................................................................................................................18 4.1 Setup................................................................................................................................19 4.1.1 Preconditions.............................................................................................................. 19 4.1.2 Description..................................................................................................................19 4.1.3 Setup.......................................................................................................................... 19 4.1.4 Licensing Description...................................................................................................26 4.1.5 Licensing.....................................................................................................................26 4.2 Login Procedure................................................................................................................30 4.2.1 Initial Login................................................................................................................. 30 4.3 Create Operational CA.......................................................................................................35 4.4 Create a Server Certificate for Web UI and EST Server.........................................................40 4.5 Download and Trust the CA Certificate.............................................................................. 45 4.6 Set the Created Server Certificate as SICAM GridPass Web-Server Certificate.......................53 4.7 Configure Centralized Syslog Logging................................................................................55 5 User Management...................................................................................................................................... 56 5.1 Introduction......................................................................................................................57 5.1.1 Overview.....................................................................................................................57 5.2 User Administration.......................................................................................................... 57 5.2.1 Local User Administration............................................................................................ 57 5.2.2 Logout........................................................................................................................ 60 4 SICAM, GridPass, Manual E50417-H8940-C598-A6, Edition 05.2020 Table of Contents 5.2.3 Initial Login with a Local Account.................................................................................61 6 Certificate Management.............................................................................................................................63 6.1 Overview of Import, Export, and Creation of Certificates.................................................... 64 6.2 Remote Requests.............................................................................................................. 65 6.3 Local Requests.................................................................................................................. 66 6.3.1 Create a Certificate...................................................................................................... 66 6.3.2 Import a CSR and Issue a Certificate............................................................................. 70 6.3.3 Import a Certificate with CA Chain............................................................................... 73 6.3.4 Export a Certificate...................................................................................................... 76 6.3.5 Revoke a Certificate..................................................................................................... 78 6.4 Certification Authorities.................................................................................................... 79 6.4.1 Create a Root-CA......................................................................................................... 79 6.4.2 Import a Certification Authority....................................................................................79 6.4.3 Export a CA Certificate................................................................................................