Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

Join our "Ask Me About" community webinar on May 20th at 9 AM CET and 5 PM CET to explore cybersecurity and monitoring for Data Center and edge IT. Learn about market trends, cutting-edge technologies, and best practices from industry experts.
Register and secure your Critical IT infrastructure

Impact from Microsoft Update for Minimum Certificate Key Length

Geo SCADA Knowledge Base

Access vast amounts of technical know-how and pro tips from our community of Geo SCADA experts.

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • Home
  • Schneider Electric Community
  • Knowledge Center
  • Geo SCADA Knowledge Base
  • Impact from Microsoft Update for Minimum Certificate Key Length
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close
Top Labels
Top Labels
  • Alphabetical
  • database 32
  • Web Server and Client 31
  • WebX 19
  • Request Form 18
  • Lists, Events & Alarms 16
  • ViewX 15
  • Application Programming 12
  • Setup 12
  • Telemetry 8
  • Events & Alarms 7
  • Lists 7
  • Mimic Graphics 7
  • Downloads 6
  • Support 5
  • IoT 5
  • SCADA 5
  • Geo SCADA Expert 5
  • Drivers and Communications 4
  • Security 4
  • DNP 3 3
  • IEC 61131-3 Logic 3
  • Trends and Historian 2
  • Virtual ViewX 2
  • Geo Scada 1
  • ClearSCADA 1
  • Templates and Instances 1
  • Releases 1
  • Maps and GIS 1
  • Mobile 1
  • Architectures 1
  • Tools & Resources 1
  • Privacy Policy 1
  • OPC-UA 1
  • Previous
  • 1 of 4
  • Next
Latest Blog Posts
  • OPC UA - Driver and Server
  • Requirements for Generating a Valid OPC UA Server Certificate
  • Load Events Using LoadRecord and LoadRecords
  • Geo SCADA Embedded Component Licenses
  • Geo SCADA 2023 Known Issues
Related Products
product field
Schneider Electric
EcoStruxure™ Geo SCADA Expert

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Anonymous user
Not applicable
‎2021-06-09 06:10 PM
0 Likes
0
1236
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

‎2021-06-09 06:10 PM

Impact from Microsoft Update for Minimum Certificate Key Length

Originally published on Geo SCADA Knowledge Base by Anonymous user | June 10, 2021 03:10 AM

📖 Home  Back  

Problem

Microsoft has released update KB2661254 for all operating systems including Windows XP Service Pack 3/Vista/7 (32bit & 64bit) and Windows Server 2003/2008 (32bit & 64bit).  This update has a direct impact on ClearSCADA (WebX in particular) as it restricts the minimum certificate length to 1024 bits.  WebX users who are currently using 512 bit certificates will suddenly find an abrupt change in performance once this update is installed.  The effects of installing KB2661254 on systems that use a 512 bit certificate are as follows:

  • WebX will no longer connect or display any data from the ClearSCADA database
  • ViewX client side scripts will stop working (as they connect to the ClearSCADA server over the secure web socket)


NOTE: ClearSCADA systems using 1024 bit or greater certificates are not affected by this update

Solution

There are several possible solutions to this issue for customers who are using 512 bit certificates:

Certificates larger than 512 bits are only supported on CS 2009 R2.4 and above. If purchasing new certificates to replace old ones please note that intermediate certificates are only supported in CS 2010 R3 and above. Most certificate authorities now sell intermediate by default.

  • Upgrade to a 1024 or 2048 bit certificate
  • If the certificate was purchased (e.g. from Verisign) then an updated certificate will need to be purchased
  • If the certificate was generated by ClearSCADA then deleting the existing certificate (*both* the private key and certificate files) and then restarting the ClearSCADA server will generate a new self-signed certificate.

The location of the private key and certificate files are defined the the following registry keys:

HKLM\SOFTWARE\Schneider Electric\ClearSCADA\DB\WebSSLPrivKeyHKLM\SOFTWARE\Schneider Electric\ClearSCADA\DB\WebSSLPubCert


The key length for certificates generated by ClearSCADA is defined by the following registry key (needs to be at least 1024):

HKLM\SOFTWARE\Schneider Electric\ClearSCADA\DB\WebSSLKeySize

 

  • Flush the old certificates from client machines by going to (Internet Options - Content - Clear SSL State)
  • Reduce the minimum key length back to 512 bits on the client machine:

 

Certutil -setreg chain\minRSAPubKeyBitLength 512


See http://blogs.technet.com/b/pki/archive/2012/07/13/blocking-rsa-keys-less-than-1024-bits-part-2.aspx for more details.

Go: Home Back

Labels:
  • Security

  • WebX

Author

Biography

Anonymous user

Link copied. Please paste this link to share this article on your social media post.

  • Back to Blog
  • Newer Article
  • Older Article
To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2025 Schneider Electric

This is a heading

With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

of