Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

Join our "Ask Me About" community webinar on May 20th at 9 AM CET and 5 PM CET to explore cybersecurity and monitoring for Data Center and edge IT. Learn about market trends, cutting-edge technologies, and best practices from industry experts.
Register and secure your Critical IT infrastructure

SSL Certificates - Security Certificate Risk warning logging in to WorkStation or WebStation using HTTPS

Building Automation Knowledge Base

Schneider Electric Building Automation Knowledge Base is a self-service resource to answer all your questions about EcoStruxure Building suite, Andover Continuum, Satchwell, TAC…

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • Home
  • Schneider Electric Community
  • Knowledge Center
  • Building Automation Knowledge Base
  • SSL Certificates - Security Certificate Risk warning logging in to WorkStation or WebStation using HTTPS
Options
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close

Related Forums

  • Intelligent Devices Forum

Previous Next
Contributors
  • DavidFisher
    DavidFisher
  • AbeMeran
    AbeMeran
  • Cody_Failinger
    Cody_Failinger
  • RobertAndriolo
    RobertAndriolo
  • Benji
    Benji
  • Product_Support
    Product_Support

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Back to Building Automation Knowledge Base
Options
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
2 Likes
33002 Views

Link copied. Please paste this link to share this article on your social media post.

Trying to translate this page to your language?
Select your language from the translate dropdown in the upper right. arrow
Translate to: English
  • (Français) French
  • (Deutsche) German
  • (Italiano) Italian
  • (Português) Portuguese
  • (Русский) Russian
  • (Español) Spanish

SSL Certificates - Security Certificate Risk warning logging in to WorkStation or WebStation using HTTPS

Picard Product_Support
‎2018-09-11 01:38 PM

Issue

When logging in to SmartStruxure WorkStation you get a security certificate risk warning

Security Certificate Risk
There were errors validating the security certificate in use. This may pose a security risk to the system.
The certificate presented by this server was issued for a different server's address.
How do you wish to proceed? Trust certificate or Cancel

You can also get a warning when logging in through WebStation if you use the https address

Warning in Google Chrome - FireFox - Internet Explorer

Product Line

EcoStruxure Building Operation

Environment

  • SmartStruxure version 1.6 and newer
  • WorkStation
  • WebStation

Cause

Starting in version 1.6, a new security feature has been introduced validating the ES and AS server identity based on security certificates. In order to avoid seeing this warning each time you log in, you need to apply a certificate to each server (ES, AS, ASP or ASB) - either a self-signed or an existing.

Resolution

This article will describe how to import or generate a certificate, and how to install the certificate through WorkStation or a browser.

If you generate the certificate for an Automation Server, make sure that the time and time zone is correctly set in the Automation Server before generating the certificate.

Regarding external CA certificates

In step 8 below, it's shown how to generate a self-signed certificate. It might be that it's required to use an external CA certificate issued by a trusted issuer e.g. Verisign. All X509 certificates are supported. The format of the certificate must be PEM (as opposed to DER, PKCS7 or PKCS12). More about certificate types here. SBO currently only supports certificates using the PEM format which is the most common. If the external CA certificate is delivered in a container format (such as .pfx) it must be extracted before it can be used in SmartStruxure. More about extracting certificates here.


Importing or generating a certificate

  1. Log in to Workstation clicking "Trust certificate"
  2. Navigate to the control panel
  3. Click on "Security Settings"
  4. Click on "Certificates"
  5. If you see a message saying that a secure communication protocol is not in use, it means that one or more AS's are communicating with the ES using the TCP port (4444) rather than https. In order to manage certificates for all servers in one operation, you need to change the communication ports. Click on "Configure communication settings" to do that.
    - and change the protocol to HTTPS and the port to 443
  6. Back in the certificates settings, select one or more servers (in this example just the ES) and click "Manage Certificate"
  7. Select a certificate type to add. Unless a certificate is bought from a third party provider, select "Generate certificate" which will make a self-signed certificate.
  8. Enter a name, tick "Use IP/DNS..." and select a date when the certificate will expire as a minimum, and fill out more info if needed. Click "OK". 
    NOTE: Do not exceed year 2060 in the "Valid to" field, doing so will result in a certificate expired error when trying to apply the certificate.
  9. Select the certificate just created and save
     

Installing a certificate through Workstation

  1. Close Workstation (just logging out is not enough)
  2. Open Workstation and log in using the IP address or DNS name - never "localhost" as that name will not match the certificate.
  3. Now you will be able to tick "Always trust this certificate" as the name (IP address or DNS name) in the certificate matches the server you are logging on to. Tick the box, and click "Trust Certificate".
  4. Click "Yes" to confirm the installation of the certificate
  5. Now you will not get the security warning when logging on

Installing a certificate through a browser

  1. Access the server using Internet Explorer (important) entering the https address (e.g. https://localhost)
  2. Click on "Continue to this website"
  3. Click on the "Certificate error" field next to the address bar
  4. Click on "Install certificate"
  5. Select "Trusted Root Certification Authorities"
  6. Click next and ok
  7. Close the browser
  8. Now you can use both Internet Explorer, Google Chrome and FireFox to access the server from Webstation using https and not get the warning

If the certificate fails to install and be trusted properly, it might be because you need to manually select which physical storage to add it to.

Refer to the following discussion

Labels (1)
Labels:
  • EcoStruxure Building Operation
Attachments
Tags (2)
  • Find more articles tagged with:
  • 17198
  • untrusted
Was this article helpful? Yes No
88% helpful (29/33)

Link copied. Please paste this link to share this article on your social media post.

To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2025 Schneider Electric

This is a heading

With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

of