User Manual

Network Security Controls
3
29
Siemens
Application Note
Smart Infrastructure
The communication certificates should be specific. Therefore, it is recom-
mended to use different host certificates for client and server.
The communication certificates are used by the Desigo CC client/FEP.
Therefore, the logged-on user of the client/FEP operating system requires
access to the private key of the host certificate stored in the Windows Certif-
icate store.
The owner of the Desigo CC system is responsible for distributing authorized
certificates and keys. This is often done by the IT infrastructure, particularly,
if commercial
certificates are used instead of the self
-
signed ones.
Deployment Diagram
Figure 10: Client/Server Communication.
NOTE: TRCA and Personal Store are explained in section 1.2.
3.2.3 Server and Remote Web Server (IIS)
Intended Use Case
This section describes a typical deployment scenario for setting up a Desigo CC
system with the web server (IIS) installed on a separate computer.
Web
Desigo CC
Main server
Installed clients Win. App. Client
Click once
Web Client
Browser
Desigo CC
Web server
Fire-
wall
Fire-
wall
Figure 11: Server and Remote Web Server.