Search found 13 matches

by dominik_z
22 Aug 2025, 13:28
Forum: General
Topic: Is a specialized CA necessary to generate PROFINET-specific extensions in a certificate?
Replies: 1
Views: 39807

Re: Is a specialized CA necessary to generate PROFINET-specific extensions in a certificate?

Webinar_Question wrote: 22 Aug 2025, 09:58 Is a specialized CA necessary to generate PROFINET-specific extensions in a certificate?
No, a special CA is not required (off-the-shelf OpenSSL does the job), despite the PN-specific extensions. Caveat: one has to accept that the CA signs extensions it cannot check semantically.
by dominik_z
22 Aug 2025, 13:28
Forum: General
Topic: Is there a difference in performance between “authentication only” and “authentication AND encryption”?
Replies: 1
Views: 11919

Re: Is there a difference in performance between “authentication only” and “authentication AND encryption”?

Is there a difference in execution performance or duration of the AES-GCM algorithm when using 'authentication only' compared to 'authentication AND encryption'? Yes, authenticated encryption is typically more costly than authentication only. Therefore, both options ae provided to be able to provid...
by dominik_z
22 Aug 2025, 11:56
Forum: General
Topic: Secure PROFINET connection and device-integrated web servers
Replies: 1
Views: 12240

Re: Secure PROFINET connection and device-integrated web servers

Webinar_Question wrote: 22 Aug 2025, 09:54 Does the now secure PROFINET connection also extend to device-embedded webservers or would this need to be secured separately?

PROFINET Security does not cover non-PROFINET connections/services (e.g., webservers).
by dominik_z
22 Aug 2025, 11:54
Forum: General
Topic: Completely isolate the PROFINET network from the outside world or implement security measures?
Replies: 1
Views: 11871

Re: Completely isolate the PROFINET network from the outside world or implement security measures?

It seems simpler to totally isolate your PROFINET network from external surroundings rather than implementing these complex security measures. In an ideal world, security mechanisms would be unnecessary. However, due to developments such as IIoT and IT/OT convergence, the number of devices in facto...
by dominik_z
22 Aug 2025, 11:49
Forum: General
Topic: Is there a decision rule for determining which PROFINET Security Class (1, 2, or 3) a product must comply with?
Replies: 1
Views: 11996

Re: Is there a decision rule for determining which PROFINET Security Class (1, 2, or 3) a product must comply with?

Is there a decision rule for determining which PROFINET Security Class (1, 2, or 3) a product must comply with? PROFINET Security is optional, and its implementation is highly dependent on threat and risk analysis, as well as the intended use and environment. This approach aligns with the standards...
by dominik_z
22 Aug 2025, 11:46
Forum: General
Topic: Who is responsible for controlling the assignment of PROFINET roles to a certificate requestor?
Replies: 1
Views: 12084

Re: Who is responsible for controlling the assignment of PROFINET roles to a certificate requestor?

When using an existing customer PKI to issue certificates, who is responsible for controlling the assignment of PROFINET roles to a certificate requestor? It seems this responsibility falls on the issuing CA, doesn't it? As those credentials will be managed by the operator/customer, they are respon...
by dominik_z
22 Aug 2025, 11:43
Forum: General
Topic: Is an internet connection required for managing certificates?
Replies: 1
Views: 11738

Re: Is an internet connection required for managing certificates?

Webinar_Question wrote: 22 Aug 2025, 09:58 Is an internet connection required for managing certificates?
No, an internet connection is not necessary.
by dominik_z
19 Dec 2024, 16:14
Forum: GSDX
Topic: Can we retrospectively add files to a signed GSDX container?
Replies: 1
Views: 34565

Re: Can we retrospectively add files to a signed GSDX container?

Can we retrospectively add files to a signed GSDX container? No, it’s not possible to add files to a signed GSDX container after the signature has been created. GSDX containers are designed to secure the entire content at the time of signing. Any modifications, such as adding new files, would leave...
by dominik_z
19 Dec 2024, 16:14
Forum: GSDX
Topic: Will Security Class 1 be mandatory for all devices in the future?
Replies: 1
Views: 34158

Re: Will Security Class 1 be mandatory for all devices in the future?

Webinar_Question wrote: 19 Dec 2024, 15:59 Will Security Class 1 be mandatory for all devices in the future?
Security Class 1 and higher are optional and depend on the manufacturer’s choice.
by dominik_z
19 Dec 2024, 16:14
Forum: GSDX
Topic: Is the PROFINET Security Class linked to the security levels defined in IEC 62443-4-2?
Replies: 1
Views: 33953

Re: Is the PROFINET Security Class linked to the security levels defined in IEC 62443-4-2?

Is the PROFINET Security Class linked to the security levels defined in IEC 62443-4-2? PROFINET Security Class and the security levels defined in IEC 62443-4-2 are not directly linked. However, there is a whitepaper available that discusses the relationship between PROFINET Security and IEC 62443, ...
by dominik_z
19 Dec 2024, 16:13
Forum: GSDX
Topic: Will all engineering systems need to be modified to be able to import GSDX files, in addition to traditional GSDML files
Replies: 1
Views: 34534

Re: Will all engineering systems need to be modified to be able to import GSDX files, in addition to traditional GSDML f

Webinar_Question wrote: 19 Dec 2024, 16:00 Will all engineering systems need to be modified to be able to import GSDX files, in addition to traditional GSDML files?
Yes, since GSDX is a new technology that requires signature validation, engineering systems will need to be updated.
by dominik_z
19 Dec 2024, 16:13
Forum: GSDX
Topic: Do the device manufacturers have to provide the GSDX files with a new signature after 3 years?
Replies: 1
Views: 35098

Re: Do the device manufacturers have to provide the GSDX files with a new signature after 3 years?

Webinar_Question wrote: 19 Dec 2024, 16:01 Do the device manufacturers have to provide the GSDX files with a new signature after 3 years, as is the case with the signature card?
No, the GSDX files stay valid for a long period. Even when the certificate has expired, the GSDX file will remain valid.
by dominik_z
19 Dec 2024, 16:12
Forum: GSDX
Topic: What does the Engineering tool need to check the signature?
Replies: 1
Views: 35445

Re: What does the Engineering tool need to check the signature?

Webinar_Question wrote: 19 Dec 2024, 16:01 What does the Engineering tool need to check the signature?
The exact behavior required for the Engineering tool to check the signature is described in the GSDX Specification. You can find more details in the document here: https://www.profibus.com/download/gsdml ... r-profinet