January 1, 2021

#56 - SCADA Ignition Enabling "Force Secure Redirect" over HTTPS on the Gateway

One of the fundamental steps to increase the security of communication between Gateway and Clients / Designers is to enable the option "Force Secure Redirect" in Gateway Config> Network> Web Server.


When doing this, and with a valid SSL / TLS certificate installed, HTTP traffic will   be forced  to HTTPS on the configured port, and will ensure that the data is encrypted in this communication.

From now on, when trying to open an HTTP connection (port 8088), an automatic route to HTTPS (port 8043) will be made. One point to add, is that SSL / TLS certificates must be renewed frequently because they have a precise expiration date and there are ways to automate this process using ACME (Automatic Certificate Management Environment). A free trial of the quality of a server's SSL can be done on this SSL Labs website.

No comments:

Post a Comment