Clarification on Secure FTPS Configuration in Automation Studio (4PPC70)

I am currently configuring FTPS communication in Automation Studio for a 4PPC70 PLC and would like to confirm whether my approach follows recommended security practices.

Configuration steps performed:

  1. Created a certificate under Access and Security β†’ Certificate Store (own certificate with auto-generated private key).

  2. Enabled secure communication in PLC configuration:

    • Online Parameters β†’ Protocol: Secure (SSL/TLS)

    • FTP Server: ON (FTPS)

    • Web Server: ON (HTTPS)

    • OPC UA: Enabled

  3. Downloaded the configuration to the PLC.

  4. Connected using WinSCP with:

    • Protocol: FTP

    • Encryption: Explicit TLS/SSL

    • Encountered error: β€œSSL3 alert write fatal: Protocol version”

  5. Resolved the issue by setting minimum TLS version to TLS 1.0 in client settings.

After this change, I am able to access PLC files successfully.

However, I would like to understand:

  • Is this configuration considered secure?

  • What are the recommended best practices for FTPS configuration in Automation Studio?

  • Is using TLS 1.0 acceptable in this case, or should it be avoided?

  • Are there additional security measures I should implement?

  • What would be the most secure approach for configuring FTPS or alternative file transfer methods in this context?

Any guidance on achieving a more secure setup would be appreciated.

Thank you :smiley: .

Hi Sandeep, I would recommend checking the following page for general guidance on Automation Runtime cybersecurity: B&R Online Help

Specifically, here are some considerations and best practices regarding FTPS:

Please let us know if you still have specific questions after consulting this page.

Additionally, I want to inform you that we have an Online Course (paid) that discusses System Hardening in AS 4 and AS 6, here is the link in case you would like to learn more information: Cyber Security basics and system hardening with Automation Studio [SOC990.1] | B&R Industrial Automation