Set up TLS with your own certificate in the software - LSM 3.6 SP1 Business + Prof.

This chapter uses the WaveNet Manager to illustrate the setup for LSM Business. In the example, an existing RouterNode 3 is converted to TLS. The installation consists of the following parts:

  1. Install your own certificates
  2. Installing TLSConnector (Windows Explorer: Folder: C:\Program Files (x86)\SimonsVoss\TLSConnector)
  3. Restart service for CommNode server (Windows services)
  4. RouterNode 3 Configure (WaveNet Manager)
  5. Transfer configuration files (LSM)

There are two ways to install your own certificates:

  1. Double-click installation: As a certificate in the Windows certificate store (certmgr.msc)
  2. This method is recommended as it allows the certificates to be managed and backed up alongside other certificates. That is why this method is chosen in the example.
  3. Save as file in folder C:\Program Files (x86)\SimonsVoss\TLSConnector

If you do not yet have a RouterNode 3 in your WaveNet Manager, the procedure is almost identical. Instead of replacing the existing RouterNode 3 with the same configuration (Replace with ...), simply add it again (Add: IP or USB router or Find IP or USB router).

The procedure in the software is independent of client authentication and is therefore the same regardless of whether client authentication is used or not.

  1. LSM 3.6 SP1 incl. additional applications installed.
  2. LSM open.
  3. Own certificates available ( example, see Create your own certificates (OpenSSL under Windows/Linux)).
  4. RouterNode 3 is configured for TLS with its own certificate and without authentication (see Setting up own without authentication on the RouterNode).
  5. RouterNode 3 in the same network.
  1. In consultation with your IT administrator, install the following certificates: Custom Device CA certificate ( CustomDeviceCA.crt ), Custom Client CA certificate (example: CustomClientCA.crt ) and the client certificate package (example: CustomClient.pfx ).
    (A custom client CA certificate is optional, but recommended to enable Windows to carry out full verification.)
  2. Copy the file TLSConnector.cfg.json_store_sample from the installation directory of your LSM or WaveNet Manager to a temporary location.
  3. Open the file TLSConnector.cfg.json_store_sample with a suitable editor.
  4. Edit the file after consulting your IT administrator (see TLSConnector.cfg.json for own certificate from certificate store for the contents) and save it as TLSConnector.cfg.json.
  5. Copy the file TLSConnector.cfg.json to the folder C:\Program Files (x86)\SimonsVoss\TLSConnector.
  6. NOTE

    notice

    TLSConnector folder for all software components

    As several software components (WaveNet Manager, CommNode Server, etc.) establish a TLS connection, TLSConnector.cfg.json is located in a neutral folder. All software components that establish a TLS connection access this file (and any certificates stored in this folder).

  7. TLS configuration file TLSConnector.cfg.json is available for all software components.
  8. Open the Windows Services and search for the service SimonsVoss CommNode Server.
  9. Restart the service.
  10. When restarted, the service SimonsVoss CommNode Server reads the TLSConnector.cfg.json and also uses the settings saved there.
  11. Open the WaveNet Manager via Network - WaveNet Manager.
  12. A window displaying the WaveNet Manager’s path details opens.
  13. Make sure that the paths to the WaveNet Manager files are correct (WaveNetManager.exe and wntop.csv).
  14. NOTE

    notice

    Changed default installation path for WaveNet Manager from LSM 3.6 SP1 onwards

    Previously the WaveNet Manager and the WaveNet files were installed in the following folder: C:\Program Files (x86)\SimonsVoss\WavenetManager. This folder is located in the protected program folder and problems may occur if is not started with admin rights.

    From LSM 3.6 SP1, the WaveNet Manager is therefore installed in the following folder: C:\SimonsVoss\Wavenet Manager (see also Release Notes LSM 3.6 SP1).

    The required files are normally copied from LSM to the new directory or created by the WaveNet Manager itself. They appear automatically after the LSM is launched for the first time.

    1. If necessary, adjust the paths.
    2. Select the WNManager.ini file from the old installation directory and apply. It contains the WaveNet password.
  15. Click the Start button.
  16. WaveNet Manager asks for the password for the WaveNet configuration.
  17. Click on the OK button.
  18. The WaveNet Manager opens.
  19. RouterNode 3 is not currently linked via TLS.
  20. Right-click to open the RouterNode 3 context menu.
  21. Select the option Replace with ....
  22. Click on the OK button.
  23. WaveNet Manager asks for the IP or host name of the RouterNode 3.
  24. NOTE

    notice

    Adding TLS-protected RouterNode 3 only with IP

    TLS protected RouterNode 3 cannot be integrated via the hostname.

    1. If necessary, determine the IP address of RouterNode 3 (see the manual RouterNode 3).
    2. Select the IP address and enter the IP address.
  25. Click on the OK button.
  26. WaveNet Manager writes the configuration again to the RouterNode 3.
  27. If the TLS connection is successful, this is indicated in WaveNet Manager by the abbreviation TLS at RouterNode 3.
  28. Click on the button SAVE.
  29. Click on the Exit button.
  30. Click on the Yes button.
  31. The WaveNet Manager closes and the import dialogue opens.
  32. Click the button Import.
  33. The results overview opens.
  34. Click on the OK button.
  35. The results overview closes and the import is executed.
  36. Select Network/Communication nodes.
  37. Ensure that the communication node used for your WaveNet is visible.
    The reading for RouterNode 3 must be within the range of Connections.
    If necessary, use the arrow keys to switch to the correct communication node ( and ).
  38. Click on the Config files button.
  39. The Explorer window will open.
  40. Select the folder in which your CommNode server is located (default: %ProgramFiles(x86)%\SimonsVoss\\CommNodeSvr_3_x).
  41. Click on the OK button.
  42. A query regarding the node-specific path appears.
  43. Click the No button.
  44. Config files are saved in the services directory.
  45. Click the Transmit button.
  46. Configuration files are transferred to the service.
  47. The service now knows not only which TLS settings to use, but also which routers to address with TLS.
  48. As the connection between the CommNode server and RouterNode 3 uses its own certificates via TLS, you can now also secure the RouterNode 3 web interface using the same certificates (see Setting up own without authentication on the RouterNode).
  1. RouterNode 3 is connected to TLS.
  2. RouterNode 3 lights up turquoise.